Granted you need local access to modify the config, but generally the .kdbx is stored (securely) on some shared environment. Grabbing that would mean you could export passwords at your leisure in this setup?
Granted you need local access to modify the config, but generally the .kdbx is stored (securely) on some shared environment. Grabbing that would mean you could export passwords at your leisure in this setup?
Keepass will (by default) not ask for the password a second time before exporting - but you have to decrypt the database once before it can be exported.
So this is not a risk if your threat model is "attacker obtains a copy of my .kdbx", but it is a risk if your threat model is "attacker can modify .kdbx without me noticing, and can access my local computer or a mounted network disk to read the exported passwords".
If an attacker can modify your local install, you've lost anyway....
No, the threat model is "the attacker can modify config file", which for default installation also means "the attacker can modify the executable".