5 ms·
>an attacker, who has write access to the XML configuration file If an attacker already has write-access to local files he could also replace keepass.exe or in
by Run_DOS_Run 4y ago
>an attacker, who has write access to the XML configuration file
If an attacker already has write-access to local files he could also replace keepass.exe or install a keylogger.
If this happens, it's already too late.. this CVE is a joke!
- ntauthority 4y agoThere's a lot of CVE submissions lately that seem badly sourced and derived from 'disagreements' at best. Another recent example is https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24059 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2405... which is for a purely theoretical exploit - not even a PoC - with the only 'sources' being Reddit/Twitter scaremongering, and 'support forum posts' that quote these exact same Twitter threads.
- usrusr 4y agoUnsafe defaults like "we run all plugins, unless someone goes through all the right motions of closing that door in all the right ...config.xml, ...config.enforced.xml" (and who knows what others) is just terrible. Terrible for any software, and worse for a piece of software that has no purpose at all besides security. What if there's a typo in your lockdown incantations? Not locked down. That CVE isn't just a disagreement, it's a warning. Avoid security related software from people who enjoy keeping a security edge over the unwashed masses who aren't in the know, who don't get a kick out of locking down. Because that's why they keep the unsafe defaults, they keep them because they enjoy going the extra mile for their own safety. That is, unless they (also) have worse reasons for keeping unsafe defaults, but, well, Hanlon to the rescue.
- paulryanrogers 4y agoConvenience and tradeoffs are inevitable. KP is meant for regular users with moderate risk tolerance and profile. Without plugins KP is much less useful. If the alternative is no password manager or trusting a SAAS then it may be worthwhile.
- usrusr 4y agoI'm all for convenience trade-offs, but they need to be opt-in, not opt out.
- paulryanrogers 4y agoDefaults are usually built for the widest market. Full disclosure, I sell a premium KP2 plugin and would hate for users to have to reinstall KP2 or go through extra hoops to use my plugin.
- usrusr 4y agoThat's answered in the SourceForge discussions linked from the CVE: if you assume the password manager to be only as secure as the user's configuration files, why don't you just skip the hassle and put your passwords in a csv?
- raziel2p 4y agoan argument could be made that it's more likely for the password manager file to end up in a malicious actor's hand (in which case an unencrypted csv would be worse), than it is for a malicious actor to get access to your local filesystem.
- someguydave 4y ago> why don't you just skip the hassle and put your passwords in a csv? What threats did you think keepass was defending against exactly?
- Macha 4y agoA .csv file on an encrypted hard drive, in a single user system or with proper user permissions arguably does provide 90% of the security benefit of KeePass. But: 1. Ease of use is a security concern - if it's a pain in the ass to use a security measure, users won't. 2. There's also attacks that for whatever reason aren't able to achieve persistence, but are able to obtain files. Let's imagine a browser or scp or rsync or whatever exploit that tricks it into uploading unintended files. These cases will be blocked by KeePass but not by your .csv 3. Users want to sync their password database via untrusted means (e.g. cloud providers). This is easier when the database is itself encrypted. (This attack targets the application config, not the database config, which is a strange choice to sync).
- PurpleRamen 4y agoHas the configuration the same permissions as the exe? IIRC, binaries under windows are often saved with different permissions than the user-profile. Similar, a virus-scanner will look intensively at exe-files and access to keyboard-input, but not so much at some random configuration, which is supposed to change all the time anyway.