One downside is that i’ll have no more passkeys. The vault syncing, i can do via SyncThing.

  • Crabhands@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    2 hours ago

    I think I’ve done the opposite of most. After using keepassx for the last 4 or 5 years I switched to ProtonPass.

    I value security and privacy but Ive realized some of my processes have become too complex, like using syncthing to keep my keepass on my phone and PC aligned. I’m not confident that older man version of me will be able to keep up so Ive stared valuing simplicity.

    Im sure many will argue that it is simple but between backups and keys and passwords it really is a lot, especially with a new device each time.

  • ReversalHatchery@beehaw.org
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    14 hours ago

    Syncthing is fine and secure, but be absolutely sure you set up some kind of file versioning for the shared folder. at least a trashcan versioning, if not better. protects you against accidental deletion

  • Dem Bosain@midwest.social
    link
    fedilink
    English
    arrow-up
    13
    ·
    edit-2
    1 day ago

    There have been too many data breaches from cloud-based services to trust another one. I have a Proton account for email and online storage, but I won’t use their password service because it’s cloud based.

    https://blog.lastpass.com/posts/notice-of-recent-security-incident

    Lastpass leaked their password database in 2022, and bad actors are still using it to access peoples files, stealing passwords and hundreds of thousands of dollars in crypto.

    DON’T trust anything important to cloud-based storage or services. Use Keepass. Use Syncthing if you need to keep the database on multiple devices.

    (I see other comments using Dropbox. Dropbox = cloud. Don’t store anything security related in the cloud.)

  • Sonalder@lemmy.ml
    link
    fedilink
    arrow-up
    12
    ·
    1 day ago

    It really depend on your threat model, Proton Pass is fine. Of course a self-hosted or local solution will be more privacy friendly but at the cost of being responsable for security and good backups (3,2 1 rule).

    There is no black or white regarding privacy. You want to ask yourself what you want to protect from and is the investment worth being sovereign ?

  • Pearl@lemmy.ml
    link
    fedilink
    arrow-up
    4
    ·
    1 day ago

    Doesn’t keypass support passkeys?

    As you can see from the thread, this question is divided amongst the cult of “sensible privacy is a thing provided you’re not a criminal” to the cult of “everybody’s on a FEMA/🧊 spreadsheet and they’re working their way down”.

    I’d say make sure you use a separate password for proton pass, it’s an advanced option. You are far more likely to get hacked for your money and password manager goes 97% of the way to defeating those attacks.

    Don’t take your eye off the ball. The real threats to your wallet have always been the shareholders.

  • hankthetankie [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    1 day ago

    KeePass then you have your own file instead of relying on a third party. And you are free to sync it how you wish , syncthing is great . I left proton earlier since I don’t trust them , but never used the proton pass at all.

  • Sem@lemmy.ml
    link
    fedilink
    arrow-up
    4
    arrow-down
    1
    ·
    1 day ago

    I think proton is the most blocked by governments group of services in the entire world. To have a backup in .kbdx file sounds at least like a good idea.

  • salvor_hardin@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    1 day ago

    Any specific reason that makes Proton Pass less secure? I am curious since I am using both pass and bitwarden at the moment. bitwarden for all my logins and pass for alias + their logins.