3 ms·
Why not use dropbox? It is only used for sync databases, not access them, I always though if someone found my keypass database encrypted it would be useless.
by rhlala 9y ago
Why not use dropbox? It is only used for sync databases, not access them,
I always though if someone found my keypass database encrypted it would be useless.
- dannysu 9y agoParanoia Yeah, the KeePass database is encrypted and I secure it with both password and keyfile, but I still want something that won't leave my database "out there" available for bruteforce attempts or other attempts at it.
- roryisok 9y agoIt's hardly "out there" though. A hacker would still need to hack dropbox before they could access your keepass db and begin brute forcing. What makes your own private server more secure than dropbox's network?
- dannysu 9y agoYou're trusting them to not have issues like this: https://blogs.dropbox.com/dropbox/2011/06/yesterdays-authentication-bug/ https://blogs.dropbox.com/dropbox/2011/06/yesterdays-authent... I don't trust the servers (Dropbox or my), and thus I want it encrypted on my computer prior to sending it out on the Internet.
- roryisok 9y agoI suppose it couldn't hurt!
- stephengillie 9y agoWhat is the cause for your paranoia about keeping your keyfile in your Dropbox? I have used and advocated this model for years with no ill effects. My Dropbox is secured by MFA, with the Dropbox password itself being a random password within the KeePass keyfile. I store the whole Keepass program for Windows inside the same Dropbox account, feel free to indicate that as a security gap. On mobile I use the KeePass2Android app.
- dannysu 9y agoYou meant the kdbx file right? not the separate keyfile you can use to secure the kdbx file with. I think the feeling is the same as the feeling of just leaving your SSH private key "out there". Sure, it's protected with a passphrase, but I still don't want to do that. Can you trust Dropbox would never have security issues? See https://blogs.dropbox.com/dropbox/2011/06/yesterdays-authentication-bug/ https://blogs.dropbox.com/dropbox/2011/06/yesterdays-authent... Didn't matter if you have MFA or use a secure password.
- stephengillie 9y agoSome people will not be satisfied so long as the keyfile, KDBX, and password reside in the same version of our shared reality, as it's still mathematically possible to decode the numbers into something they personally value.
- iimpact 9y agoyou can also encrypt the db file it self (before putting it on dropbox) with something like EncFS.
- dannysu 9y agoI used to do that when I used purely Linux. However, once you bring iPhone and Windows into the picture it doesn't work anymore.