They're proposing that the author change the application so that it pops up a dialog whenever the KeePass application is directed to export the decrypted document.
I'm not a KeePass dev, but with a bit of search and pattern recognition, it looks like this export feature is implemented in KeePass-2.53-Source\KeePass\DataExchange\ExportUtil.cs:
public static bool Export(PwExportInfo pwExportInfo, FileFormatProvider fileFormat,
IOConnectionInfo iocOutput, IStatusLogger slLogger)
{
PwDatabase pd = pwExportInfo.ContextDatabase;
...
// [IF CONFIG FILE DOESN'T ALLOW EXPORTING WITHOUT KEY]
if(!AppPolicy.Current.ExportNoKey && (pd != null))
{
// [THEN ASK FOR IT AGAIN]
if(!KeyUtil.ReAskKey(pd, true)) return false;
}
...
Stream s = (bFileReq ? IOConnection.OpenWrite(iocOutput) : null);
try { bResult = fileFormat.Export(pwExportInfo, s, slLogger); }
finally { if(s != null) s.Close(); }
}
They're complaining that an evil maid attack can turn off `AppPolicy.Current.ExportNoKey` and set it up to export the document silently. They want it to read: public static bool Export(PwExportInfo pwExportInfo, FileFormatProvider fileFormat,
IOConnectionInfo iocOutput, IStatusLogger slLogger)
{
PwDatabase pd = pwExportInfo.ContextDatabase;
...
// [ALWAYS ASK FOR MASTER PASSWORD AGAIN BEFORE EXPORTING]
if(!KeyUtil.ReAskKey(pd, true)) return false;
...
Stream s = (bFileReq ? IOConnection.OpenWrite(iocOutput) : null);
try { bResult = fileFormat.Export(pwExportInfo, s, slLogger); }
finally { if(s != null) s.Close(); }
}
They've even gone so far as to ask the author to create a "KeePass Essentials" version, which removes the export feature, plugins, and configuration files entirely:https://sourceforge.net/p/keepass/feature-requests/2704/#b3c...
But they ignore that with write access to the application directory, an attacker can just change the application to not show that dialog at all.