It grinds my gears when password managers bundle 2FA/MFA without pointing out how this weakens the security of it, or discussing mitigations.
"Proton Pass makes 2FA easier with an integrated authenticator that stores your 2FA codes and automatically displays and autofills them."
Is it really multiple factor auth if you're using the same device for the password and automatically filling in the token? It's not a unique failure of Proton Pass but, people reading this should rightly be sceptical and this is a significant failing.
When I read their audits on Proton Drive, I see that the web page claims the PDF is end-to-end encrypted. But the link with the key in the URL hash is public. It's a poor demonstration of their technology. When I see the defects that were found by the audits, it doesn't leave an amazing impression.
It's great that they have an open source client and do open audits though.
Claiming it's open source, does come across as hype without a server too though.
Overall this is a welcome thing but it's very rough around the edges, I wouldn't feel it's a compelling offering yet with these big issues.