I’m using proton services and now the Pass password manager as well. I never let any managers save my bank data such as credit cards or login credentials being sort of afraid to.
Is this concern still valid? when using a manager like Proton Pass that has e2e encryption? what’s your opinion on holding bank data in managers like this?
that are good suggestions. my bank accounts all require two steps authentications, with the second one being mostly auth via mobile app, so that part is enforced and always keeps the account secured better.
I do have one concern with the Proton account itself, as you wrote “no all eggs in one basket” rule of thumb. With the Pass, I have the 2FA integrated together with passwords (not for bank accounts) - a little risk in here with a gain on convenience.
Though I certainly do not store my Proton password in it, keeping it memorable and more than 40 characters long makes me feel safe. Im not sure what 2FA app to use for the Proton tho, would you recommend anything? I cannot use a physical key, as my devices have different USB connectors and I cannot have a one key for all.
I personally use Aegis for Android (https://getaegis.app/) and FreeOTP for iOS (https://apps.apple.com/us/app/freeotp-authenticator/id872559395) both open source.
YubiKey makes several models for physical keys but I could understand not wanting it. I use NFC for my mobile device and USB-C on my computers.
that are two separate keys? or that’s one key that has USB + NFC on it? cause that would be kinda good, as all my devices have USB except for the iPhone, but it has NFC so that would be sufficient enough
It’s one key with NFC for mobile devices plus a port of your choice. I’d check out there main site for this model, https://www.yubico.com/product/yubikey-5-series/yubikey-5c-nfc/
It is kinda pricey but they work well and they are well built, very easy for setup and use. I’ve almost always had better luck finding it a bit cheaper on Amazon.
ok, I see some on my country sites with a reasonable price. thanks for the tips! if you don’t mind I would like to ask one more question in regards to the keys.
How does they work in pairs? Like, I see an auction where I can buy one key separately, but to dont get locked out of account I would rather want to buy two. Should I look for auction with bundle of two? or I can set up two separate keys to be used for the same authorizaion?
Yes, it is recommended to purchase 2. It literally makes them identical in case you lose your primary. 1 in a safe and 1 on your key ring kinda thing.
Some websites may not allow recovery if you lose your key, so yes a 2nd one is useful if possible. And yes, you would be able to use both interchangeably.
thanks for your help! gotta get them then for my Proton account to keep it safe and handle all the other auths with passwords and TOTPs I guess.
For MFA apps, Google Authenticator seems to be the norm.
I personally use OTPAuth with sync disabled and regular backups. Mostly because it is easier to organise and back up.
Regarding hardware security keys as part of MFA, you can either get yourself dual USB-C / Lightning or USB-C / USB-A keys from Yubikey. Then just buy a USB-A to USB-C dongle (or vice versa) and keep it on your key chain. That’s mostly what I do, not ideal but does the job.
I also use OnlyKey for some passwords, especially encryption passphrases on some servers and laptops. I usually need to enter them on boot, and it just takes too long to do that manually and I’m lazy.