Proton pass

Guys I use proton mail and proton pass but the issue I have is that how can I have a secure password for proton mail with 2fa if I use proton pass? If I have a less difficult password then I am lowering my security and If I want to have a 2fa (with local encrypted file) then I have to save it on some secure cloud, which for me is proton drive or mega then again I have those passwords saved in proton pass so I would have to login to proton pass first, If I lower password of those apps then again it risks security. ( I am sorry I am so confused). Please help!

15 points

Proton warns to not use 2fa from Proton Pass for your Proton account.

permalink
report
reply
5 points

Yeah, from what I’ve read the best approach is a different service for 2fa and/or something involving backups and a physical safe.

permalink
report
parent
reply
1 point

What? Really?

permalink
report
parent
reply
1 point

Yes. I seem to recall that it will change later on, but i don’t know when

permalink
report
parent
reply
7 points

Sounds like it’s time for some correcthorsebatterystaple!

permalink
report
reply
3 points
*
Deleted by creator
permalink
report
parent
reply
4 points

Okay yeah I’ll admit that’s pretty bad, haha. The only password I actually know nowadays is the passphrase to my Keepass database, which clocks in at 40 characters. I rarely say this to people, but have you considered a shorter password? :P

permalink
report
parent
reply
2 points

I don’t even know my master password :D I use some script to generate it and I just copy+paste it.

permalink
report
parent
reply
6 points

Password manager inception. Sign up for last pass, and bitwarden, and Google auth and Ms auth. Get a burner phone and rotate and change passwords monthly.

…sorry for my useless post.

permalink
report
reply
5 points

Use a passphrase (not a password) and a physical security key, like a yubikey. It also supports TOTP or whatever 2fa Proton uses, you just connect it with a laptop or phone and it gives you a key.

A physical key is much more secure than 2fa from a password manager (although both are probably fine)

permalink
report
reply
4 points

In my opinion the centralization of all your data and secrets to one single company is itself a security risk. When I realized that, I completely stopped using proton. I see 2 main issues with using all-proton: 1. they could turn evil (like a lot of big companies do) 2. They can have exploits which then can effect all your data / secrets. I switched to have a different company for each service and I don’t really pay more than what I would have to pay proton to get the same things.

permalink
report
reply

Asklemmy

!asklemmy@lemmy.ml

Create post

A loosely moderated place to ask open-ended questions

Search asklemmy 🔍

If your post meets the following criteria, it’s welcome here!

  1. Open-ended question
  2. Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
  3. Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
  4. Not ad nauseam inducing: please make sure it is a question that would be new to most members
  5. An actual topic of discussion

Looking for support?

Looking for a community?

Icon by @Double_A@discuss.tchncs.de

Community stats

  • 10K

    Monthly active users

  • 5.9K

    Posts

  • 319K

    Comments