MitM Attack against KeePass 2’s Update Check
bogner.sh
bogner.sh
Well the indirect costs of not fixing it just got a lot bigger. Now a lot of people will realize that their passwords are not as safe as KeePass claims they are and will switch to a different product. So this way they loose both their money and their users' trust. Not a very good business decision.
Not really.
Just check the package you download is signed by the developer and you're safe. Authenticode signatures are present on all KeePass releases on Windows and most Linux users probably get it from a distro package manager anyways.
Anyway, I'm not quite sure on the differences between them but I've been using KeePassX for years and recommend it thoroughly (as long as you're not looking for a easily synced or multi-user product): https://www.keepassx.org/
Both of the websites for PuTTY (www.putty.org and www.chiark.greenend.org.uk) are also non-encrypted. At least the downloads are hosted on a third server (the.earth.li) which does use HTTPS and 2048-bit GPG signatures are provided.
Unfortunately there is no KeePassHttp support yet, so you can't hook it up to your browser, but there is a fork available with full support.
An alternate solution is to keep a single password database on a FAT32 formatted partition or thumbdrive which is readable from both Operating systems.
1) have nearly the same level of support for defining complex password generation rules
2) have support for saving said custom password generation as a profile
So, KeePass + wine it is until I have a better alternative. :)What I have works for me very well although I will admit that the v2 database format is supported well enough these days that I could migrate.
Having used both for several months, I found the only workable option for myself was converting the database to KDB 1.x and using KeePassX.
I looked at KeePassX several years ago but it didn't have as many security features as KeePass. For example, KeePass supports entering the password via secure desktop where KeePassX didn't.
Both were closed, with reasons like "this is a bug in .NET", "this is a bug in Windows". Maybe they were, but somehow other applications didn't expose them. The bugs were annoying, and if it were my software I would have fixed them somehow, even if they were not my fault.
Long story short, the author gave me a bad impression, the kind of "know it all, know it best" attitude. So his refusal to fix this MITM problem doesn't surprise me one bit.
So any possible attack against KeePass would as most cause the notification dialog to appear saying there's a new version.
anyway, the author found a solution by signing the text file that the update checker looks at. IMO, that's a superior solution to HTTPS. He's posted a statement on the KeePass website. http://keepass.info/help/kb/sec_issues.html#updsig
The indirect costs of switching to HTTPS (like lost
advertisement revenue) make it a inviable solution.
How does HTTPS result in lost ad revenue?Or just sign the updates and version information.
I'm baffled.
I completely understand the need to support the project financially, but this answer leaves me feeling very uncomfortable.
I've seen several open source systems that share on GitHub such as PadLock but have yet to be able to test these to compare to Roboform. Considering how cheap I was able to pick up Roboform to (as a college student I got 4 years for 1) I really haven't seen the urge to switch considering on how universal Siber System's Roboform does on multiple systems.
Even though this can also be a downfall if the developer's slack on one system, I have been satisfied with these guys since I started using them so many years ago and really haven't found many complaints.
edit My entire reasoning for posting was that while I'm very familiar with Roboform my experience with KeePass was always lacking compared to others.
But the excuse of the dev is bogus in any case. In is trivial to have that single file transferred via HTTPS. His ad revenue excuse makes me thing something fishy is going on here.
https://sourceforge.net/p/keepass/discussion/329220/thread/a...
Anyone know any good password managers that have web login and support U2F? Lastpass does not :(
This doesn't entirely make sense. I'm sure it's possible to serve adverts on a HTTPS page, and let's encrypt is hardly expensive
Yes, you can, but you lose a tremendous amount of ad revenue and a number of ad providers still don't support HTTPS.
Too many ad buyers don't have https support, so the number of bidders for the ad space is lower, meaning a lower price per ad.
Use 1password and pay $5 a month if you want the right to complain.
Updates themselves are signed packages. While it's not ideal, careful users do gain value in an open, free, and mature solution.
Full disclosure: I sell a plugin for KeePass 2.
It is not free software, it's proprietary. Please don't use the phrase "free software" in this context, as it confuses people. It has a very specific meaning in the context of software.
In the context of software it can also mean FOSS, but just because we're talking about software doesn't mean we suddenly lose the 'no cost' meaning.
Why do you say it's proprietary?
Well certainly those advertisers will leave along with the user base. This sort of silly attitude is what keeps a lot of people from using free software to begin with.