Original keepass downloads are hosted on sourceforge which has not had the best history of integrity the way I see it.
Original keepass downloads are hosted on sourceforge which has not had the best history of integrity the way I see it.
https://sourceforge.net/blog/brief-history-sourceforge-look-...
* Being open source protects against a malicious developer. Otherwise there is nothing preventing him to build the binary with a different source, and send the passwords to his own server.
* Signed code archive prevents against a compromised hosting site.
Then you're not going to the good people. Stop going through intermediaries, go straight for the source (package specific issues on Ubuntu must be reported to Ubuntu -like python not recognizing a new module-, but bad code inside the package must be dealt with with upstream).
> Half the time the developers are extremely resistant to changes and believe the change is wrong/unnecessary, or the current state is already correct, or that the changes are too big and/or not worth it, [...]
That's why I take the habit of jumping on IRC first, talking with devs a bit and trying to understand why I find a specific piece of code problematic.
I was trying to add support for i686 on an AUR package I maintain; quickly dismissed "we don't support i686 anymore anyway, just slap comments in your PKGBUILD and ship it".
I was working with the btrfs(8) util, which has the most horrific interface ever designed; "OK, we're not hostile to a new interface design, but you'll have to provide a comprehensive explanation of what you want and how it should behave".
And finally, documentation usually gets merged real fast (recently on cbsd(8) and nextcloud).[0][1]
I think 7zip has a way for you to check the hash signature with just a right click on the file so thats dandy
Not implying you are but there is plenty of software where that is how they expect users to verify the integrity of the download. Useful for checking bit errors, but in the event that someone has replaced the binary then they could probably also replace the checksum...
I was thinking about all the times I had to download a windows ISO. And how microsoft had openly published what the checksum values were so I could verify this after downloading from a 3rd party
I would need to do more research here you make a good point
You're not really going to get around having to install "something" to sync your passwords if you want to have your passwords synced
You could use something like Syncthing if you just don't want to trust any company with your data
Otherwise, I cant really suggest a solution either
Sorry, I hope it's clear now.
> You're not really going to get around having to install "something" to sync your passwords if you want to have your passwords synced
Huh? This is obviously wrong; I'm doing literally this with KeePass. I haven't installed anything, and it has a plugin to sync directly with Google Drive that doesn't mess with or care about anything in the rest of the system.
Additionally, I was not personally aware of any way to "sync directly" other than using the Google Drive desktop client (https://www.google.com/drive/download/) and storing the database file in the synced folder. It sounds like you're saying Keepass has some direct integration with Google Drive?
All of that said, I am really not invested in this issue - I use multiple cloud sync services and it doesn't bother me.
Indeed it has a plugin for this, yeah. That's exactly what I'm saying. https://sourceforge.net/projects/kp-googlesync/
I created a keepass/syncthing directory somewhere inside my home directory, and I told Syncthing to sync only that directory. And the directory only contains the Keepass database plus a few Syncthing log files and such.