4 ms·
"Received response from Dominik Reichl: The vulnerability will not be fixed. The indirect costs of switching to HTTPS (like lost advertisement revenue) make it
by crypt1d 10y ago
"Received response from Dominik Reichl: The vulnerability will not be fixed. The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution."
Well the indirect costs of not fixing it just got a lot bigger. Now a lot of people will realize that their passwords are not as safe as KeePass claims they are and will switch to a different product. So this way they loose both their money and their users' trust. Not a very good business decision.
- Animats 10y agoRight. This is a security product. Any security product that makes things worse (and there are all too many of them) has no right to exist.
- deftnerd 10y agoThat response is crazy. If he's so set at keeping the homepage http, then make a download.keypass.com site and keep the downloads on there, with https required.
- 3pt14159 10y agoEh. Still vulnerable to HSTS attack. To me HTTPS without HSTS is only protection to programmers. To the public, HTTPS without HSTS protection is essentially useless against MITM attacks.
- draw_down 10y agoMaybe, maybe not. People might not notice or care. (Of course I agree that this is a poor decision security-wise.)
- EpicEng 10y agoSure, but it seems as though the type of person who would use KeePass in the first place is the sort who would care.
- artursapek 10y agoWhy would switching to HTTPS cost him any advertising revenue?
- tibiapejagala 10y agoSee https://news.ycombinator.com/item?id=11803716 https://news.ycombinator.com/item?id=11803716 from yesterday
- Buge 10y agoThat's if they switch the entire site to https. They could just switch the update check to https and have no problems with ads (although it would be admittedly less secure).
- ultramancool 10y ago> Now a lot of people will realize that their passwords are not as safe as KeePass claims they are and will switch to a different product. Not really. Just check the package you download is signed by the developer and you're safe. Authenticode signatures are present on all KeePass releases on Windows and most Linux users probably get it from a distro package manager anyways.