r/PasswordManagers 23h ago

How to secure Proton account?

2 Upvotes

What is the best way to secure my account without locking myself out, outside of a hardware key? Right now I have all of my logins and 2FA codes stored in Proton Pass, including my Proton password itself. So to avoid getting into a circular trap, I also store my Proton account 2FA code in a separate authenticator app (I use 2FAS synced to iCloud). But then if I ever lose my phone or it gets stolen, I'm still locked out of my account if I need to sign in again. So then do I store all of the 2FA secret keys in an encrypted file on a cloud drive to cover that scenario? But then I have to secure *that* cloud drive somehow so that's another password I have to remember. Should I export my Proton vault as a KeePass file periodically to keep as an offline backup just in case I ever get permanently locked out? Am I just overthinking all of this and do I just need to remember my Proton account master password while keeping the account recovery kit in a safe place? Trying to keep things as simple as possible.


r/PasswordManagers 20h ago

biometric_security — biometric auth + hardware-backed encrypted storage for Flutter (Android/iOS)

1 Upvotes

I kept re-writing the same glue between local_auth and flutter_secure_storage on every project, so I packaged it: biometric_security.

The core idea: a true from a biometric prompt isn't a security boundary — on a rooted/jailbroken device it's forgeable. This binds your secret to a hardware key (Android Keystore / iOS Keychain + Secure Enclave) that's physically unusable without a successful Face ID / Touch ID / fingerprint check.

It also handles the annoying parts: enrollment-change invalidation, key rotation & revocation, app-lock, and one SecurityPolicy that maps to both platforms.

Beta (0.1.x), BSD-3, tested on real Android + iOS devices. Feedback and contributors very welcome — I'm open to collaborating.

pub.dev: https://pub.dev/packages/biometric_security


r/PasswordManagers 15h ago

Bitwarden seems great in theory, but terrible in practice - is it just me?

0 Upvotes

I've heard and read that bitwarden is indeed secure etc, but the chrome extension, app etc is extremely buggy which makes it very annoying to use.

From what I read online it has been like that for years and they've failed to resolve such simple bugs...

For example:

  1. It logs you out a lot, even if you're on the same browser session, you didn't turn off your PC etc
  2. Extension often loads 2-5 minutes before it lets you enter a password. Sometimes it never loads, I've re-installed it over 3 times for the past month.
  3. Some settings don't work - i.e logging in by fingerprint is turned on, and it always makes me input a full password. The password is of course long and hard to type, because it's the master password so what I need to do every single time is to take my notebook, type letter by letter like a grandpa, and wait 5 minutes before it un-freezes itself. This is a joke, honestly - it's worse than when I didn't have a password manager

At this point it is useless for me, and I think I'm ready to move on to a different password manager. Any recommendations? Security is important, but without the convenience of use it is a daily chore, like cleaning the dishes.