3 ms·
Discussion on CVE-2023–35866 (regarding KeePassXC)
- SeriousM 3y agoThat's kinda the same "attack" as extracting stored passwords of >your favorite browser< with a binary with userspace-rights. It is already a problem if a binary has your rights and it needs to be addressed how it get thus far, no matter what it does in your rights context.
- hyperman1 3y agoA comparable issue: Feynman noticed unlocked safes were vulnerable to get their code stolen. It seems this principle holds for a lot of things: Try to keep secure storage locked if not in use. From the top if my head: Our web password vault is 1 xss bug away from being cloned if open. Same for my bank website. Full disk encryption does not help against files like pgpass being read by malware if I am logged in Passwords not in memory can't end up in a core dump. Browser stored passwords also seem vulnerable. Etc....
- NikkiA 3y ago> A comparable issue: Feynman noticed unlocked safes were vulnerable to get their code stolen. That would imply that the CVE is that the master password can be gained from an open kdbx, but that hasn't been my understanding, it's just that the contents can be re-saved with a new master password. Which is more of an analogy to the contents of the safe being vulnerable to be stolen if it's left unlocked.
- jdmg94 3y agoclassic layer 8 issue