007Bistromath
My feedback
5 results found
-
1,682 votes
An error occurred while saving the comment An error occurred while saving the comment
007Bistromath
commented
This is probably the most important security upgrade you could do. Until I can secure my account in general and especially proton pass with yubikeys, it can't completely replace keepass. I'm not putting TOTP or passkeys into something that doesn't ask for a challenge-response from one of my password-protected keys. I actually don't want my credentials in the cloud at all, but I sometimes need to share creds with people who don't touch computers enough to set up both keepass and syncthing. I'd be doing this without you if I didn't have family.
I just want to point out that if somebody who just got your service yesterday is already making an account on your feedback website and upvoting a complaint with comments going back more than a year, you're making them seriously regret their purchase.
007Bistromath
supported this idea
·
-
1,608 votes
007Bistromath
supported this idea
·
-
776 votes
007Bistromath
supported this idea
·
-
305 votes
007Bistromath
supported this idea
·
-
1,015 votes
007Bistromath
supported this idea
·
Just want to point out that I nearly lost access to all my credentials because I decided to try Proton Authenticator. When you register a yubikey with it, it overwrites slot 2. I know this because I was suddenly unable to get into the keepass db which had my existing TOTP stuff and MY PROTON ACCOUNT PASSWORD.
The only reason I was able to salvage the situation is I hadn't used my laptop recently enough to have migrated, so I had an old copy of my full keepass db. Which I will continue using instead of Proton Pass, because you couldn't pay me to put my passwords in the cloud if I can't even put 2FA on them. Quite literally, I have 2FA at home. I don't need Proton's. Phone authenticators rely on hardware that is known to be compromised!
This is making me strongly reconsider having a Proton account at all. I have had it for one day, and it nearly ruined my life. For a company that markets paranoia, Proton is really bad at it.
PS: the authenticator is orphaned on arch linux, so I couldn't even try it on desktop
PPS: I have suffered permanent data loss because an external drive I forgot about was secured with the old HMAC secret.