5 ms·
Got to agree with the developer on the dispute. If someone can edit the XML they could also just add a plugin that exports everything on load? Plugs are trivia
by moritonal 4y ago
Got to agree with the developer on the dispute.
If someone can edit the XML they could also just add a plugin that exports everything on load? Plugs are trivial to write and have access to everything automatically if they exist on disk in the plugins directory.
- jonathanstrange 4y agoThat feature is extremely insecure and makes no sense for a password manager. It ought not be possible to trigger anything in an unencrypted document or install/run anything over plaintext data without first providing the master passphrase for that password document. That should be obvious.
- adlpz 4y agoI'm just guessing here, but I'd assume this vulnerability does happen once the master password is input. So, the attacker modifies the config file, then the user eventually uses the password manager as usual, and then a file in disk with all plain text passwords is generated and subsequently read by the attacker. I guess the point here is you don't need a memory read vulnerability. Can someone more knowledgeable confirm?
- Ensorceled 4y agoThe point is that the file itself should be encrypted or at least signed with the master password.
- detaro 4y agoFor a general configuration file, there is not "the" master password, since it is independent of password database files.
- adlpz 4y agoI guess it's an issue of UI. Given that dumping a cleartext password list is a legitimate thing you might want to do, and being a plugin (or setting) a somewhat acceptable way of achieving this, the issue here is that, as it is, the user is not being unequivocally made aware of what happened. So yeah, I agree, in any case the feature, as it is implemented, is completely unacceptable.
- _puk 4y agoAm I reading that right, that if you point Keepass.exe at any .kdbx and simply add an export option to the XML config it'll export it without the master password? Granted you need local access to modify the config, but generally the .kdbx is stored (securely) on some shared environment. Grabbing that would mean you could export passwords at your leisure in this setup?
- coding123 4y agoSo this makes no sense. Someone that works at Dropbox has access to millions of kdbx files, and doesn't need any master passwords, just their own copy of keepass.exe?
- vgalin 4y agoTo perform an export of a KeePass database, the database needs to be opened using (at least) a master password. A database file without its master password is still worthless on its own.
- usrusr 4y agoBut you don't know that you are entering the password to release all your passwords into cleartext, all you wanted to do is check wether your farmville cows still exist.
- jonathanstrange 4y agoThat's my biggest quirk. There shouldn't be any way to export plaintext data without explicit user feedback and confirmation in the first place. That this is triggered by an unprotected global configuration file is just the icing on the cake.
- gnud 4y agoAs I understand it, if you modify the xml, Keepass will silently export entries in the database once you load it (by providing the password). Keepass will (by default) not ask for the password a second time before exporting - but you have to decrypt the database once before it can be exported. So this is not a risk if your threat model is "attacker obtains a copy of my .kdbx", but it is a risk if your threat model is "attacker can modify .kdbx without me noticing, and can access my local computer or a mounted network disk to read the exported passwords".
- tinus_hn 4y agoI would hope that the password manager application does not itself have access to the unencrypted passwords, without the user providing the master password.
- notRobot 4y agoThis is correct.
- LeifCarrotson 4y agoBut users are constantly providing the master password to use the application normally. The only complaint is that after first providing the master password to cause the application to decrypt the document, the application decrypts the document, and if someone has modified the application to do other stuff after decrypting the document, it does that stuff. They're proposing that the author change the application so that it pops up a dialog whenever the KeePass application is directed to export the decrypted document. I'm not a KeePass dev, but with a bit of search and pattern recognition, it looks like this export feature is implemented in KeePass-2.53-Source\KeePass\DataExchange\ExportUtil.cs: public static bool Export(PwExportInfo pwExportInfo, FileFormatProvider fileFormat, IOConnectionInfo iocOutput, IStatusLogger slLogger) { PwDatabase pd = pwExportInfo.ContextDatabase; ... // [IF CONFIG FILE DOESN'T ALLOW EXPORTING WITHOUT KEY] if(!AppPolicy.Current.ExportNoKey && (pd != null)) { // [THEN ASK FOR IT AGAIN] if(!KeyUtil.ReAskKey(pd, true)) return false; } ... Stream s = (bFileReq ? IOConnection.OpenWrite(iocOutput) : null); try { bResult = fileFormat.Export(pwExportInfo, s, slLogger); } finally { if(s != null) s.Close(); } } They're complaining that an evil maid attack can turn off `AppPolicy.Current.ExportNoKey` and set it up to export the document silently. They want it to read: public static bool Export(PwExportInfo pwExportInfo, FileFormatProvider fileFormat, IOConnectionInfo iocOutput, IStatusLogger slLogger) { PwDatabase pd = pwExportInfo.ContextDatabase; ... // [ALWAYS ASK FOR MASTER PASSWORD AGAIN BEFORE EXPORTING] if(!KeyUtil.ReAskKey(pd, true)) return false; ... Stream s = (bFileReq ? IOConnection.OpenWrite(iocOutput) : null); try { bResult = fileFormat.Export(pwExportInfo, s, slLogger); } finally { if(s != null) s.Close(); } } They've even gone so far as to ask the author to create a "KeePass Essentials" version, which removes the export feature, plugins, and configuration files entirely: https://sourceforge.net/p/keepass/feature-requests/2704/#b3cb https://sourceforge.net/p/keepass/feature-requests/2704/#b3c... But they ignore that with write access to the application directory, an attacker can just change the application to not show that dialog at all.
- detaro 4y agoApplication directory and Application Settings directory are not the same thing, usually. (Indeed usually on Windows and Linux, the former isn't writeable to the user account without elevating privileges, the latter is)
- H4ZB7 4y agoyou extremely have no idea what you're talking about. the password exists because that's how encryption works, and no other reason. if your hard drive is stolen, they need the password. there is not one single other reason that the password exists
- that_guy_iain 4y agoI would expect to be able to give someone access to my computer let them do random things without them having access to things that are passworded within the computer. Being able to sliently make my password manager insecure is a big issue. It should be right up there with the LastPass hacks.
- vgalin 4y agoThis 'someone' could also, on most computers, install a keylogger to get your master password, or passwords that aren't registered in a password manager. Would you consider this a vulnerability coming from the password manager?
- that_guy_iain 4y agoIn most cases they wouldn't be able to do that. Because there are security measures to prevent that.
- blincoln 4y agoWhat security measures do you think would protect against someone installing a keylogger or extracting saved passwords from your browser data files if you let them use your computer? Also, are you envisioning setting up a new, non-administrative user account for that person, or just logging on using your own account and then handing over the keyboard and mouse like most people would do?
- that_guy_iain 4y agoAnti-virus systems...
- usrusr 4y agoThere's an option to disable plugins, for that very reason. But that's the core of the issue, if you're unsafe by default adding lockdown options which may or may not work is a very weak improvement. That entire attitude seems more security toy than security tool.
- moritonal 4y agoBut, isn't it more dangerous to give a false sense of security? Wouldn't you prefer a tool that doesn't try to defend against scenarios it knows it isn't strong enough to handle?
- usrusr 4y agoFalse sense of security is exactly what they did: a sturdy looking lock with a main mechanism that would give the lockpickinglawyer a challenge, but with a number of hidden bypass options that are easy enough for you and I do use (if we know about them). Bypass options that are considered enough of a problem to give the legitimate user ways to disable then and they are just as hidden as the bypasses themselves. And default to not disabled.