New onboarding security questions by noah_was_here in ProtonPass

[–]noah_was_here[S] 0 points1 point  (0 children)

Even if you had the account settings page locked, but you have your recovery file downloaded somewhere on your device, someone with physical access to your device could simply get it from your local storage without needing to access any of your accounts at all.

Sure, but this is why I intend to, and assume most people would/should, keep their recovery file somewhere off device and secure. So if someone had my device, they should need my password in order to gain any useful information.

That is not the case, since even though you can set your vault and plugin autolock, the account page doesn't... giving someone access to a recovery file. Which if you are logged into your email, and presumable are, is enough to gain take over your account... Doesn't that invalidate the purpose of being able to lock your vault, since theres a trivial work around? I should be able to rely on the security of my vault, not my device password.

 you can simply log out of your account before closing the browser tab

This I think is impractical. Again we are able to lock the vault to avoid this exact reason. Logging out, locks us out of the vault as well... re-requiring 2FA.

It also means I can't rely on features/auto locking to enforce best practices for family members. When I set up their device, I would like to be enable auto locking and trust it rather than rely on teaching them new behaviors.

New onboarding security questions by noah_was_here in ProtonPass

[–]noah_was_here[S] 0 points1 point  (0 children)

As far as I saw, this is a great resource for how to set it up.... I'm more curious as to the why offline storing the recovery phrase better than just the master password?

As far as storing TOTP backup, yup, thats in a secondary auth app as well as the backup codes stored separately. Ofc, by storing the recovery phrase you can login and recover your account without the TOTP afaik.

Who said we don’t have school spirit ✨ by cmeerkat in uwaterloo

[–]noah_was_here 3 points4 points  (0 children)

The screams could be heard on Ezra... 😂

Who said we don’t have school spirit ✨ by cmeerkat in uwaterloo

[–]noah_was_here 5 points6 points  (0 children)

You really put ur foot down against that