Today, we are releasing Proton Authenticator, a standalone 2FA app that provides a straightforward way to further protect your accounts against data leaks and hackers.
Authenticator enables you to store your 2FA codes separately from your regular login credentials, thereby enhancing the overall security of your Proton account - and any other account.
This standalone app offers a flexible and open-source solution as an additional layer of defense.
Authenticator is free to use, and no Proton account is required.
Proton Authenticator gives you the freedom to use your 2FA codes however you want, wherever you want.
You can use Proton Authenticator to:
Access your 2FA codes on mobile and desktop apps, even offline.
Sync your 2FA codes to all your devices with end-to-end encryption.
Enable automatic backups for ultimate peace of mind.
Easily import from other 2FA apps, as well as export codes from Proton Authenticator.
Protect your account with biometrics or a PIN code.
This feature has been requested in various ways via Uservoice, our community-powered platform; you can let us know what you’d like us to work on by raising it there.
Enjoy our cross-platform and privacy-first authenticator app.
Pass was working fine this morning but at some point today the extension started crashing whenever clicked and the website itself just pulls up the Chrome "Oh Snap!" error and says STATUS_ACCESS_VIOLATION. Anyone else running into this?
(Already tried updating Chrome, reinstalling the extension, and restarting the computer)
Ok, I don't know if I'm doing something wrong, but I have the latest version of Android and the Authenticator app, and when exporting, even if I enter the password, it's just a regular json file.
The same with automatic backups, the password is entered, but the export is a json file.
Shouldn't it be encrypted pgp format?
I'm not logged in, the only thing I have, is that I have biometric access to open the app.
I have a few custom domains attached to simple login. I want to make a simple html page so that when someone visits the site it looks like a real email service. I obviously won't give anyone any services, but I think it'll make my aliases look more legit.
Could there be any legal problem? Or a problem with the terms of service of Proton?
I have just migrated to Proton Pass. When I attempt a passkey authentication, Proton Pass does not react, I just get a prompt from Firefox: "touch your security key".
Is it supposed to be working? FYI, I imported my Bitwarden collection, I'm not sure if passkeys were transferred. I don't see a mention of passkeys in my saved items.
Passkey auth works fine with the Bitwarden extension in Firefox.
I’ve TRIED sending feedback in on this Proton Pass issue for months now. But not only does their feedback form never work correctly, but then Proton VPN literally stalls by the time I can make any progress submitting the issue for Proton Pass. I’ve also tried to report that issue and it goes nowhere. Even when they’ve responded, they’ve only asked me for screenshots/recordings which I already provided.
What the hell are any of us supposed to do? Is it just time to leave?
I've always sort of wondered about that. It's a bit of a hassle to have to promptly extract and re-encrypt the download when I back up my vault. Is there some technological reason it's infeasible? I mean, they're encrypted when they're in the vault, so it doesn't really seem like that should be an issue.
Wenn ich in Chrome auf Android benutze fragt mich Google Passwort ob ich mein Passwort speichern will und nicht ProtonPass, bzw. es wird mit auch von Google ein sicheres Passwort vorgeschlagen.
Ich habe ein Samsung Galaxy s25+, Chrome Browser. falls es wichtig ist, ich benutze Gboard Tastatur.
I’d love to know the algorithm that decides whether a password is weak or not.
About 60% of my passwords are marked as ‘weak’. I have 14 character, mixed case, alphanumeric passwords marked as ‘weak’ when I think they’re absolutely not.
94^14 is about 4.22 x10^27 possible permutations. So best case scenario, a threat actor trying a billion permutations per second finds the right combination at the half way point, taking about 67 million years.
And that’s just an offline brute force attack, whereas most reputable online services will have throttling, lockouts, MFA etc.
In what reality is 67 million years not considered an acceptable cover time and why is proton saying this is ‘weak’?
I like the app but, honestly, get real with the warnings about password being weak or at least give us the options to turn that off.
I've been using Proton Pass (Free) for some time, and i love it, but i can't stand the fact that i can't organise my logins without an subscription. So i was wondering about popular alternatives, and i heard about bitwarden. Unfortunately, it also have 2 vaults (for free), same as Proton Pass, BUT it has "folders", which removes my single main inconvinece about Proton Pass. But i've also heard about Proton planning to implement them soon, but what do you think? Should i wait or swich to Bitwarden?
I've been on LastPass for many years, and for the most part have been happy there. Reading about the data breaches has made me uneasy and am trying out Proton Pass. Unfortunately, I cannot get the autofill to work for half the sites I normally use. Am I doing something wrong? I have autofill settings turned on (or at least I think I do). Or does the autofill only work when you become a paying subscriber? I'm obviously on the FREE version to try it out.
I previously used Google password manager before migrating over to proton pass. So I have lots of saved passwords in both places currently.
This morning I received a critical security alert email from Google saying one of my passwords related to an site was found online. It listed the website and password too.
I went to proton pass, and made sure that it was added in the dark web monitoring, but it's not detecting any breaches for this password.
Right now I have cloudflare forwarding my emails for free, but I have to deal with third-party SMTP service to send mails, I have to also trust these companies aren't collecting my mails when sending.
If I get Proton Pass lifetime, can I just replace my current set up? I wasn't able to figure out how the emails are sent? Are they sent via Proton's mail servers or is a seperate mail service hosted by? I rarely ever initiate emails so I'm okay with the hassle of adding them as a contact first. Is there something I'm missing?
Hi everyone. I decided to switch from "Authy" to "Proton Authenticator" today. Everything went smoothly until I got to Snapchat. I have to copy the code because Snapchat doesn't recognize Proton Auth for some reason. Then I get a 6-digit code, and when I try to paste it, I get a message: "This is an incorrect code!" Has anyone else had this problem, or can anyone help me?
In these two videos (on is MacBook, the other is iPhone), you can see that random passwords that are considered strong in the macOS application, are weak on mobile devices. I have passwords that I set in macOS where the app told me it was a strong password, but when I view the password on my iPhone, Samsung Galaxy S25, or iPad Pro, they are weak. Why is that?
I have already used the force synchronization. I have checked to make sure all my apps are up to date. I have quit and relaunched the apps. The only thing I haven’t done is delete and reinstall. So is this a bug anyone else has noticed?
I checked the Password Monitor tab all the devices. My weak password count is 120 on my MacBook and 123 on all my mobile devices. So is the MacBook version more relaxed when it comes to passwords? It seems like Proton Pass for Mac is more willing to label passwords as strong.
So far, I have only checked the "Memorable Password" type with periods.
I know we can add alias emails but I also don't want to reuse the same username across all sites if it can be helped. I think there should also be a generic username generator along with the ability to add a "username" under the main section with username / email and password. I just manually add my usernames as a new text entry, it seperates it and looks off.
I was today years old when I discovered that not only can I disable Aliases, but I can get more granular and disable specific contacts within an Alias!!!
I have a “firstnamelastname.com” domain that used to belong to someone else. When I tried to use [email protected], I started to receive their junk mail.
Now I can just disable the contacts, instead, so I can use that email. I’ll try it for a while, but if it gets crazy I may have to disable the whole thing again….
I know Proton Mail has Post-Quantum Cryptography already, well it started rolling out in May 2026 - I have yet to see it as an available option in my Proton Mail account settings yet...
We especially need this in Proton Pass to further protect the valuable data we have stored in it.
Since its available for Mail I assume they would be able to use the same encryption algorithms in Pass? If so it might just be a matter of implementing it, which I understand could take some time. But if thats the case hopefully it happens within the near future.
On my desktop I generated passkeys for my ChatGPT login and stored those on Proton Pass (via Firefox Extension).
To login on the android app of ChatGPT I also have to use a passkey. In the login process I get redirected to a web broswer (tried it with chrome and firefox) but in both cases the system tray says that there are no passkeys stored on this device. Proton Pass was synced and it was selected as the default passord service in the settings.
I repeated this process with Bitwarden and it worked flawless. Why is that? All the apps are up to date. Is there an issue with proton pass where it does note communicate properly with the system or did I do something wrong?