3 ms·
This reply was sufficiently aggravating to make me go do some research. Here's a thread[0] from last year bringing up some issues with KeePass2 code. It also l
by gnoway 10y ago
This reply was sufficiently aggravating to make me go do some research.
Here's a thread[0] from last year bringing up some issues with KeePass2 code. It also links to an audit by some group that appears to be involved in information security for the French government[1]. It's in French. The HN comment asserts the audit found KeePass2 2.10 portable to be safe; I don't comprehend French so I don't know what the audit says.
The documentation[2] specifies that the default KDF uses 6000 rounds of AES, although that is configurable, so presumably 'hahaha...extremely fast cracking speeds' could be improved to 'fast cracking speeds' or even 'moderate to slow cracking speeds'.
KeePass has had one published vulnerability[3]; it applies to KeePass v1.17, so should not be a concern anymore.
I will continue to use KeePass2.
[0] https://news.ycombinator.com/item?id=9727297
[1] http://www.ssi.gouv.fr/uploads/IMG/cspn/anssi-cspn_2010-07fr.pdf
[2] http://keepass.info/help/base/security.html#secdictprotect
[3] https://www.cvedetails.com/product/23054/Keepass-Keepass.html?vendor_id=12214
- deleted 10y ago[deleted]