Log into Proton Pass directly with its own password (without having to log into a Proton account first)
-
ryefly
commented
We don't want an additional password. Pass should have its own/separate master password. That's the point of a password manager. Remember a secure password. If I set up a new PC, how do I get to my Proton account? If you generate a 50-character password for your Proton account, for example, how are you supposed to remember it?
Proton has worked against this request and closed it. According to the motto, look, we've given you a password.
-
ryefly
commented
I'm shocked that there is no separate master password for Pass. This definitely needs to be added. How can I log in on a new PC if I don't know the Proton password? You can't log in anywhere like this. Please implement it!
This makes the change from 1P to Pass impossible.As I understand it, Proton thinks that this request is fulfilled with the additional password. But that was never what the customers wanted. It will probably never happen, which is a shame!
-
Rodolfo Souza
commented
I am a Bitwarden user and I tried to use Pass to potentially have it as my password manager. However, I was not able to login without Bitwarden due to the 2FA! So, Pass is good, but it's not ready for needs.
-
denby41
commented
Given the single-sign-on account cookie hijacking threat described here, in a 2018 helpnetsecurity.com article:
https://www.helpnetsecurity.com/2018/08/22/single-sign-on-account-hijacking-threat/
I am extremely concerned about the risks entailed in the use of my ProtonMail password for any other Proton services.In response to the comment below, by Jelmer Hartman, users should have the option to employ as much security to their E2E encrypted accounts as they wish. Perhaps it is true that some may wish to use a simple password to secure their password managers, but others of us are coming from outside password managers which already have a complex master password that we have known for years, and which, additionally,, is backed up, elsewhere, in the event that there is ever a problem with it. In that scenario, it is not so much a matter of wanting to store a strong password and secure it with a weak password -- OR one of securing a weak password with another weak one -- but basic account security to require unique strong passwords for every individual critical account. I, myself, do not have any technical computer training, but the lack of this capability through Proton's leaving of the initial password in place and simply adding another one to it, both of which can be used to access ProtonPass, is what is stopping me dead in my tracks from adopting their password manager. Until this product is capable of being secured as well as my current password manager (leaving my ProtonMail account also fully secured), it will not be a serious option for me to consider employing.
-
Jelmer Hartman
commented
Most of the reasoning below is fundamentaly wrong. If you use a simple to remember password and then store you email password using that, it is not better than using a simple email password in the first place. Your email account is as sensitive as your password manager because most services allow you to reset your password using it. So the best way would be to have a different password for email and password manager. That only makes sense if you do not store your email password in your password manger. Using an extra password for proton pass give you exact the same level of security. So, altough this feature request would not fundamentaly weaken the security of the solution, the people who think they need to use this feature would probably weaken their personal security considerably because of it.
-
Rafael
commented
Adding an extra password is not what the request was about. How can you close this ticket without solving it?
-
Rafael
commented
This is literally what's preventing me from switching from Bitwarden. I will not change my random Proton password to a "simpler" one just to be able to use Proton Pass.
Also, the possibility to have an additional password only for the password manager makes no sense at all, as I would need to remember the "main" and the "pass" passwords.
-
Chris
commented
I don't know my Proton password. Like others, I would like to be able to unlock other Proton services (Mail, Drive, Wallet, etc.) using a passkey or 2FA. I understand that this likely represents a re-architecture of your authentication and/or key generation strategy but many do not. It would be worth making a statement explaining this and the work you are doing to address this need in one of your next product update emails.
-
Maikel Mast commented
How is this not at the top of the list? I absolutely refuse to use ProtonPass without this. As many people are stating... I need to use 1Password to unlock Proton Pass, so why would I ever switch?
-
protonuser
commented
This is very important and should be a priority task.
-
Anonymous
commented
Would like to move from Bitwarden to proton pass but this is not possible as long as this feature, a separate password for proton pass, is not correctly implemented. The implemented second password is not the correct solution.
-
Chaz
commented
Guys this just doesn't make any sense because you're effectively still using Proton Mail as the defacto master password. Every password manager provider knows that people want to remember 1x password, for the manager, then the manager remembers password for the mail and other services, not the other way around. This is a deal breaker and I regret buying the lifetime pass without having done prior research. It's insane how you think this is ok?? We don't want an extra password we just want a SINGLE, separate password.
-
Thierry
commented
Hi there,
Using its own PW is just so important !
Thanks 😉
-
Erik Barrow commented
I recently moved my email to protonmail with the proton ultimate plan. I set up my protonaccount with a secure random password generated by bitwarden that I currently use. It makes sense for me to consider using protonpass as it is part of the package I now pay for, but I don't want to use the long random password to log into it, I need to use my long but memorable password to access my password manager with the random passwords. And I don't really want to set my email password to the less random memorable password I use for my password manager. I see proton pass has a second password feature, but only as an additional password that has to be entered with he protonaccount password, but I want to be able to just have a separate password from proton pass, without needing my proton account password.
I want to be able to login to protonaccount with proton pass, not the other away round, Otherwise I will need to keep using bitwarden just to manage login to protonpass.
-
Brancu Alexandru commented
Hey guys please implement this
-
AT
commented
the concept that i need 1password to unlock my protonpass is absolutely ******** as if i would trust my password manager to have the same authentication as my email client and everything else so if somebody steal your session cookies bye bye password manager
-
curmudgeony tom
commented
There are currently 1593 total votes for this feature across this idea and the earlier idea posted here:
https://protonmail.uservoice.com/forums/953584-proton-pass/suggestions/46727686-use-a-different-password-for-protonpassThis makes it the highest requested feature for Proton Pass of all time. Why is this not planned yet? Why is it not even under review?
-
uservoicebutter
commented
I'm in the same boat as "JP". It makes no sense to use Proton Pass at the moment as long as I have to keep using another password Manager for the Proton password.
-
JP
commented
I require the ability to lock Proton Pass with a secure, memorable password that is completely separate from my Proton Account password. Currently I need to continue using Bitwarden to store my randomly generated Proton account password, because I need said password to access Proton Pass... At this point there's no reason for me to make the switch to Proton Pass when I already have to open Bitwarden to login.
-
curmudgeony tom
commented
This is critical for me to switch to Proton Pass. Otherwise I need to use another password manager just to login to Proton Pass with a secure password.