Log into Proton Pass directly with its own password (without having to log into a Proton account first)

-
Rodolfo Souza commented
I am a Bitwarden user and I tried to use Pass to potentially have it as my password manager. However, I was not able to login without Bitwarden due to the 2FA! So, Pass is good, but it's not ready for needs.
-
denby41 commented
Given the single-sign-on account cookie hijacking threat described here, in a 2018 helpnetsecurity.com article:
https://www.helpnetsecurity.com/2018/08/22/single-sign-on-account-hijacking-threat/
I am extremely concerned about the risks entailed in the use of my ProtonMail password for any other Proton services.In response to the comment below, by Jelmer Hartman, users should have the option to employ as much security to their E2E encrypted accounts as they wish. Perhaps it is true that some may wish to use a simple password to secure their password managers, but others of us are coming from outside password managers which already have a complex master password that we have known for years, and which, additionally,, is backed up, elsewhere, in the event that there is ever a problem with it. In that scenario, it is not so much a matter of wanting to store a strong password and secure it with a weak password -- OR one of securing a weak password with another weak one -- but basic account security to require unique strong passwords for every individual critical account. I, myself, do not have any technical computer training, but the lack of this capability through Proton's leaving of the initial password in place and simply adding another one to it, both of which can be used to access ProtonPass, is what is stopping me dead in my tracks from adopting their password manager. Until this product is capable of being secured as well as my current password manager (leaving my ProtonMail account also fully secured), it will not be a serious option for me to consider employing.
-
Jelmer Hartman commented
Most of the reasoning below is fundamentaly wrong. If you use a simple to remember password and then store you email password using that, it is not better than using a simple email password in the first place. Your email account is as sensitive as your password manager because most services allow you to reset your password using it. So the best way would be to have a different password for email and password manager. That only makes sense if you do not store your email password in your password manger. Using an extra password for proton pass give you exact the same level of security. So, altough this feature request would not fundamentaly weaken the security of the solution, the people who think they need to use this feature would probably weaken their personal security considerably because of it.
-
Rafael commented
This is literally what's preventing me from switching from Bitwarden. I will not change my random Proton password to a "simpler" one just to be able to use Proton Pass.
Also, the possibility to have an additional password only for the password manager makes no sense at all, as I would need to remember the "main" and the "pass" passwords.
-
Chris commented
I don't know my Proton password. Like others, I would like to be able to unlock other Proton services (Mail, Drive, Wallet, etc.) using a passkey or 2FA. I understand that this likely represents a re-architecture of your authentication and/or key generation strategy but many do not. It would be worth making a statement explaining this and the work you are doing to address this need in one of your next product update emails.
-
Maikel Mast commented
How is this not at the top of the list? I absolutely refuse to use ProtonPass without this. As many people are stating... I need to use 1Password to unlock Proton Pass, so why would I ever switch?
-
protonuser commented
This is very important and should be a priority task.
-
Anonymous commented
Would like to move from Bitwarden to proton pass but this is not possible as long as this feature, a separate password for proton pass, is not correctly implemented. The implemented second password is not the correct solution.
-
Thierry commented
Hi there,
Using its own PW is just so important !
Thanks 😉
-
Erik Barrow commented
I recently moved my email to protonmail with the proton ultimate plan. I set up my protonaccount with a secure random password generated by bitwarden that I currently use. It makes sense for me to consider using protonpass as it is part of the package I now pay for, but I don't want to use the long random password to log into it, I need to use my long but memorable password to access my password manager with the random passwords. And I don't really want to set my email password to the less random memorable password I use for my password manager. I see proton pass has a second password feature, but only as an additional password that has to be entered with he protonaccount password, but I want to be able to just have a separate password from proton pass, without needing my proton account password.
I want to be able to login to protonaccount with proton pass, not the other away round, Otherwise I will need to keep using bitwarden just to manage login to protonpass.
-
Brancu Alexandru commented
Hey guys please implement this
-
AT commented
the concept that i need 1password to unlock my protonpass is absolutely ******** as if i would trust my password manager to have the same authentication as my email client and everything else so if somebody steal your session cookies bye bye password manager
-
curmudgeony tom commented
There are currently 1593 total votes for this feature across this idea and the earlier idea posted here:
https://protonmail.uservoice.com/forums/953584-proton-pass/suggestions/46727686-use-a-different-password-for-protonpassThis makes it the highest requested feature for Proton Pass of all time. Why is this not planned yet? Why is it not even under review?
-
uservoicebutter commented
I'm in the same boat as "JP". It makes no sense to use Proton Pass at the moment as long as I have to keep using another password Manager for the Proton password.
-
JP commented
I require the ability to lock Proton Pass with a secure, memorable password that is completely separate from my Proton Account password. Currently I need to continue using Bitwarden to store my randomly generated Proton account password, because I need said password to access Proton Pass... At this point there's no reason for me to make the switch to Proton Pass when I already have to open Bitwarden to login.
-
curmudgeony tom commented
This is critical for me to switch to Proton Pass. Otherwise I need to use another password manager just to login to Proton Pass with a secure password.
-
Rémy Léridon commented
Voilà qui me parait un fonctionnement indispensable
-
Tes commented
This is critical, we need the app to have its OWN password, not another one.
-
Сергій commented
Really need this feature to migrate from 1password
-
Thiago B. commented
Totally agreed!
I'm trying to migrate from 1password after an upgrade to Proton Ultimate plan and this is something I really think is critical.
I understand that both app pasword and account password need to be strong, but it sounds very critical to have this other layer of security and convenience.
Plus, having the same password foraccount and Proton Pass makes impossible to set up a 2FA in the account without having to download an specific authenticator app. But I don't want to use 1password to generate a 2FA code for Proton Pass :)