3 ms·
Did you see that Keepass introduced fixes to the issues raised in that paper before it was released, thanks to the responsible disclosure by the authors? http:/
by mpettitt 11y ago
Did you see that Keepass introduced fixes to the issues raised in that paper before it was released, thanks to the responsible disclosure by the authors? http://keepass.info/help/kb/db_headerauth_upg.html http://keepass.info/help/kb/db_headerauth_upg.html
- banku_brougham 11y agoNo I didn't see that the authenticated header which was called out as the source of the vulnerability in the paper has been fixed in the 2.20 version, though I should have. Thanks for pointing that out. I'm testing KeePassX now, and it seems ok. However usability is a bigger criterion than I originally thought, because all the copy/paste of username and login is more effort than just memorizing and typing by hand. In fact I've memorized the credentials of the 5 accounts I'm testing it with. KeePassX has a timed lockout function, which is excellent. However unless I quit the browser I will remain logged in to the accounts even after computer sleeps. I would prefer to require another master password confirmation to access accounts after leaving my computer and returning and authenticating the machine. This is a new criteria I would like to add: re-authenticate master password after inactivity/sleep. This would be ideal, in the unlikely event that my employer fires me and takes my laptop away - I don't want IT admin to be able to log in to the machine and access my Evernote, gmail, or other accounts. It looks like KeePass/KeePassX cannot address this, probably would require a browser extension. Maybe I should consider the LastPass/Dashlane model, I think they offer this functionality. Also, I won't use rando Chrome extensions like Log Me Out, though it would provide the needed functionality. I would consider opening the package and rolling my own Log Me Out chrome extension. That + KeePassX would solve my problems, except for the copy/paste usability issue.
- mpettitt 11y agoThe Windows version has an autotype feature - not sure if that has made it to the ports though. It's also not as smooth a flow as Lastpass, since there is a context switch between browser and password manager (although I seem to remember that there used to be an extension offering Lastpass style access to Keepass for Firefox, possibly called KeeFox, or FoxPass?). I don't think any distinct software could automatically log out of sites - it would presumably come down to deleting cookies on sleep (or relying on the sites to have sensible session expiry times) - so I'm not sure that the password manager is the right tool for that. A password manager would protect the passwords for your accounts, but that's not the same as sessions for your accounts.