ProtonBlog(new window)

Today, we’re happy to announce another significant milestone in the growth of the Proton ecosystem with the launch of the Proton Pass beta for Lifetime and Visionary users. Invites will roll out over the next week, and you’ll receive an email from us at your Proton Mail email address when you’re eligible.

A password manager has been one of the most common requests from the Proton community ever since we first launched Proton Mail. However, while Proton Pass uses end-to-end encryption to protect your login credentials, it will be much more than a standard-issue password manager. This will become clear over the next weeks and months as we prepare Proton Pass for a public launch later this year.

Learn what a password manager is and why you need one(new window)

In 2022, Proton joined forces with SimpleLogin to bring millions of Proton users advanced hide-my-email aliases. Making logins more secure, more private, and easier was a core part of the original vision of SimpleLogin. In fact, Son Nguyen Kim, the founder of SimpleLogin, picked the name SimpleLogin for precisely this reason.

The merger united two organizations with a shared interest in tackling this problem. That’s why the SimpleLogin team, joined by a few engineers from Proton, spearheaded work on Proton Pass.

We’re launching Proton Pass now for two primary reasons. First, joining with SimpleLogin increased our ability to develop a new password manager without impacting efforts on other Proton services. Second, passwords are such sensitive information that an insecure password manager is a risk to the Proton community. 

If an attacker obtains your password (be it through a data breach or hacking your password manager), they can essentially bypass all of Proton Mail’s advanced encryption. Protecting your passwords properly requires a high level of competence with encryption and security, which few organizations have. We’ve always been worried about the risk posed by a major password manager breach, which unfortunately became a reality with the recent hack of LastPass(new window).

Raising the bar on security

Proton Pass is not just another password manager. It’s perhaps the first one built by a dedicated encryption and privacy company, leading to tangible differences in security. For example, while many other password managers only encrypt the password field, Proton Pass uses end-to-end encryption on all fields (including the username, web address, and more).

This is important because seemingly innocuous bits of information (such as saved URLs, which many other password managers don’t encrypt) can be used to create a highly detailed profile on you. For example, if an attacker can see that you have passwords saved for an account with Grindr, gop.com, or even a manga fan site, they’ll know a lot about you as a person, even if they can’t actually access your accounts. 

Cryptographic details matter, and Proton Pass uses a strong bcrypt password hashing implementation (weak PBKDF2 implementations have made other password managers vulnerable) and a hardened implementation of Secure Remote Password (SRP) for authentication. Proton Pass is also a password manager that includes a fully integrated two-factor authenticator (2FA) and supports 2FA autofill. This is meant to make it easier to use 2FA everywhere since it’s one of the most effective safeguards for your online accounts.

Read the Proton Pass security model(new window)

Like every other Proton service, Proton Pass will be open source and publicly auditable upon launch, so anyone can independently verify our security features and their implementation.

What’s next?

After fielding thousands of requests over the years, we’re glad to deliver a password manager to the Proton community. The Proton Pass beta is available on iPhone/iPad, Android, and desktop (browser extensions are available for Brave, Chrome, and Firefox)

With some of the features we have planned, we think that Proton Pass will be a milestone for password managers in general and redefine the role password managers play in our online lives. We look forward to receiving your feedback in the coming days and weeks and getting Proton Pass out to everybody as soon as possible. Over time, we will add more details to the new Proton Pass website: proton.me/pass.

If you have feedback, you can email us directly at pass@proton.me or let us know on Twitter @ProtonPrivacy(new window) or Reddit at reddit.com/r/ProtonPass(new window).

Update April 28, 2023: Added that the Proton Pass browser extension for Firefox is now available.

Protect your passwords
Crear una cuenta gratuita

Artículos relacionados

passwordless future
en
  • Lo básico sobre privacidad
With the advent of passkeys, plenty of people are predicting the end of passwords. Is the future passwordless, though? Or is there room for both types of authentication to exist side-by-side?  At Proton, we are optimistic about passkeys and have int
en
At Proton, we have always been highly disciplined, focusing on how to best sustain our mission over time. This job is incredibly difficult. Everything we create always takes longer and is more complex than it would be if we did it without focusing on
is icloud keychain safe
en
  • Lo básico sobre privacidad
If you’re on any Apple device, you’re familiar with the iCloud Keychain, the Apple password manager. It’s a handy tool that stores passwords for you and helps you manage your logins.  For a program that stores all your most sensitive data in one pla
en
We recently announced that Proton Pass now supports passkeys for everyone across all devices. Universal compatibility is a unique approach to implementing passkeys, unfortunately. Even though passkeys were developed by the FIDO Alliance and the Worl
How to upload and share private video
en
Your private videos are for your eyes only. However, not all cloud storage services are good at storing videos securely, let alone privately. In this article we explain what you can do to keep file sharing companies from having access to the videos y
en
Many email services, citing security reasons, require a phone number for identity verification. This creates an unfortunate paradox in which you must give up a highly sensitive piece of personal data to Big Tech. But there are simple ways to create
Can you password-protect a folder in Google Drive?
en
Protecting a folder with a password is a simple yet effective way of securing files. You may wonder whether you can password-protect a folder in Google Drive. We explain what access controls Google Drive offers and what you can do to improve your sec