The answer is yes, and the TL;DR is not to use them, use 2FA, and not share personal details online (which is hopefully all obvious advice)
cross-posted from: https://lemmy.world/post/12060980
no they are not, just another stupid article from proton. nothing stops you from saying that bwE0FpHb5iPzMZiismyeiTIWhoB*#V8SaD0F3R*SeH was your first pets name.
proton however stops you from disabling otp after setting up multiple security keys, they stop you from putting a pin on your drive app and they stop you from using an +4 digit pin on your mail app.
but yea, the potentially insecure thing they dont even offer is the biggest concernn here 🤦♀️
Nothing stops us enthusiasts from doing that, this article is for a more casual user who might not realise how easy the real answers are for a hacker to discover