I’m (probably) switching to Proton Pass from Bitwarden because its easier to create email aliases (all in one instead of making an alias with SimpleLogin, then copying that to Bitwarden and making a password there) but I’ve heard people saying not to use Proton Pass to not “put all your eggs in one basket”. Can someone explain what this means?

Thought if there is a way to generate those aliases within Bitwarden (using Proton’s alias not SimpleLogin’s as I’m going to be paying for Proton Unlimited anyways, I don’t wanna pay for SimpleLogin too) I’d appreciate it, as I prefer Bitwarden.

Thank you all :)

EDIT: I understand now. TL:DR: If one service dies you still have the other. Either way, turns out I can just grab my API Key from SimpleLogin and use it with Bitwarden, as thats what Proton uses anyways. Also the Proton Pass extension just shit itsself and I’m not a fan of Proton’s UI so I will be sticking with Bitwarden.

  • xela@lemmy.ml
    link
    fedilink
    arrow-up
    32
    ·
    7 months ago

    If a service is ever compromised, you would have chosen to consolidate information that would lead you to be more greatly vulnerable than if you had spread over multiple services.

  • carzian@lemmy.ml
    link
    fedilink
    arrow-up
    22
    ·
    edit-2
    7 months ago

    A (small) part of not putting all your eggs in one basket is also avoiding vender lock-in. Having your personal email with proton, and your password manager with them makes it very difficult to switch in the future if you need to.

    On a side note, I use anonaddy (now Addy.io). It allows you to create email aliases on the fly. So when I sign up for a new account somewhere, I generally make up some email like “example@my-account.anonaddy.com” for the email and save that right to bitwarden.

    Looks like simplelogin supports the same thing https://simplelogin.io/blog/subdomains/

    PS. Using your own domain name is a great way to avoid vender lock-in =)

  • Simon Müller@sopuli.xyz
    link
    fedilink
    arrow-up
    15
    ·
    7 months ago

    The idea is quite simple. If you put all your eggs into one basket, if that basket breaks, you’re screwed.

    If we put this into context, this would mean that you would, for example, use all of Proton’s services and when Proton does something bad, now your entire suite of services is fucked.

  • cerement@slrpnk.net
    link
    fedilink
    arrow-up
    13
    arrow-down
    1
    ·
    7 months ago

    in the case of technology (specifically anything cloud based * ) – if you have your needs split across multiple services, if one of them goes down / gets hacked / goes belly up, you only lose access to what was stored on that service – if everything is on one service, then you lose access to everything

    * the cloud is just someone else’s computer

  • MagneticFusion@lemm.ee
    link
    fedilink
    arrow-up
    7
    ·
    7 months ago

    If your Proton password EVER gets compromised your entire online entity is leaked now because they have access to not only your email, but every single password and other email that you use. While this is not common, you have to keep in mind that this can lead to years of headache and unrepairable damage to whatever it is about your online identity whether it is your health, finances, political activities, etc.

    However, Proton Pass as a standalone product is excellent. I just would not use it with my main protonmail account, and instead create a completely separate account just for Pass. Good OpSec will always save you when you least expect it.

  • cosmic_cowboy@reddthat.com
    link
    fedilink
    English
    arrow-up
    5
    ·
    7 months ago

    It all depends on your risk tolerance and perceived threat model.

    I would recommend that if you do use Proton Pass in conjunction with your email, keep a backup KeePass file stored locally and in a few other places and update routinely.

    The Proton ecosystem definitely doesn’t fit everyone’s security model, but it is a massive leap compared to what Google and Apple offer.

  • davel@lemmy.ml
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    7 months ago

    I don’t put my passwords in the cloud in the first place, so what it means to me is: keep backups.

  • AnAnonymous@lemm.ee
    link
    fedilink
    arrow-up
    4
    arrow-down
    1
    ·
    7 months ago

    Don’t depend completely on something or someone, if at some point it goes to the fuck you will also go to the fuck…

    That’s basically the main point into that phrase.

  • fluckx@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    7 months ago

    You can have bitwarden auto generate simplelogin emails as well when generating usernames. You just need to fetch an API key from simplelogin :)