I’m (probably) switching to Proton Pass from Bitwarden because its easier to create email aliases (all in one instead of making an alias with SimpleLogin, then copying that to Bitwarden and making a password there) but I’ve heard people saying not to use Proton Pass to not “put all your eggs in one basket”. Can someone explain what this means?

Thought if there is a way to generate those aliases within Bitwarden (using Proton’s alias not SimpleLogin’s as I’m going to be paying for Proton Unlimited anyways, I don’t wanna pay for SimpleLogin too) I’d appreciate it, as I prefer Bitwarden.

Thank you all :)

EDIT: I understand now. TL:DR: If one service dies you still have the other. Either way, turns out I can just grab my API Key from SimpleLogin and use it with Bitwarden, as thats what Proton uses anyways. Also the Proton Pass extension just shit itsself and I’m not a fan of Proton’s UI so I will be sticking with Bitwarden.

  • xela
    link
    fedilink
    arrow-up
    32
    ·
    2 months ago

    If a service is ever compromised, you would have chosen to consolidate information that would lead you to be more greatly vulnerable than if you had spread over multiple services.

  • carzian
    link
    fedilink
    arrow-up
    22
    ·
    edit-2
    2 months ago

    A (small) part of not putting all your eggs in one basket is also avoiding vender lock-in. Having your personal email with proton, and your password manager with them makes it very difficult to switch in the future if you need to.

    On a side note, I use anonaddy (now Addy.io). It allows you to create email aliases on the fly. So when I sign up for a new account somewhere, I generally make up some email like “example@my-account.anonaddy.com” for the email and save that right to bitwarden.

    Looks like simplelogin supports the same thing https://simplelogin.io/blog/subdomains/

    PS. Using your own domain name is a great way to avoid vender lock-in =)

  • Simon Müller@sopuli.xyz
    link
    fedilink
    arrow-up
    15
    ·
    2 months ago

    The idea is quite simple. If you put all your eggs into one basket, if that basket breaks, you’re screwed.

    If we put this into context, this would mean that you would, for example, use all of Proton’s services and when Proton does something bad, now your entire suite of services is fucked.

  • cerement@slrpnk.net
    link
    fedilink
    arrow-up
    13
    arrow-down
    1
    ·
    2 months ago

    in the case of technology (specifically anything cloud based * ) – if you have your needs split across multiple services, if one of them goes down / gets hacked / goes belly up, you only lose access to what was stored on that service – if everything is on one service, then you lose access to everything

    * the cloud is just someone else’s computer

  • cosmic_cowboy@reddthat.com
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 months ago

    It all depends on your risk tolerance and perceived threat model.

    I would recommend that if you do use Proton Pass in conjunction with your email, keep a backup KeePass file stored locally and in a few other places and update routinely.

    The Proton ecosystem definitely doesn’t fit everyone’s security model, but it is a massive leap compared to what Google and Apple offer.

  • davelA
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    2 months ago

    I don’t put my passwords in the cloud in the first place, so what it means to me is: keep backups.

  • AnAnonymous@lemm.ee
    link
    fedilink
    arrow-up
    4
    arrow-down
    1
    ·
    2 months ago

    Don’t depend completely on something or someone, if at some point it goes to the fuck you will also go to the fuck…

    That’s basically the main point into that phrase.

  • fluckx@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    2 months ago

    You can have bitwarden auto generate simplelogin emails as well when generating usernames. You just need to fetch an API key from simplelogin :)