posted friction
My feedback
32 results found
-
1,094 votes
posted friction
supported this idea
·
-
435 votes
posted friction
supported this idea
·
-
139 votes
posted friction
supported this idea
·
-
2,740 votes
Subscribers now have access to offline view with the introduction of the Proton Pass desktop app for Windows:
For more information, including what's coming next, check out: https://proton.me/blog/proton-pass-windows-app
posted friction
supported this idea
·
-
2,417 votes
posted friction
supported this idea
·
-
54 votes
posted friction
supported this idea
·
-
26 votes
posted friction
supported this idea
·
-
29 votes
posted friction
supported this idea
·
-
559 votes
posted friction
supported this idea
·
-
399 votes
posted friction
supported this idea
·
-
6 votes
An error occurred while saving the comment
posted friction
supported this idea
·
-
173 votes
posted friction
supported this idea
·
This is absolutely critical! I wish I could use my paid Proton account on my untrusted desktop PC, in controlled manner.
My use case is accessing VPN and specific Drive folders. It should also be possible to isolate Proton Pass from other services as well. Secondary password just doesn't cut it.
I'm sure there are people signed into Proton VPN on insecure devices such as smart TVs. This can lead to an attacker gaining access to everything inside user's Proton account by exploiting a much weaker link. It is an unacceptable risk.
Right now the only way to mitigate this is to create a separate (device-specific) Proton account and add it to a family/duo plan, just to be able to use a specific service. This workaround is extremely impractical and unnecessarily expensive.
Related but not the same. It's merely a single way to tackle the problem: https://protonmail.uservoice.com/forums/935538-accounts-payments/suggestions/43173582-different-passwords-for-mail-vpn-and-drive
Ideally I should be able to use some features of my Proton account on any device without major security drawbacks. Perhaps something like device-specific profiles could solve this? Think of them as a way to manage separate, yet internally linked, Proton accounts with fine-grained permissions. They would not be using the main e-mail address for logging-in.
Example profiles:
1. "VPN for my Smart TV" - can access only VPN, doesn't provide additinal info such as primary e-mail address or VPN settings from other profiles.
2. "potentially insecure desktop PC" - used for synchronizing specific files and folders between devices, can't view anything about other services.
I am aware that solving this issue might require a complex, careful implementation that has not been deployed by any other service provider yet. I also believe that it's in Proton's best interest to further expand security protections, so that their services can be used by people with different threat models. Not everyone can afford to fully trust all devices that they need to use on a daily basis!
Please, have somebody think about this issue.
For what it's worth, I could help brainstorming all solutions that would be deemed feasible by Proton.
Thank You.