Skip to content

Vivek R.

My feedback

2 results found

  1. 157 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    An error occurred while saving the comment
    Vivek R. commented  · 

    As an addendum to my comment about allowing direct login into Proton Pass using a passKEY, I think allowing direct login using a 6-digit TOTP (generated by a third-party authenticator app like Duo Mobile or Authy) would also be a viable option. I would still avoid allowing direct login into Proton Pass with nothing but a single passWORD because then literally anyone with Internet access would in principle be able to breach your Proton Pass account, as opposed to only someone who has access to your biometric data (in the case of a passkey) or at the very least your smartphone (in the case of an authenticator app-generated TOTP).

    An error occurred while saving the comment
    Vivek R. commented  · 

    I would support this only if you would be logging directly into Proton Pass with a passKEY (which most browsers and mobile devices now support natively, meaning that the passkey would not need to be stored inside Proton). Quantum computing is going to radically change the security of conventional static passWORDS; as such, I think having only a single static passWORD (that has to be short enough that you can remember it in your head) protect *all* of the credentials stored in Proton Pass would be a significant security liability, especially considering that Proton Pass is accessible online and is thus attackable by anyone who knows or can guess your username.

    Personally, I use two-password mode coupled with a 2FA authenticator app just for my *regular* Proton account, and I also took advantage of the extra password option recently added to Proton Pass, meaning that a potential attacker has to get through not one but FOUR layers of authentication to reach my Proton Pass credentials (which is exactly how I like it). However, for those who aren't as die-hard about security as I am, I think adding the option for direct passKEY (not passWORD) login would be a reasonable compromise.

  2. 66 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    An error occurred while saving the comment
    Vivek R. commented  · 

    Agree; this feature would significantly improve the usability of Proton Pass on websites that have restrictive password requirements.

    Vivek R. supported this idea  · 

Feedback and Knowledge Base