An exploit can reveal your KeePass master password in plaintext
pcworld.com
pcworld.com
Still, it does require the attacker to either have root on your machine or physical access to your disk. If the attacker has root on your machine, it's game over anyway. You can mitigate the threat of recovering the password from your disk by using disk encryption.
Even when I hear about KeePass vulnerabilities, they're always substantially less severe than the attacks we see on LastPass and other web-hosted password managers where an attacker can exfiltrate bulk credentials at once by compromising a server.
Same with the hibernation file, Bitlocker will require your password again (if it has one) on resume.
This is also the reason you always use full disk encryption: because you don't know what sensitive content might get sprayed into your files.
How does Windows enforce signing these days? If I run "keeppass_compiled_by_attacker.exe" do you get some sort of prompt?
Without it, even with local user access it's kind of "game over"; there's nothing preventing the attacker from replacing the desktop or start menu shortcut to their own wrapper or own version which steals the master password. No modification of system files or special access to memory or whatnot needed.
And even with it, many users will likely just click through the warning.
On Linux and other Unix-like system this is certainly an issue.
Sometimes I think people are a bit too focused on these kind of complex and advanced exploits, while in reality it turns out you often don't need them to do malicious stuff.
Yes, smartscreen
Great.
Hardware password managers exist and are not so inconvenient.
Full disclosure, I sell a paid KP2 plugin to soft lock the UI. (It won't protect memory or dumps but does prevent naive snooping.)
> KeePass 2.X uses a custom-developed text box for password entry, SecureTextBoxEx. This text box is not only used for the master password entry, but in other places in KeePass as well, like password edit boxes (so the attack can also be used to recover their contents).
> The flaw exploited here is that for every character typed, a leftover string is created in memory. Because of how .NET works, it is nearly impossible to get rid of it once it gets created. For example, when "Password" is typed, it will result in these leftover strings: •a, ••s, •••s, ••••w, •••••o, ••••••r, •••••••d. The POC application searches the dump for these patterns and offers a likely password character for each position in the password.
I work from home. I feel much safer with my password written on a piece of paper than with a password manager. God forbid the password manager is cloud-enabled.
God help her if she needs to log into her email after I'm dead.
But he also wrote his own password manager: https://www.schneier.com/academic/passsafe/
Having all your passwords on a piece of paper could be safer than a password manager, but it's so inconvenient to store a hundred different random passwords this way that people simply won't do it and will reuse passwords. So if password managers get people out of the password reuse trap, they're a net gain in security, that far outweighs all the password manager risks.
The first part is generated from the website/system.
The second part is the code phrase - this is the part that I need to remember (and for passwords I use rarely - that I need to write down).
The 3rd part is changing predictably every time the system is forcing me to change my password.
The stuff I am writing down I'm writing using a script I created long ago for my TTRPG. It's not hard to decrypt if you had whole pages of it, but it's not a trivial substitution. I used it as a puzzle in my D&D campaigns for friends (including people with PhD in CS and MA in math) and they couldn't solve it over several weeks without a lot of hints. I don't think a random guy who broke in will solve it looking at a piece of paper with 10 or 30 symbols.
No worries about the cloud that way, and you're free to use whatever means you're most comfortable with to handle updating databases between devices, but it does leave you on the hook for keeping and maintaining regular backups.
https://www.amazon.co.uk/password-book/s?k=password+book
Often people will mock them on social media for the likes, but actually in some circumstances ... I think they are the best option.
(They can be made stronger too - tell people to remember one word that they put in front of all their passwords but don't write down, like "cat". Then anyone who steals the book can't use it but they are still using different passwords for each site.)
>All existing versions of KeePass 2.x (e.g., 2.53.1) are affected. Meanwhile, KeePass 1.x (an older edition of the program that’s still being maintained), KeePassXC, and Strongbox, which are other password managers compatible with KeePass database files, are not affected according to vdohney.
The author of the software seems to be cooperating to release a fix, I would think making it public would help people who would exploit this maliciously.
It need admin access to dump process memory. Those can do that are doing it already.
- Only compare the crypttexts, never the plaintexts
- For input use a modified input field to minimize the time the plaintext kept in memory then wipe the memory used by the input field before releasing the memory
- If possible ask the OS never to swap the memory used by the input field