On the Security of Password Manager Database Formats (2012) [pdf]
cs.ox.ac.uk
cs.ox.ac.uk
Problem. In their paper 'On The Security of Password Manager Database Formats', P. Gasti and K. B. Rasmussen have presented attacks on the KDB and KDBX file formats based on unauthenticated header data. For KDB, this issue has allowed silent data removal attacks. For KDBX, the issue has allowed silent data corruption attacks. Both were minor security issues (confidentiality was not compromised).
Status. Header data authentication has been introduced for both KDB and KDBX in KeePass 1.24 and 2.20, in order to prevent the attacks. Also see the release notes KeePass 1.24 and 2.20 Header Authentication. P. Gasti and K. B. Rasmussen published their paper in a responsible disclosure process, and the defenses in KeePass have been implemented before the issues were presented to the public.
I think KeePass with the key file option (not readable by user accounts, run KP as admin) is the best solution on Windows I've found.
http://lifehacker.com/lastpass-hacked-time-to-change-your-ma...
The only scenario I see this happening is if, upon the creation of a new master password, PasswordSafe encrypts the header (with the old password). This way, when the user enters their new password, PS uses it to decrypt the header, and then uses the old password (stored in the header) to decrypt the database. This would make it easy for someone with access to the old password and the database to simply decrypt it.
Is this how it works? I can't think of any other way it would be able to not re-encrypt the database with the new password. Plus the lingo/acronyms in the paper are going a bit over my head.
"2.6 B1 and B2 are two 128-bit blocks encrypted with Twofish [TWOFISH] using P' as the key, in ECB mode. These blocks contain the 256 bit random key K that is used to encrypt the actual records. (This has the property that there is no known or guessable information on the plaintext encrypted with the passphrase-derived key that allows an attacker to mount an attack that bypasses the key stretching algorithm.)"
http://passwordsafe.sourceforge.net/
Available for:
- Windows
- Linux
- Android
Chrome has since implemented OS-level security, the SQLite database contains ciphertext instead of plain passwords.
Is this encryption directly related to my Windows password? Can I transfer the "Login Data" database to another PC with the same password? Or is my password only a passphrase for a longer key?
Finally, our works shows that it is indeed possible to construct a format that provides security, usability and low computation and storage overhead, using standard cryptographic tools.