28 ms·
Suspicious iOS KeePass Client
- JorgeFrias 3y agoI feel your pain! So much that I built my own Local Password Manager -> Pocket Pass Manager [You get it? Pocket ≠ Cloud eh eh eh]. When LastPass moved from a free to a paid business model (paid-or-f%$k-you with users locked-in), I decided to build a password manager for myself, friends and family. I knew that password managers like One Password used only open source libraries for encryption, which made it seem simple to create a similar app, but improving the user interface and overall experience (I'm a sucker for great UIs). This was before all LastPass fuck-ups, I (correctly) thought vault syncing was a bad idea, thus I took the local approach. Building a local password manager has several advantages. Firstly, it avoids the risks involved in sending passwords over the internet. Secondly, there is no need for servers, meaning there are no fixed costs, forcing me to implement a subscription model. Lastly, users can be assured their passwords are secure, as they know where their passwords are at all times; for instance, you can check the app doesn't make any internet connections, and the encrypted sqlite database can be downloaded and audited. Admittedly, I understand that other local password managers exist, but building my own was a fun personal project, developed to my satisfaction. [I built this thing in pure Swift exclusively for iOS, as is what I used daily at Reliby (my startup-ish), and I wanted to try a 100% SwiftUI approach] Before getting to code, one problem needed more thought: how to access the passwords from other devices? Macs have a shared clipboard, but I used Windows half of the time, I needed to find a way without compromising the security nor the locality. Inspired by Snapdrop and VLC's local upload, I came up with the idea of making the iPhone behave as a local web server, enabling users to access their keys on other devices on the same network (local network). The first implementation, V1, used SSL (HTTPS) to encrypt the passwords payload, but the certificate couldn't be trusted, and some web browsers didn't accept it. Hence, I had to install the certificate on my computers, which ultimately became frustrating. However, this approach proved the concept could work. I ditched LastPass in just a couple of weeks! For the second version (current is 2.3.0), I rewrote most of the code, focusing on creating a new web server approach that runs over unencrypted HTTP. The password payload is then encrypted with 256-bit AES using another key randomly generated on the explorer (client) that is transmitted to the phone by scanning a QR code. This approach ensures that even if someone is "listening" on the local network, they cannot obtain the key. What's more, users have a physical confirmation of the computer they were sharing the key with. Even if someone accessed the user's phone server, nothing would be transmitted without scanning the code. How cool is that? Using the Pocket Pass Manager app, which is available in the App Store, users press "Share on the phone," access "jorges-iPhone.local," scan the QR code, and passwords (and other data) appear like magic on their other device. The app also includes a built-in authenticator, credit cards, notes, offline security analysis of passwords, CSV import, and custom backups. There is in-app purchase ($4) for adding over 20 passwords. However, those who cannot or do not want to pay can join the beta channel, where unlimited access is granted. Feedback is appreciated, but you should do backups as the app could experience bugs. I cannot believe that my app's UI looks better than LastPass, which has millions of expenditure. Here are the links if you want to try it out, I hope you like it. - AppStore: https://apps.apple.com/us/app/pocket-pass-manager/id1563839314 https://apps.apple.com/us/app/pocket-pass-manager/id15638393... - TestFlight (beta/free): https://testflight.apple.com/join/NeYmSS4B https://testflight.apple.com/join/NeYmSS4B Feedback is much appreciated.
- quenix 3y agoIn retrospect, this seems like an obvious flaw in using third party clients for password management. The fact that KeePass is OSS is great, but it leads you to have to rely on these shady pieces of software to access your vault on non-officially supported platforms like iOS. You wouldn’t have this problem if you used e.g. 1Password or Bitwarden. They have official iOS clients made by the same entity which you’ve already trusted with your secrets. tl;dr Having to trust a third party KeePass client isn’t very smart and forces you to trust two (2) entities instead of one with your secrets. This is such a deal breaker that it might turn one off accessing their KeePass vault on iOS at all.
- artjomb 3y agoExactly, as a user you need to be aware of this addition of risk. Anonymous OSS maintainers are the issue here. When I want to use a project and want to reduce the risk here, I need to vet the maintainers in a similar way I would vet a company I want to invest in.
- bobmaxup 3y agoI don't think there is a need to have someone's reputation score to use their software. There are plenty of pieces of open source software running on operating systems that were contributed by people who are effectively anonymous. Also, it doesn't seem like a contributor's overall character would be a great measure of how malicious their contriubtions are, as evidenced by plenty of examples of assumed good people eventually doing bad things.
- kjreact 3y agoI don’t understand why people believe that open source inherently makes software secure and trustable. Yes, you have access to look through the code, but I usually don’t have the expertise to understand what I’m looking at. I wouldn’t know how to look for well hidden exploits or malicious intent. I’m still reliant on others to find these issues. At the moment, I do rely on reputation before I trust open source software. But in the case of an app store, I can trust the reputation of the store. I can trust that the app store has to work to uphold their reputation which is their motivation for maintaining a good track record of identifying problem apps. I agree this is far from perfect, but I think it’s much safer than relying on open source. I love the idea of open source and I hope that it will never be replaced by app stores, but I don’t feel that software is inherently more trustworthy if it’s open source.
- WesolyKubeczek 3y agoThis is one of those cases where, regrettably, decentralization and open sourceness can play out not very well, to say the least. Someone can make an API, a library, a file format, which is bona fide good, and for good purposes. They leave the implementation for platforms they don't care about to others, because why not? And then someone makes an app which looks totally legit, is open source even. You end up thinking that the fact it's open source is by itself enough clout to trust the app. But the thing is, there's so much code in the repositories added every day that no one will be able to give it enough eyeballs so that all the shady bollocks it does are shallow. Malware authors don't even have to particularly hide the malicious bollocks away, or compile their published app from different sources. And if you chase them down, they rebrand, do SEO, and publish two new totes legit looking apps for each one you get to take down. Centralized services like Bitwarden (LastPass left a bitter taste in my mouth) come with their own sets of problems, but at least they have a company behind them whose site can be verified as belonging to them and pointing to the correct version of their official client app.
- fauigerzigerk 3y ago>This is one of those cases where, regrettably, decentralization and open sourceness can play out not very well, to say the least. I think this is one of the cases where the problems of decentralisations are exacerbated by the problems of centralisation. It's hard enough to vet a github repository, but at least it can be done. After funneling the code through an intransparent, centralised review process that claims to ensure "the highest standards for privacy, security and content" you can no longer verify anything.
- WesolyKubeczek 3y ago> It's hard enough to vet a github repository, but at least it can be done. It will, more often than not, fall victim to the bystander syndrome. Someone else will do it, right? Right? Well, in fact, nobody will do it. Here's why: a KeePass client is already a niche piece of software; people who are aware of it and would like to use it on their iOS devices form a small subset of all KeePass users; of those, people who have actual chops to perform a review of source code, are an even smaller subset; of those, people having enough spare time and brain cycles to be bothered is a number very close to zero, or can be counted on a drunk carpenter's fingers. Those people will maybe carve time to look once they suspect something fishy is happening.
- maratc 3y agoTangentially related question: What is the [recommended|best|most used] iOS KeePass client? The KeePass site recommends MiniKeePass that's been archived for a couple of years already.
- ajdude 3y agoI'm a very happy user of strongbox: https://strongboxsafe.com/ https://strongboxsafe.com/ I currently sync my vault via WebDAV and they even support storing the local keyfile.
- prophesi 3y agoSame here. Nextcloud to sync the database, and a local keyfile that doesn't touch the internet/cloud. It's also open-source under AGPL, though iOS doesn't have anything like F-Droid to verify builds. https://github.com/strongbox-password-safe/Strongbox https://github.com/strongbox-password-safe/Strongbox
- shocks 3y agoI’m using Strongbox also.
- garganzol 3y agoKeePass Touch works reasonably well.
- k8sToGo 3y agoI’m a fan of KeePassium
- sebazzz 3y agoKeePassium is awesome, as it also integrates on the iOS level as a password auto-fill solution.
- deleted 3y ago[deleted]
- bee_rider 3y agoLooks like it is riffing off the name of the dearly departed MiniKeePass.
- sammachin 3y agoThe problem is there’s no way to truely publish OSS on the iOS App Store (or Play store) you submit a binary to Apple and you can publish a repo to GitHub but AFAIK there’s no way to correlate that those two things are the same. So unless you build the app from source yourself there could be anything in the binary.
- emsy 3y agoYou just made the case for how sideloading can be more secure than a centralized App Store.
- 2muchcoffeeman 3y agoThat’s not really a solution to this either, because security can’t just be for people who know how to compile and side load apps.
- zouhair 3y agoSo everyone's safe or no one is safe?
- 2muchcoffeeman 3y agoThat could be the case. I’m not arguing that you shouldn’t allow side loading. But let’s say this is what developers start doing. We compile our own code and side load. Great for us. How many people can each individual support? Immediate family and close friends? Are most people on their own? Now say your immediate contacts are compromised. That exposes some of your details as well would it not? At least you’d be more vulnerable to social engineering. So maybe you have to work towards a system where everyone is safe.
- redeeman 3y agotheres no other way in general, those who have no clue about things will be doomed to not know how to conduct themselves in a secure manner
- 3y ago
- whamlastxmas 3y agoGlad I saw this. I have this installed on my phone too, though I thankfully possibly never used it? I mostly only ever use FF password manager these days and I haven’t updated any keepass entries for 2 years. Going to change all my keepass saved passwords regardless
- fodi 3y agoI'd stay away from any KeePass clients with network access. I don't have a recommendation for iOS, but for Android KeePassDX [0] seems like a good option as it has no network permission to begin with. [0] https://www.keepassdx.com/ https://www.keepassdx.com/
- m-p-3 3y agoThere is also Keepass2Android Offline https://play.google.com/store/apps/details?id=keepass2android.keepass2android_nonet https://play.google.com/store/apps/details?id=keepass2androi...
- k8sToGo 3y agoFor iOS I use KeePassium. A paid app.
- KeePassium 3y agoTo be precise, KeePassium is a freemium app (free tier + some premium features)
- ssbash 3y agoStrongbox is a fantastic KeePass client on iOS and macOS. They offer a fully offline version called Strongbox Zero. https://strongboxsafe.com https://strongboxsafe.com
- arepublicadoceu 3y agoHow do you attest this without simply trusting the dev or monitoring package data transferred by the app?[1] iOS, differently from Android, doesn’t have a explicit network permission that the user can verify. All apps have network access by default and there’s nothing you can do about it without jailbreaking. [1] as many pointed out: open source in iOS is a moot point as there’s no way to verify the binaries.
- ssbash 3y ago
- lifty 3y agoToo bad operating systems allow full internet access for applications that shouldn’t. Hopefully this security feature will one day be implemented in popular operating systems.
- garganzol 3y agoBTW, the GitHub profile of the repository owner points to a sketchy website [0] which looks somewhat plausible from the first glance, but then more like a content stub on a closer inspection. [0] www.unicomedv.de Update: the reason I think it is more a content stub than a real thing is because there are no trial downloads available for theirs desktop products, and that's a red flag. Some site sections like "Office 365" represent a total nonsense with buttons leading nowhere. The pricing page has gray-on-black text elements, so looks clearly deoptimized for performing any real conversions. The whole site gives a strong fly-by-night vibe.
- MrGilbert 3y agoAccording to Northdata[0], the Managing Director has been part of the now-defunct "Black Diamond Suxess Club GmbH", which allegedly has been running a Ponzi scheme[1]. Also, if you look up the address, it's not an office complex. It's a residential area with single-family homes. [0]: https://www.northdata.com/M%C3%BCller,+Montgomery,+K%C3%B6ln/wjc https://www.northdata.com/M%C3%BCller,+Montgomery,+K%C3%B6ln... [1]: https://www.bekm.us/black-diamond-suxess-club-gmbh-mario-oreggia-and-his-cologne-shadow-plant-for-lyconet/ https://www.bekm.us/black-diamond-suxess-club-gmbh-mario-ore...
- garganzol 3y ago> if you look up the address, it's not an office complex. It's a residential area with single-family homes. And I bet there are no Wozniaks in that garage.
- bdcravens 3y ago> Also, if you look up the address, it's not an office complex. It's a residential area with single-family homes. I don't like considering this a signal. We want indie developers to flourish (a business name is little more than paperwork that anyone can get), and it's too easy for the nefarious to buy a "virtual office" in a legit-looking office building that is little more than a PO Box.
- pevey 3y agoI was coming here to say the same thing. It's really amazing that they used their own domain name to receive the payload from this malware analytics code. Possibilities are (1) all of the people associated with this company are not real people (faked LinkedIn profiles and everything), (2) they are really, really dumb, or (3) it was a roque employee/contractor who saw an opportunity to set this up and skim some cream.
- eternauta3k 3y agoIf this is malicious, then I don't understand why the evil code was in the public repository instead of just in the binary.
- nightpool 3y agobecause people are stupid and maintaining a separate private fork is more annoying than it's worth?
- lxgr 3y agoIf the intention here was really to steal passwords, it could also be deniability? Uploading sensitive stuff to logging and/or analytics packages or third party providers is a surprisingly easy mistake to make – which in turn makes it an excellent avenue for plausible deniability. It can be really hard to tell which one it was without inside information or a detailed investigation.
- quyleanh 3y agoWait. I just thought iOS App Store has manual review process with human? And it gains reputation by kill all suspicious applications before published to App Store?
- zamadatix 3y agoNothing in security catches "all" things. A review process with a human may be good but it's far from turning humans into infallible detectors. The reputation gained by the App Store is by catching many such apps before they are published, not every single one.
- dingledork69 3y ago[flagged]
- zouhair 3y agoFrom KeePassXC FAQ, suggested mobile apps[0]. [0]: https://keepassxc.org/docs/#faq-platform-mobile https://keepassxc.org/docs/#faq-platform-mobile
- egberts1 3y agoMy running note on self-hosted password managers: 1password: since version 8, dead due to cloud-only-now, not standalone, its over-usage of Electron web and its many unverified modules/libraries; remote storage of password only in encrypted form. Key stays offline. vaultwarden: yet another Electron web app and its usage of many unverified modules/libraries; remote storage of password only in encrypted form. Key stays offline. KeepassXC, with syncthing: leading contender, best-self-hosted solution that stores password remotely only in encrypted form. but still has iOS unverifiable source code imposed by Apple. Key stays offline. NordPass: best zero knowledge remote storage; has apps for Windows, macOS, Linux, Android, and iOS. When it comes to browser extensions, one would be hard-pressed to find a wider selection. You can install NordPass on Chrome, Firefox, Safari, Opera, Brave, Vivaldi, and Edge. Not open-source. LassPass, hacked in 2022; remote storage of raw passwords pwsafe, still is the safest CLI-only solution to date. The design of pwsafe (Password Safe CLI) got started by Bruce Schnier, the crypto security privacy expert. In pwsafe, unbroken TwoFish algorithm is still being used instead of currently safer Argon2i, simply because it's faster (after millions of iterations). The recommended client-wise of PasswordSafe is still Netwrix (formerly MATESO of Germany) PasswordSafe with YubiKey but stay away from its web-client variants due to ease of memory access to JavaScript variable names (by OS, browser, JS engine, and JS language) Only downside for ANY PasswordSafe-design GUI client is trusting yet another app repository source.
- Aaron2222 3y ago> Electron web and its many unverified modules/libraries What do you mean by this? That Electron itself uses unverified modules/libraries, or that 1Password is? And do you have any citations for this?
- egberts1 3y ago[dead]
- pjmlp 3y agoUnfortunately 1password has been a requirement in many projects I have been involved with.
- nkotov 3y agoIn case it wasn’t clear, the app in question is KeePassMini. Here’s the AppStore link: https://apps.apple.com/us/app/keepassmini/id6446373282 https://apps.apple.com/us/app/keepassmini/id6446373282
- heisenbit 3y agoDid or will Apple inform affected users? If not how could Apple maintain the argument the app store provides protection?
- crop_rotation 3y agoOne such incident doesn't eradicate Apple's argument. By that logic one bad sideloading incident would undermine the logic that sideloading can be safe.
- crop_rotation 3y agoUnfortunately neither iOS nor Android allow you to totally disable internet access on a per app basis. On Android side manufacturers like Xiaomi do allow it, but nothing built in for all. There is Netguard on Android atleast. I really think it should be possible to disable internet access on a per app basis.
- Nextgrid 3y agoIronically enough, iPhones for the Chinese market allow you to disable an app's network access completely. Non-Chinese-market ones only allow disabling mobile data but not Wi-Fi.
- crop_rotation 3y agoIf they already have the feature then it makes even less sense to not give it to everyone. Like I would switch my phone OS just if there was a simple way to disable internet access totally for apps.
- Nextgrid 3y agoI wouldn’t be surprised if the only reason this exists in China is because of some legal requirement or a requirement from local carriers. I’m sure Apple and the rest of the industry would rather not offer this as it would break many data collection and “engagement” strategies (you can disable network access for single-player games and not have any ads for example).
- Nevicar 3y agonext time, actually link the app in your github post to call them out rather than making an entirely cryptic post with names that can be easily changed and swapped around. incredible security warning "hey this app that had its name changed may have been compromised". very established message that warns the other users that could have it. go search through the comments and hope its there instead!
- mynameisvlad 3y ago> To my surprise the app I was using to read my KeePass database, iOSKeePass, was missing from App Store. It was deleted and I only owned a local copy. What exactly would they link to? A dead App Store listing?
- dt3ft 3y agoThe new listing.
- vrglvrglvrgl 3y ago[dead]
- joering2 3y agoJust my 2c. I don't trust any cloud keypasses myself, and you shouldn't either. The way I been doing this is having a regular text file with all my passwords that is then encrypted by veracrypt and encrypted file container is then hosted in a pCloud. I used to do it with DropBox until one time their new version stopped doing bit-by-bit comparison, something pCloud does.
- egberts1 3y agoUpdated: password managers, self-hosted (revision 2) 1password: since version 8, now dead for self-hosting due to "their"-cloud-only-now, not a standalone, and its downside usage of Electron web and its many unverified modules/libraries; remote storage of password only in encrypted form. Key stays offline. vaultwarden: yet another Electron web app and its usage of many unverified modules/libraries; remote storage of password only in encrypted form. Key stays offline. KeepassXC, with syncthing: leading contender, best-self-hosted solution that stores password remotely only in encrypted form. but still has iOS unverifiable source code imposed by Apple. Key stays offline. For Keepass usage on iOS/macOS platforms, consider a lifetime (one-fee) StrongBoxSafe app (Keepass-compatible) instead. NordPass: best zero knowledge remote storage; has apps for Windows, macOS, Linux, Android, and iOS. Self-hosted. When it comes to browser extensions, one would be hard-pressed to find a wider selection. You can install NordPass on Chrome, Firefox, Safari, Opera, Brave, Vivaldi, and Edge. Not an open-source. LassPass, hacked in 2022; remote storage of raw passwords pwsafe, still is the safest CLI-only solution to date. The design of pwsafe (Password Safe CLI) got started by Bruce Schnier, the crypto security privacy expert. In pwsafe, unbroken TwoFish algorithm is still being used instead of the currently safer Argon2i, simply because it's faster (after millions of iterations; also AES is not immune to hard-memory FPGA brute-force like Argon2, yet both remain hard-CPU). The recommended client-wise of PasswordSafe is still Netwrix (formerly MATESO of Germany) PasswordSafe with YubiKey. Only downside for ANY PasswordSafe-design GUI client is trusting yet another app repository and the compilation of "their copy of open source". For any password manager, stay away from its web-client variants due to ease of memory access to JavaScript variable names (by OS, browser, JS engine, and JS language)
- adultSwim 3y agohttps://web.archive.org/web/20230521122746/https://old.reddit.com/r/techsupport/comments/13nqarb/suspicious_ios_keepass_client/ https://web.archive.org/web/20230521122746/https://old.reddi...