22 ms·
KeePassXC Audit Report
- kej 3y agoI feel like "Who is Zaur Molotnikov?" is an important question that is not addressed on the page. His CV is here: https://molotnikov.de/cv https://molotnikov.de/cv
- sdfghswe 3y agoI have found that I develop emotional loyalty to good software. Most software is shit, but KeePassXC has been really good.
- paulryanrogers 3y agoI feel similarly, and would also say KeePass 2 is also good and well written. (If a bit DI heavy for my taste.)
- sdfghswe 3y agoWhat's DI?
- paulryanrogers 3y agoDependency Injection
- l0b0 3y agoSame, so much that I've been a paying supporter[1] (hint, hint) for a good while now. [1] https://www.patreon.com/keepassxc/posts https://www.patreon.com/keepassxc/posts
- mywacaday 3y agoHow do people mange passwords themselves across laptop/tablet/mobile? I have been meaning to leave lastpass but always seems like too much hassle.
- gabrielgio 3y agoI use a third party app to sync the database file, in my case Nextcloud.
- theSage 3y agoI use KeepassXC + Syncthing. On a few devices that never connect to the same wifi i use tailscale to connect Syncthing.
- rglullis 3y agoSyncthing (the most recent versions, at least) also allows for password-encrypted sharing. So even if you are syncing across a relay, no data is in clear.
- j0057 3y agoRelays can't see your data, because the connections between your synchthing instances are mTLS encrypted. Using an additional shared secret on a folder allows you to sync a folder to an untrusted device, which then itself only sees encrypted files.
- _dain_ 3y agoThe password database is literally just A File On Your Computer. So any file synchronization tool will work. I use Syncthing.
- sigio 3y agoVaultwarden self-hosted bitwarden and passwordstore.org
- bhbh 3y agoI keep my KeePass file on my OneDrive / iCloud account. This way it is always up to date as it syncs automatically after each change and my devices always open the most recent version.
- 2Gkashmiri 3y agoyou dont exactly need to have it hot synced imo. i've been running this scheme where i keep the "live" DB on my phone so any change i need to do, i do it on the phone and every often i sync or copy it to the laptop. this has served me well for like the past 6-9 years so i guess it works. You definitely do not need an online service. its not like passwords change like crazy. i've had entries that i only change because of stupid password reset policies (every 4 months for example), other than that, i only update the DB if i add a new entry.
- _dain_ 3y agoThis part in the PDF gave me pause: >As KeePassXC is a relatively complex program and the review effort was limited, I did not review all of the code base. Some helper features stay not reviewed, for example: TOTP, SSH agent, browser plug-in communication, auto-type, KeeShare password sharing mechanism, freedesktop integration, HIBP support, database statistics feature. Maybe these features could be a subject to a next review version. Those integrations seem like scary weak-points, especially to the browser.. and I'm a little confused because later on he says he did review the browser extension code: >KeePassXC supports integration with browser extensions. The communication between the password manager application and the browser extensions is implemented using secure and modern libsodium-style encryption. I personally trust this cryptography choice and salut the use of encryption to communicate with browser extensions.
- HPsquared 3y agoMaybe we need someone to audit the audit.
- iotku 3y agoWho audits the auditors?
- droidmonkey 3y agoHi there, lead developer of KeePassXC here (and writer of a lot of code). The TOTP and SSH Agent are generally not a security issue. TOTP has no external interfaces and SSH Agent only writes to the known interface standards of those programs. There is actually not much to those code areas. Auto-Type is similarly rather simple at the interface level (except for X11 because its X11). We call native OS functions to emulate typing. Similarly the internal reporting features are rather benign. HIBP checks requires explicit approval by the user before anything happens. The browser code and FDO Secrets code definitely needs auditing. The browser extension is separate from the browser code within KeePassXC proper. KeeShare is going to be entirely rewritten for our 2.8.0 release.
- scrollaway 3y ago
- woodruffw 3y ago> KeePassXC is written well and exercises defensive coding sufficiently. This might be a transcription or language problem, but: auditors really shouldn’t normative claims like “software X is written well,” much less actually endorse the software they’re paid to review (as the audit’s summary appears to at the end of the post). It’s a massive conflict of interest, and undermines the actual purpose of an audit: to accurately report any weaknesses found (if any!), rather than offer an opinion on the product’s value or future exploitability (including against unknown adversaries). (This is not a dig at KeePassXC or this auditor in particular; lots of auditing shops are guilty of this.)
- sdfghswe 3y ago> much less actually endorse the software they’re paid to review > It’s a massive conflict of interest They weren't paid. There's no conflict of interest, at least not a commercial one.
- woodruffw 3y agoThat’s important information, and should be included in a public announcement of an audit! Even still: pro bono audits carry reputational value, meaning that there’s no way to fully discharge the conflict of interest here. The only correct way to do it is to refuse to endorse the software you audit; an audit that enthusiastically recommends the software it covers sets off red flags. Edit: I misread the post, which does explicitly state that the audit was conducted for free.
- politelemon 3y agoIt is in the first paragraph
- woodruffw 3y agoYou’re right, sorry — I missed that. I’m going to edit my comment with an explicit correction. The second point still stands.
- mdaniel 3y agoBased on the dates in the audit, I would have expected references to existing issues, e.g. > The memory deallocation could be improved to not to contain secrets after the database is locked though. See https://github.com/keepassxreboot/keepassxc/issues/7335 https://github.com/keepassxreboot/keepassxc/issues/7335 for progress on this issue Then again, the PDF mysteriously doesn't indicate which words are hyperlinked and so maybe I just didn't wave my cursor over enough words to find those references Also, because the outer blogpost didn't mention it (although it is in the actual PDF) the auditor is https://molotnikov.de/cv https://molotnikov.de/cv and it says they work for AWS as a Senior Security Architect. I didn't see anything especially C++ focused, but I guess any independent audit is better than none
- spansoa 3y ago> The memory deallocation could be improved to not to contain secrets Attacks against RAM are as old as time. The beauty of RAM is everything gets wiped when you power off, so secrets don't persist.
- hyperman1 3y agoNo, unfortunately. When they swap out, they end up on disk. Sector remapping can then keep them there, even if swap space is reused. I think there is an API in windows to mark a small part of memory as unswappable, but it can't be very big.
- bionade24 3y agoEven if you don't encrypt your Linux' filesystem partitions, you definately should encrypt the swap / the partition the swapfile is on. A new encryption key for the swap can be created at every boot, removing the need of an encryption password. This behaviour does make hibernation impossible, so swap encryption isn't the default on Linux distros that have opt-in encryption. https://wiki.archlinux.org/title/Dm-crypt/Swap_encryption https://wiki.archlinux.org/title/Dm-crypt/Swap_encryption Does someone know how it's handled on Windows and macOS?
- 3y ago
- deleted 3y ago[deleted]
- djha-skin 3y agoIt is worth noting that most users use KeyPassXC with the mobile applications Keepass2Android or Keypassium on Apple. A complete picture of the security of the system must therefore necessarily include an audit of these tools as well.
- pedrogpimenta 3y agoAnd the way you sync the databases as well, if you do that.
- marcosdumay 3y agoThe point of those tools is that the security requirements on the database file are much less strict than on the tooling.
- jbj 3y agoNot KeePassDX which is in F-Droid?
- Seattle3503 3y agoI'm glad I read this. My database was on KDBX 3, when KDBX 4 is the latest and most secure version of the DB. I upgraded my DB right away. If version 4 is mores safe, KeePassXC should insert a nudge for their users to upgrade.
- qutorial 3y agoHi all. Zaur here, the author of the audit report. Thanks a lot for the feedback here. I've decided to clarify some points and also introduce changes to the most recent audit PDF. https://molotnikov.de/keepassxc-review https://molotnikov.de/keepassxc-review - The links in the most recent review version are now highlighted with blue. - I did not yet have a too deep of a look in Keepassium, KeepassDX, or browser extensions, although, I know these exist. On my radar, need to find time and dive deep! - The not reviewed features by me are just not reviewed yet. I wouldn't call them scary. The use of them is optional btw. Again, need to find time and look deeper. It is also a tip for other researchers where to look next. - My review contains certain subjective statements like on quality of code, and on recommending the use of KeePassXC. Well, my goal was to inspect an offline, without servers, subjectively likeable and recommendable from the UI/UX perspective tool, because the main problem with the password managers is that they are still not used enough in the wild. I have found a subjectively good desktop UI, checked the code quality (structure, availability of tests, clean use of C++ and Qt), could see sound modern crypto, and.. proceeded to solving a bigger problem - recommending the use of it. Making the judgment for the potential review readers, to whom the deep details are too much to interpret, and who need a simplified answer, what to incline toward, if to rather use it or not... I noted though for the next reviews to avoid too general judgements. - Personal questions on who Zaur is, and why my opinion matters.. :) Well, the CV is pointed to, I know applied security and applied crypto, I have 6 years professional experience with C++. I code and review projects for security daily. No complex and working software is ideal and perfectly secure. Plenty of software online is low-bar in secuirty. I had capacity to check the basics and a little beyond them for KeePassXC, and put my subjective judgment here on the right side of the weights. - Loved the discussion on mobile phone and multi-device sync. Syncthing and other suggestions. On an iPhone nothing really works very well, as files are compartmentalized per app... For those of us who only need a few passwords on mobile, it is recommendable to create a separate small database with only those passwords, and use it readonly on the mobile.
- kludge41 3y agoWhen you evaluate Keepassium could you look into if the application honors not contacting anything on the internet? For me this is a major point of feeling secure when using the application and iOS has no way to block apps from accessing the internet. Otherwise thank you a lot for checking KeePassXC!