Proton Authenticator: free open-source two-factor authentication app

Discussion in 'privacy technology' started by stapp, Jul 31, 2025.

  1. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    28,531
    Location:
    UK
    https://www.ghacks.net/2025/07/31/p...ee-open-source-two-factor-authentication-app/
     
  2. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    28,531
    Location:
    UK
  3. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,649
    Wow not a good way to start things off. :(
     
  4. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,313
    Location:
    USA
    Not great but could be worse. I'll keep an eye on it. I may find a use for it if they don't have any more incidents like this.
     
  5. Palancar

    Palancar Registered Member

    Joined:
    Oct 26, 2011
    Posts:
    2,537
    As a step up in sign in security I strongly prefer to use my TOTP auth offline using a YubiKey. Very fast an no authentication numbers travel over the internet so there is nothing to "pick off" by an experienced hacker. I don't use Protonmail much but I do have Proton Drive to hold things for me.
     
  6. Quassar

    Quassar Registered Member

    Joined:
    Oct 19, 2011
    Posts:
    262
    Location:
    Poland
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,224
    Location:
    The Netherlands
    To clarify, it didn't affect the desktop version right? I think I might give it a try, and perhaps it's a good idea to block it from getting network access?
     
    Last edited: Aug 24, 2025 at 6:45 AM
  8. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,313
    Location:
    USA
    I couldn't tell you, haven't actually used it. Just watching and waiting to see if I decide to do so.
     
  9. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,224
    Location:
    The Netherlands
    It's a bit confusing, I now read that Proton says that logs ''always store TOTP secrets in plain text'' but never send them unencrypted to the server? So they are saying that if a hacker gets access to your device you will always have a problem? It's not clear if they fixed this issue or not, but I don't think I'll be using their desktop app anytime soon.
     
  10. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,313
    Location:
    USA
    Very likely but in that situation you already have a bigger problem. From what I have seen I don't think this will be a product that is in my short term plans.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.