Encrypted email service Proton announces end-to-end encrypted password manager Proton Pass



Proton , which develops the end-to-end encrypted mail service Proton Mail, which is also operated in Switzerland where there is a strong privacy protection law, has announced its own password manager ` ` Proton Pass ''.

Proton Pass is now in beta | Proton
https://proton.me/blog/proton-pass-beta




Proton launches an end-to-end encrypted password manager - The Verge
https://www.theverge.com/2023/4/20/23691097/proton-end-to-end-encrypted-password-manager-e2ee

On April 20, 2023 local time, Proton will launch a beta version of its own password manager with end-to-end encryption, 'Proton Pass', for users ( Visionaries ) who have supported Proton Mail since the beginning of the service. has started to provide Invitations to the beta version of Proton Pass will be emailed to eligible participants during the fifth week of April 2023.

A password manager is one of the most requested new products by Proton users. Proton Pass, developed in response to such voices, protects credentials by using end-to-end encryption like Proton Mail, making it more secure than a standard password manager. Proton is preparing to open the Proton Pass to the public in the second half of 2023, and ``details will be revealed in the coming weeks and months.''

In 2022, Proton acquired SimpleLogin, an open source anonymous email service. SimpleLogin is a service that allows you to create an account on a web service and receive emails without disclosing your email address. SimpleLogin's original vision was to make logging into your account safer, more private, and easier, and the service was named after this vision. Proton Pass is said to be a password manager developed by such SimpleLogin and Proton engineers in cooperation.



``By acquiring SimpleLogin, we were able to develop a new password manager without impacting our efforts on other Proton services,'' said Andy Yen, founder and CEO of Proton. Appeal that the acquisition of SimpleLogin will no longer affect the development of other services. In addition, ``Because passwords are confidential information, an insecure password manager is very dangerous for the Proton community,'' he said, saying that password managers were one of the important issues for Proton, which emphasizes privacy and security.

Proton says, ``If a malicious attacker steals your password by hacking or otherwise, you can basically bypass the advanced encryption of all Proton services. and a high level of security competence, which few organizations have.We have always been concerned about the risks posed by a large-scale password manager breach. , The recent

hack of LastPass has made the fear a reality , ”he explains why he decided to launch his own password manager.

Proton added, ``Proton Pass is more than just a password manager. While many other password managers only encrypt passwords, Proton Pass does end-to-end encryption on all fields (including usernames, web addresses, etc.), so you don't lose any seemingly harmless information (like many others). This encryption is very important because you can also create very detailed profiles by using stored URLs, which are not encrypted in our password manager,' he said, explaining the difference from other password managers. appeal.



Note that Proton Pass implements bcrypt , a strong password hashing function, Secure Remote Password (SRP) for authentication, and many other features, including fully integrated two-factor authentication. I'm here. It also supports auto-entry of two-factor authentication, and it seems that anyone can easily and securely protect their account.

Proton Pass, like all other Proton services, is open source and open to anyone to independently validate its security features and implementation.

At the time of article creation, beta version Proton Pass is available for iPhone / iPad, Android, desktop. Browser extensions are available for Chrome and Brave. It seems that a Firefox version add-on is under development, but it is not available at the time of article creation because it was not approved before release.

in Software,   Security, Posted by logu_ii