22 ms·
KeePass – questionable security
I've been a long-time user of KeePass. I inspected its 2.x .NET source code today and quickly noticed the following issues which I find quite concerning:
The kdbx database is encrypted with AES in CBC/PKCS7 mode without proper authentication. HMAC is nowhere to be found in the code, other than when used for sha1-totp. There are SHA2 hashes that seem to guard the integrity of ciphertext, while these might catch a typical file corruption they will not prevent malicious tampering. Even if the hashes are used prior to encryption, that's still MtE - not EtM.
KeePass likely does not have an online threat model, so attacks like Padding-Oracle might not be applicable, but a lack of AEAD is IMHO highly concerning because it indicates that the author(s) are winging it when it comes to doing crypto right.
Byte array comparisons are done with this function from MemUtil.cs:
public static bool ArraysEqual(byte[] x, byte[] y)
{
// Return false if one of them is null (not comparable)!
if((x == null) || (y == null)) { Debug.Assert(false); return false; }
if(x.Length != y.Length) return false;
for(int i = 0; i < x.Length; ++i)
{
if(x[i] != y[i]) return false;
}
return true;
}
There are many other questionable patterns, code smells, and "I-invented-it" approaches that indicate a non-expert .NET programming skill. They can't even implement a Singleton correctly (see CryptoRandom.cs).
Has anyone ever done a security audit of KeePass 2.x or does everyone just believe that it's "good enough"?
P.S. None of this detracts from the fact that KeePass is a very useful, free utility with a lot of effort put into it. I thank all contributors for making/improving it over the years.
- deleted 11y ago[deleted]
- negus 11y agoAnswering on whether somebody did an audit for KeePass http://keepass.info/ratings.html http://keepass.info/ratings.html I'm not sure but one may look at https://www.allianz-fuer-cybersicherheit.de/ACS/DE/_downloads/anwender/software/BSI-CS_003.html https://www.allianz-fuer-cybersicherheit.de/ACS/DE/_download... and http://www.ssi.gouv.fr/entreprise/certification_cspn/keepass-version-2-10-portable/ http://www.ssi.gouv.fr/entreprise/certification_cspn/keepass...
- FractalNerve 11y agoWhat about KeePassX? That's what I've been using for a long time now. It's not written in C#, but C++ EDIT: source: https://github.com/keepassx/keepassx https://github.com/keepassx/keepassx
- karlgrz 11y agoYea, that's what I've been using for the past 2 or 3 years, I think.
- feld 11y agoWell, the language isn't really in question here -- it's the crypto used for the database files themselves. KeePassX is the old database format and KeePass 2.x+ uses a newer one. I don't know if the database format also resulted in any crypto changes.
- sdrapkin 11y agoThere are 2 problems here. (1) The c# .NET implementation is lacking; (2) the fundamental crypto design of the kdbx database (which is shared by all implementations, in any language) is lacking.
- feld 11y agoYes, but since this isn't some networked service I'm not as concerned about the general quality of the code. Offline attacks really have to focus on the encrypted password database. If an attacker has local access you're already owned -- they could just modify the application to do whatever they want... or keylog you, etc. The safety of your database in a world where your keepass database is leaked due to a Dropbox attack or something is what really matters here, IMO. Did they screw up the crypto so offline attacks are easier?
- Locke1689 11y agoIt's not 100% offline. As you said, if they manage to access your Dropbox, they could theoretically sync an altered database back to you. If the application leaks some information while attempting to open the database or can be made to leak information, that would be bad.
- negus 11y agoOk, your password database was affected by malicious modification. So what? How it can break the confidentiality of your data? Update: By the way, what's wrong with the bytearray compare code snippet?
- justizin 11y agoI broke into your e-mail and need to get you to force a password reset on some other account, so I maliciously modify to give you an invalid stored password.
- sdrapkin 11y agoI notice that the "change-password" function of yourbank.com is accidentally being served over HTTP instead of HTTPS. I just need to trick you into changing your password. I have access to your kdbx db (ex. you sync to Dropbox and I'm Dropbox employee). I can alter the kdbx file to change your password so that it is no longer valid. KeePass doesn't complain at all. You have a WTF moment and try to change your password over HTTP, while I inspect network packets and grab your new password. You say "this is far-fetched, non-realistic scenario". I say "this is poor crypto design".
- StavrosK 11y agoWait, you just inserted an invalid password in my database, how do I change my password? Hell, the only way I'll even realize something's wrong is by trying to log in in the first place, and, if you can see my connection, why would you have me enter a wrong password, rather than the right one?
- wumbernang 11y agoIt's better than nothing and likely better than something without source. Using the CLR which has no guaranteed memory zeroing and has immutable strings and GC and an exposed profiler and debugging APi is a larger concern IMHO.
- acchow 11y ago> It's better than nothing There are real issues with a false sense of security that you're glossing over here...
- Guillaume86 11y agoI didn't check but I assume they use SecureString.
- wumbernang 11y agoI'd be surprised if they did and don't forget that it's serialized/deserialized from something which will be hanging around in the GC in the form of a memory backed stream or something too.
- alkonaut 11y ago> the CLR which has no guaranteed memory zeroing That's interesting. Can you elaborate? > and has immutable strings and GC Immutable strings is a pretty standard feature for a language, right?
- wumbernang 11y agoBasically, when an object goes out of scope, it isn't de-allocated instantly. Immutable strings aren't standard; they're an implementation choice.
- deltaecho1338 11y agoThanks for your remarks on KeePass; I have at times been a heavy user. I've often wondered about its security (especially the security of its ports) but I don't have the expertise to evaluate it myself. I'm not aware of any audits or systematic analyses as it hasn't received the attention that mobile password managers have. The truly paranoid keep their KeePass database in an encrypted volume used solely for that purpose.
- littlestitious 11y agowhat is the problem with the singleton?
- sdrapkin 11y agoAny takers on that question?
- jarito 11y agoI assume that they are implying that the code is not constant time. In this snippet, the code bails as soon as a deviation is detected. This can, in theory, allow an attacker to determine the desired value by measuring the time taken to reject incorrect options. I haven't reviewed the code to see if this is actually a problem, but that's my guess for why it was highlighted.
- philbarr 11y agoWell, it's not thread safe but they might not think that's an issue. It looks like this: private static CryptoRandom m_pInstance = null; public static CryptoRandom Instance { get { if(m_pInstance != null) return m_pInstance; m_pInstance = new CryptoRandom(); return m_pInstance; } }
- sdrapkin 11y agoPhilbarr is correct. The pattern they are using is fundamentally supposed to provide a thread-safe Singleton, and it fails to do that. Is that a security problem in this specific context? No. But it's a "No" because the authors are lucky in this case - not because they are competent. Now, that's just one instance of poor skill. There are many more. Are you sure none of them have security implications?
- xenophonf 11y ago"On The Security of Password Manager Database Formats" (https://www.cs.ox.ac.uk/files/6487/pwvault.pdf https://www.cs.ox.ac.uk/files/6487/pwvault.pdf) was a good review of KeePass, Password Safe, and others. As I understood it, only Password Safe provided both secrecy and data authenticity.
- sdrapkin 11y agoStep-1: open the above PDF. Step-2: search for "HMAC". Step-3: note which application uses HMAC. Step-4: you should prefer (3) to all others.
- xenophonf 11y agoI agree completely.
- namtrac 11y agoLinux support seems to be BETA.
- jansc 11y agoWhere did you get that information?
- abrowne 11y agohttp://passwordsafe.sourceforge.net/news.shtml http://passwordsafe.sourceforge.net/news.shtml Under 28 Dec 2014 it mentions 0.95, but there is a 0.96 from 12 June of 2015 available at http://sourceforge.net/projects/passwordsafe/files/Linux-BETA/ http://sourceforge.net/projects/passwordsafe/files/Linux-BET...
- exhilaration 11y agoA note to other 1Password users like myself, per the linked PDF 1Password does not use HMAC.
- Globz 11y agoI have been a KeePass user for many years and I always used this in conjunction with a TrueCrypt container meaning that I keep my kdbx file inside the container. Yes TrueCrypt isn't "safe" but at this point it will take one highly motivated attacker to steal my "important" passwords. Sadly I am not aware of any audits related to KeePass but I would be happy to read one!
- ethanbond 11y agoWhy do you say TrueCrypt isn't safe? I only skimmed the audit, but it seemed to have an overall positive impression, no?
- Globz 11y agoWell I believe it is safe for my personal purpose but if you read the note the author left on Truecrypt website/software you can clearly read : WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues If I recall the audit was positive but who knows why this message was plastered everywhere when "they" decided to call it quits.
- freehunter 11y ago>who knows why this message was plastered everywhere when "they" decided to call it quits. Because "they" are no longer updating it and at some point there will be security issues that will go unfixed. Same thing with Windows XP. It didn't immediately fall apart when support ended, but we were pushing so hard for it to go away because it would never see another security update. It's just really, really bad practice to use something that will never be updated, especially a security product.
- arde 11y agoWindows XP was not audited, and it's been full of bugs since day one, with new vulnerabilities every month, year after year. And it has a huge attack surface. That's hardly comparable to TrueCrypt. TrueCrypt WAS audited and yes there is a risk of some serious vulnerability being found in the future, but at least we know there's none known for now (not publicly, at least). That same risk, that some serious vulnerability could be found in the future, also affects all other existing encryption products, since none have been formally demonstrated to be secure. If I can migrate today to a different product, then I can just prepare to migrate in the future but stay with TrueCrypt until such vulnerability is found, if it ever is. There is, after all, the possibility that none will be found, and it's more likely that none will be found in TrueCrypt than it is in other non-audited products. Why should I switch now? And why would it be better today to use a product that has not been audited so far but is supposedly still being supported, instead of using one that HAS been audited even if it has been abandoned? Furthermore, currently supported products could be abandoned tomorrow too, or worse: their support could be deficient in the future. I acknowledge that your argument has some well known heavyweights backing it. Bruce Schneier mentioned this risk about TrueCrypt recently, and then he went to recommend some closed-source solution based on its creator's good vibes. Tom Ptacek also resorted to this newfangled "vibe" method in one of his comments in this very thread. I fail to see the point in all this. Maybe I'm missing something, but I find such reasonings specious. Edit: grammar.
- rhaps0dy 11y agoAnd I thought I was safe using Keepass on Dropbox. Any recommendations for password managing?
- xenophonf 11y agoPassword Safe is supposed to be the strongest. I like KeePass 2's user interface a _lot_ better, which is why I'd originally migrated away from Password Safe. However, due to KDBX4's inability to detect data corruption, I plan to migrate back to Password Safe in the very near future.
- salibhai 11y agoMore about password safe: https://www.schneier.com/passsafe.html https://www.schneier.com/passsafe.html
- freehunter 11y agoWell LastPass has had a breach now twice but the integrity of their password database is still holding strong. If you're using Dropbox to share your password database, LastPass having a breach shouldn't be of any concern. I'm fairly certain Dropbox has been broken into more times than LastPass ever will be. As someone who works in the security industry, I use LastPass and recommend it to everyone. It's no less safe than anything else + Dropbox (I really recommend against using Dropbox... use something like SpiderOak. Dropbox is not meant to be a secure file store) and the convenience is outstanding. Convenient security that everyone uses is much better than inconvenient security that no one uses. And something + Dropbox is pretty inconvenient once you're used to LastPass.
- anewhnaccount 11y agohttp://www.passwordstore.org/ http://www.passwordstore.org/
- jgrowl 11y agoIt may not be as polished as some of the other options out there, but it is what I use. I am mostly happy with it. I just wish there was a built in way to encrypt the folder structure to hide what sites I have credentials for.
- tetraodonpuffer 11y agonot built in but if you're on linux you can always overlay ecryptfs on your password safe directory, or just have your passwords in a separate vm entirely that is used only for that
- jgrowl 11y agoGood points. I've just been too lazy to encrypt the directory myself. Running a separate vm is an interesting idea that I had not thought of.
- tetraodonpuffer 11y agoI don't have it running yet but I am planning to write something where you have a vm you can connect to with the same/similar command syntax and it would pop up a window of some sort saying 'I received a request for password xyz, yes/no' this way you can have your main system and/or other vms have access to the password store in a controlled manner. If you have this vm running an FDE install then it would make it also super easy to backup all your passwords, just shutdown the vm and copy the vdi, would only be a few gigs (don't need too much software in this install, just the base system, gpg and whatever ncurses daemon to listen for password requests)
- throwaway55512 11y agoecryptfs doesn't obfuscate filenames (it is a "stacked" filesystem) so that's not going to do any good. You'll need block-level encryption such as LUKS and a loopback mount if you want to keep that hidden, at least when that partition isn't mounted.
- stephengillie 11y agoI suppose that using a random Android Keypass app is just asking for trouble.
- tptacek 11y agoI don't know that an HN thread is the best venue to discuss crypto design flaws (you might be better off writing a POC of some kind and then publishing that), but yes, it is a little disquieting to see a sensitive application using AES without an authenticator. To the many readers of this thread who believe they don't care about the integrity of their password vault, just its confidentiality: The problem is you can't necessarily have confidentiality without integrity. Sound cryptosystems that provide integrity checking rule out chosen ciphertext attacks against the cipher: in order to submit a ciphertext to such a system, you have to get past a cryptographically secure integrity check. Without that check, attackers can feed a victim systematically corrupted ciphertexts, which the victim will dutifully decrypt, and observe the behavior of the victim in handling them. This is the basis for a whole family of "error oracle" side channel attacks. You generally don't want to trust the confidentiality of a cryptosystem that doesn't check ciphertext integrity and rule out manipulated ciphertexts. As the poster points out: this might matter a lot less for a system that runs purely offline. Or it might not. I lean towards "not a super plausible attack vector". But who knows? Why be OK with bad crypto?
- mey 11y agoConsidering your background and experience, do you have a recommendation for personal level password management?
- tptacek 11y agoI use and like 1Password.
- sdrapkin 11y agoPlease remember that just because tptacek likes and uses something, do not mean that it has great security. The PDF linked below states that there is zero integrity in 1Password file format. I happen to like and use KeePass, but that is not a secure-software guarantee.
- 11y ago
- deleted 11y ago[deleted]
- clark800 11y agoOpen source, open standard, generative password manager with "two-factor" security using both a passphrase and a private key file: http://rampantlogic.com/entropass/ http://rampantlogic.com/entropass/ It only uses the industry standard pbkdf2-sha512 hashing algorithm, with no encrypted database, so it is much simpler and isn't susceptible to these kinds of issues.
- salibhai 11y agoIt looks like its mainly used for storing site login/passwords. I like to store other things too in password files like credit card numbers, notes ,etc.
- sdrapkin 11y ago1. It would be nice if someone like CodesInChaos (ie. someone with both crypto and .NET expertise) were to casually audit the KeePass 2.x codebase and do a write-up. 2. It would be nice to create a kdbx 3.0 (ix. next-gen) storage format, which does proper AEAD.
- sdrapkin 11y agoTo those who don't see a problem with leaking timing data: KeePass goes to great lengths to do in-memory encryption of data. I'm not saying these attempts are properly done, but there is certainly no lack of trying. The only reason to even bother is assume that this memory can be accessed by an attacker. So either you subscribe to that attack vector and thus must also accept the necessity of avoiding timing attacks, or you reject this threat vector and must question why KeePass engages in all kinds of memory-obfuscation security circus/theater.
- debfx 11y agoAn attacker may be able to read the unencrypted swap space on disk. In this scenario it makes sense to encrypt passwords in memory and store the key in a locked page.
- RRRA 11y agoWhat about KeePass 1.x? And considering you can freely copy the database and someone corrupting your own is "only" going to result in you not being able to login, is that really a threat model that is more important with just encrypting everything so they can't be read?
- thomp 11y agoWhat about pass (http://www.passwordstore.org/ http://www.passwordstore.org/)? No "funky file formats" -- just GPG and a convenient CLI.
- ntnn 11y ago"It's capable of temporarily putting passwords on your clipboard and tracking password changes using git." Holy moly, thats awesome. I think I'm gonna drop keepass for that.
- benoliver999 11y agoBeen using it for a month now, it's fantastic.
- rakoo 11y agoDo you use any syncing mechanism, eg syncing to a repo on Github ? The format should lend to using some remote git repo, but I'm still afraid of the implications of having my passwords in the wild, even encrypted with GPG.
- tacticus 11y agoI push it up to an encrypted disk on my VPS behind an ssh connection. the only people with access to the host are trusted people. The only way ssh access works without a key is from certain trusted networks. (over a vpn only)
- ufo 11y agoThere are two things that bug me about pass: * Website names are stored in plaintext filenames and directory hierarchies. No confidentiality and no integrity guarantees for those. * It uses GPG's public-key encryption instead of symmetric-key encription. This integrates well with gpg-agent but it means that you need to carry a gpg private-key file around with you instead of just remembering a passphrase.
- thomp 11y agoWhat about pass (http://www.passwordstore.org/ http://www.passwordstore.org/)? No "funky file formats" -- just GPG and a convenient CLI.
- Aloha 11y agoThis is why for work at least, I've kept to a spreadsheet on my workstation, the workstation uses full disk encryption, so I feel this is reasonably secure. For home, I'm nearly 100% apple, so I'm using keychain.
- AlfaWolph 11y agoAny opinion on Mitro? https://www.mitro.co/ https://www.mitro.co/
- indutny 11y agoHello! Nothing about KeePass, but recently I was wondering if I could write a software for deriving the keys from the master secret and seed (i.e. domain name or whatever). Here is what I have came with: * https://github.com/indutny/derivepass https://github.com/indutny/derivepass * https://github.com/indutny/scrypt https://github.com/indutny/scrypt It is using dump scrypt implementation (see the second link), and should be pretty easy to verify by cross-reading the source and the spec. Also, there is a boilerplate iOS application which is using `derivepass`'s derivation function and `scrypt` too. Please let me know if you have any questions!
- vixsomnis 11y agoFor anyone who has wanted to switch to KeePassX (to avoid mono dependencies, for instance), but needed the integration with keepasshttp, this project is active: https://github.com/Ivan0xFF/keepassx https://github.com/Ivan0xFF/keepassx I haven't switched yet to Ivan0xFF's port yet (I've been using the auto-type based on window title). I may not actually switch, as the Pass project some others have posted here looks very good as a cross-platform solution (e.g., there is an android app and Firefox plugin) and there are scripts for converting existing databases to the new keystore.
- emsy 11y agoI love KeepassX, but the time it takes to add features and make releases is disencouraging. I don't like that I have to use a fork for months or years because the author is to proud to let in other main contributors (this concerns open source in general, but KeepassX is a great example for this).
- Itsameee 11y agoFrom my point of view, an authenticator (e.g. HMAC) is only necessary in case of a protocol-based transmission. -> And no, I don't mean to put the file (that is completly read first) on the dropbox. An authentication between the main memory and the CPU is obviously not required.
- TimWolla 11y agoApparently someone reported this thread to the author. You might want to follow the SourceForge issue: http://sourceforge.net/p/keepass/discussion/329220/thread/2eac8c83/ http://sourceforge.net/p/keepass/discussion/329220/thread/2e...
- Spooky23 11y agoDoes this affect the older version of the format and KeePassX?
- orahlu 11y agoThese has been a security audit, ordered by the french ANSSI (French government IT Security agency). This audit resulted in a "CSPN" certificate, which basically means that 35 days were spent by a competent auditor (Thales), and no important vulnerabilities were found in KeePass 2.0 Portable. Report: http://www.ssi.gouv.fr/uploads/IMG/cspn/anssi-cspn_2010-07fr.pdf http://www.ssi.gouv.fr/uploads/IMG/cspn/anssi-cspn_2010-07fr...
- Grazester 11y agoHonest question. What's wrong with the function? I have a similar function to ironically enough compare Hmacs in an encryption program I wrote in Java and C# When I release the source code for the java version I replaced my function with java's own Arrays.equals though
- TheDong 11y agoTiming attacks. It's not a valid concern in this context, however, because an attacker attempting to bruteforce it can simply code the more efficient comparison and use it. Timing attacks are a concern on network applications or when considering a block-box type attack.
- XorNot 11y agoDon't they also generally depend on the attacker either having access to a steady stream of crypto-events, or being able to cause them? i.e. you either watch a loaded system doing encryption, or create some load and time it yourself. Neither of which would be relevant to an offline file format.
- snowwrestler 11y agoWell it sounds like you just did a security audit of KeePass, albeit an incomplete and cursory one. But as a small open-source project, that's probably better than they have now. Have you considered submitting this analysis to the KeePass team? Or even better, analysis plus suggested code to fix the problems? As a user of KeePass this would be in your interest. (And as a user of KeePass myself, it is in my interest to encourage experts to help that project out.)
- tiatia 11y agoIt is so annoying. It must be something you know (Passcode), you are (Iris) or something you have (Key). In case of Passwords, it is something you know. With limitations to the site (at least X Characters, small and capital, one number but not at the beginning, no number at the end, at least one special...). Some Banking sites even only allow a scary limited amount of characters (I think Schwab allows only 7 and no special characters). Regarding a PW Manager: I found them all annoying and one has corrupted the PW database several times, resulting in a loss of the passwords. My solution: A plain textfile with all my passwords. (I use Linux with an encrypted partition). If this is not secure enough for you, encrypt it with GPG.
- INTPenis 11y agoKeepass was never meant for corporate use, that much I am positive about. So personally I use gpg through the pass(1) script. However, for corporate use I must recommend siptrack, a Django-based webbapp with a xmlrpc gui that tries not so much to replace keepass but rather racktables and keepass. So it's much more than password management but it uses pycrypto and doesn't try to re-invent encryption. Future plans have it moving to pynacl too.
- kevinSuttle 11y agoMaybe ping the EFF? https://ssd.eff.org/en/module/how-use-keepassx https://ssd.eff.org/en/module/how-use-keepassx
- voltagex_ 11y agoWargh, I use KeePass.
- Ciantic 11y agoWhat are the alternatives really? I'd love to get rid of KeePass, it's GUI is awful, it really doesn't support OS X (unless some really technical person installs it). I'm unwilling to use commercial closed, cloud based password databases.
- jmkni 11y agoIn regards to OSX, Kypass is usable, but it's not great, or free!
- deleted 11y ago[deleted]
- g5411704 11y agoIf you are such a great expert .NET programmer what sees others errors, stop complaining and help him. You have his git and you can pull request.
- yc_Paul 11y agoKeePass from version 1.24 & 2.20 (in 2012) use header authentication to prevent data corruption attacks. http://keepass.info/help/kb/sec_issues.html http://keepass.info/help/kb/sec_issues.html cheers, Paul
- esseye 11y agoMuch like 4th page retractions on stories in newspapers, headlines will always win out in terms of the influence on the readers. That said, the author of KeePass responded to all the discussions here over on the project forum at SourceForge. Since a lot of people aren't willing to even visit SF anymore, his notable responses were: The header validation was fixed as of 2.20 in 2012 The singleton safety he was aware of, and it was only instanced prior to any threading of the application, so there could never be a thread safety issue. He has fixed this anyhow as the performance impact was minimal as of 2.30 The installers available via SF mirroring are signed by the author, so SF can not ever mess with them. They have no concerns about SF doing anything to their project.
- sdrapkin 11y agoAdditional evidence of inadequate .NET implementation: There is a ton of code & pointless complexity to minimize the time sensitive data has to remain in plaintext in memory, and zeroing buffers asap. Clearly, the "process memory compromise" threat vector is taken very seriously by the authors. Here's a KeePass function that generates a key: https://github.com/wrouesnel/keepass/blob/master/KeePassLib/Keys/CompositeKey.cs#L155 https://github.com/wrouesnel/keepass/blob/master/KeePassLib/... Does anyone see what the problem is? Hint: disposing "ms" in addition to closing will not fix the problem. There are ~ 59 instances of this mistake in the codebase. The author(s) seem to come from c/c++ background, and make all kinds of assumptions about how .NET works - except that .NET doesn't work the way they think it works. The generation of the Master Key: https://github.com/wrouesnel/keepass/blob/master/KeePassLib/Keys/CompositeKey.cs#L243 https://github.com/wrouesnel/keepass/blob/master/KeePassLib/... Note that "pbNewKey" can be sitting in memory forever. TL/DR: KeePass memory protection is completely ineffective (I only speak for .NET implementation).
- mrsaint 11y agoWould be interesting to compare the .NET implementation to the "legacy" c version, Keepass 1.x. https://github.com/joshuadugie/KeePass-1.x https://github.com/joshuadugie/KeePass-1.x
- orblivion 11y ago> online threat model Unless you keep your encrypted password database on Dropbox.
- benkibbey 11y agoI've been working on a password manager for a while now. It's been a learning experience in practically every way. I'm not a cryptographer but needed a couple features that the other password managers dont have, and would be too difficult to patch, so I wrote my own. KeePass is really good and user friendly, but like I said, is missing some things I need. It's hosted on sourceforge which I don't plan on changing since they seem to have wisened up. If you want to try it out or help with development the project page is at http://sourceforge.net/projects/pwmd/ http://sourceforge.net/projects/pwmd/.
- hansimglueck 11y agoThe author is commenting on this thread here: http://sourceforge.net/p/keepass/discussion/329220/thread/2eac8c83/ http://sourceforge.net/p/keepass/discussion/329220/thread/2e... The issues raised in the thread are documented on his webpage here: http://keepass.info/help/base/security.html http://keepass.info/help/base/security.html http://keepass.info/help/kb/sec_issues.html http://keepass.info/help/kb/sec_issues.html