I’m using proton services and now the Pass password manager as well. I never let any managers save my bank data such as credit cards or login credentials being sort of afraid to.

Is this concern still valid? when using a manager like Proton Pass that has e2e encryption? what’s your opinion on holding bank data in managers like this?

  • ddnomad@infosec.pub
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    11 months ago

    As a rule of thumb, do not put all your eggs into one basket. No software is infallible and vulnerabilities can be uncovered and exploited in both open and closed sourced applications.

    That’s being said, as long as you don’t store all information necessary for a successful login in your password manager, you should be fine.

    So storing credentials for your bank account is fine, as long as it is also protected by MFA and you do not use the same password manager for handling that.

    You can store PIN codes from your debit cards in the password manager as long as you do not store card number / expiration / CVV2 there too.

    Personally, I keep passwords in a password manager, MFA tokens in a separate authenticator, MFA recovery codes go to FIPS 140-2 certified encrypted USB sticks (3 separate copies). I do store debit card PIN codes in my password manager, but only alongside the last 4 digits of the card number.