KeePassXC: Beware of unofficial Microsoft Store listing
twitter.com
twitter.com
This is a good example of how "app stores" tend to provide a false sense of security about what you're really downloading. There are clearly failures in terms of vetting what's there and towards ensuring that the user is actually getting what they think they're supposed to be getting.
Perhaps the "app store" model is still generally better than downloading executable code from completely random sources (nobody should be doing that), but I'm not sure there's anything more reliable (and also "secure") here than downloading a piece of software from its official source (such as from a server under the domain of the known publisher), verifying hashes/signatures, and leaving out as many intermediaries as possible who often have motives not fully aligned with the software user. Of course, this would require users to possess and be willing to use some knowledge of basic software and data hygiene, but it seems that along the way we have somewhat given up on that and so now we're stuck trusting these intermediaries usually much more than they ought to be trusted.
Edit: spelling
1. https://play.google.com/store/apps/details?id=com.screenmirror.forvizio.smarttv.screenshare
2. https://play.google.com/store/apps/details?id=com.smartview.castto.screenmirror.appfor.miracast
3. https://play.google.com/store/apps/details?id=com.smartview.screen.mirroringIt was one of the failure cases in EV certificates back when browsers briefly thought "maybe it would be a good idea to highlight the website's legal name in the URL bar". Find the right jurisdiction and you can get any sort of "legal name" you want, including things that should have been "obviously" counterfeit like a "Facebook.com, LLC" and were perfectly good for phishing.
/s
`winget upgrade —-all` from a command line (assuming your Windows is reasonably up-to-date, otherwise, https://github.com/microsoft/winget-cli to get the latest release manually)
This is a result of the failed strategy to explicitly not curate it and get as many apps as possible, no matter how bad they are.
I'd like to know what goes on inside of Microsoft for them to keep following strategies that appear doomed to fail from the start.
1. https://en.wikipedia.org/wiki/Universal_Windows_Platform_app...
Seems the publisher probably skates on a few other free software projects like filezilla & vnc. I assume the free apps are simply spyware.
Since I am a happy keePassXC user I would definitely donate time/money/both to push a proper release for the store if someone is interested
Microsoft makes no effort to indicate that evidently the buyer must beware entirely, and that appearance in the appstore means absolutely nothing in regards to it being spam, spyware, or legally 'counterfeit'. This is likely legally speaking risky - they're selling illegal goods, assuming this is a copyright violation which it probably is. Microsoft is guilty of the crime of fencing by doing this. I know that in The Netherlands, that crime (in dutch, 'heling') is a criminal offense. You need to be doing it intentionally, but given that they have now been notified, give it a few days and I'm pretty sure you really could just get em criminally sanctioned.
"Oh but I did not know" as a defense only gets you so far in court. It should get you absolutely nowhere in the court of public opinion, especially given that microsoft is marketing their app store as the opposite.
Apple and google are also guilty of this stuff; wanting all the cash and harping on and on about how much value they add by being the guardian of it all, and then doing an epically horrible job on guarding it.
It's so depressing that the obvious problem (the operators of these app stores are natural monopolists within that context - and monopolists tend not to focus on actually doing a good job because no competition) and that it then almost immediately goes that badly.
Recently I had to use windows. As a linux user for 2 years my first instinct is to install WSL and make the entire thing somewhat more palatable.
I Google the docs, install Debian through `wsl` command, start it through windows terminal.
It's still debian stretch aka "oldoldstable", that's the only version wsl command lists.
I googled the issue and apparently you can install the same thing through MS store to get latest stable. This has to be a Stack Overflow answer with 5 votes, not MS docs website.
So I search debian again, there are one or two 'app' listings, but no checkmark or verification on publisher. All apps look alike.
It doesn't help they show reviews, but there will be max 20-30 reviews even for legitimate apps. These reviews are probably written by people like me whose first language isn't English. But at the first sight they make the app seem even more suspicious.
If I recall correctly, unlike Google Play Store, MS store doesn't list the download count either. Not that it would help much in this case of a relatively obscure installation, but would at least help against copycats.
VS code is also from MS, Store is also from MS, what a difference!
Meanwhile there is a bullet point in policy 10.1.1 that is almost directly what you are asking for, it is currently: "Your product must not claim to be from a company, government body, or other entity if you do not have permission to make that representation."
I certainly believe that "other entity" covers most open source organizations that aren't specifically companies already (or wrapped in a Foundation/Conservancy that acts as a "corporate parent").
The problem can't be solved with just policies though, the real key is enforcement: the fake listings from non-maintainers of open source need to be reported to be enforced. That likely means review time by staff. Tweets like the one linked here today can be calls to arms to submit user reports to help Microsoft know there's a possible problem here. Hopefully policies get enforced (eventually).
You need to specify that you are using Visual C++ Redistributable? That's wild. I thought MS Store should take care of such dependency and install it automatically.
But it's good practice to find the publisher website / repo and then click on Play Store link.
- browser plugin is okay and I have no problems with it, but when it comes to password manager hostile login setups it isn't quite as good as some commercial solutions
- in some HiDPI setups with fractal scaling there had been buggy behaviour, probably fixed by now, probably had not been problem with most HiDPI setups either
- I haven't tried some of the integrations (e.g. SSH Agent).
Anyway I'm quite happy with it.
I think for some people it's probably pretty great, or for storing not-website-passwords it's probably also good, though there are probably simpler to manage tools for "terminal/server" use like `pass`.
strongbox has pretty intelligent support for maintaining a cached copy, and the sync support has always worked as expected for me there. The keepass format does store last-changed date so it is relatively trivially possible to synchronize a database (assuming you can decrypt/open it ofc).
if you need it on the go, VPN tunnel back, or again, Strongbox has good native support for dropbox sync or onedrive etc, can't specifically vouch for it but Strongbox seems pretty competent.
Guess modifying the database on 2 different machines simultaneously might cause a conflict, never tested it though.
I use it on windows, linux, and mac.
There is a Firefox add-on that works quite well and for other applications copy-paste with automatic clipboard clearing is good enough. It can't be scripted like Pass can be, but for regular use it's fine.
TOTP
SSH agent
browser integration
Switching to XC made managing, updating, and installing things much easier.
The browser plugin is good too. It rarely malfunctions, and when it does it is on user-hostile websites, like the Office365 login pages.
Of course they could still just put it up as `KeePassSX` or something, but it gives the creators a bit of ground to stand on?