7 ms·
Ok, your password database was affected by malicious modification. So what? How it can break the confidentiality of your data? Update: By the way, what's wrong
by negus 11y ago
Ok, your password database was affected by malicious modification. So what? How it can break the confidentiality of your data?
Update: By the way, what's wrong with the bytearray compare code snippet?
- justizin 11y agoI broke into your e-mail and need to get you to force a password reset on some other account, so I maliciously modify to give you an invalid stored password.
- sdrapkin 11y agoI notice that the "change-password" function of yourbank.com is accidentally being served over HTTP instead of HTTPS. I just need to trick you into changing your password. I have access to your kdbx db (ex. you sync to Dropbox and I'm Dropbox employee). I can alter the kdbx file to change your password so that it is no longer valid. KeePass doesn't complain at all. You have a WTF moment and try to change your password over HTTP, while I inspect network packets and grab your new password. You say "this is far-fetched, non-realistic scenario". I say "this is poor crypto design".
- StavrosK 11y agoWait, you just inserted an invalid password in my database, how do I change my password? Hell, the only way I'll even realize something's wrong is by trying to log in in the first place, and, if you can see my connection, why would you have me enter a wrong password, rather than the right one?
- sdrapkin 11y agoBecause the main login is HTTPS-secure (I would hope - for a bank), but the change-password feature is not.
- StavrosK 11y agoOh, you mean the account recovery page, not one that requires the old password to change to a new one. I see.
- AjithAntony 11y agoI think he's suggesting that you happen to actually know the right password, and will attempt to enter it after the failed keepass attempt? But then, if you know the right password, you could also visually inspect the keepass data to know it was wrong.
- alelefant 11y agoIf you're able to inspect the network packets and the page is over HTTP, then KeePass doesn't even matter at that point. It's game over right there.
- cmdrfred 11y agoI have a private server in a datacenter that I put together myself. I use sftp to download/upload my keepass file, I also use a keyfile that stays local and a password for auth. What is the attack vector there?
- sdrapkin 11y agoYou store u/p to your Lawyer's website, which has a copy of your Will. You die and the Executor of your Estate tries to access the Lawyer's website, only to be met with "invalid password". It turns out that the kdbx on your private server got silently corrupted (ex. fs corruption) ~5 years prior to your death. However, your Dropbox backups only have 30 days of previous kdbx versions. Can your Executor handle the disappointment? I believe this issue is grave enough.
- cmdrfred 11y agoHow are they cracking the 40+ char random alpha numeric password on my box? With fail2ban in place, and it's on a random port.
- TheDong 11y agoThat answer does not inspire confidence. 1) Random port is not helping against a specific attacker. Get a real firewall 2) Fail2ban is not a real firewall 3) Keys only, no passwords. 40chars is nothing compared to a strong rsa key with a 40char password on it
- cmdrfred 11y agoWfc.help go ahead and try.
- Guvante 11y ago> I can alter the kdbx file to change your password so that it is no longer valid. How are you generating a kdbx file that has the record where they think it is? The entire file is encrypted en-mass except the header. You can certainly make a kdbx file that KeePass will open, but it is impossible to make one that will fool the user without more than enough information to just compromise the database.
- Tomte 11y agoThe array comparison? It's literally the textbook example of a timing sidechannel. Though I won't speculate if it's a real problem here, since I have no idea what data is being compared.
- StavrosK 11y agoEven if it's the password, it's not a server/client scenario, or interactive authentication, so why would we care about a timing attack?
- imglorp 11y agoDo you care about that kind of side channel for an offline vault? If your adversaries are on your box while you operate your vault, then you have already lost because they will also have keyloggers, strace, etc.
- Nogwater 11y agoWhat if they hack your dropbox account and get a copy of the vault that way? They're not on your box, but now they can try to break into your vault.
- gnud 11y agoWell, the decryption code is open source. And they have the ciphertext. So what does a timing attack give the attacker? If keeppass removes the possible timing attack, the attacker could just add it back in and use their own client, if they have a copy of your database.
- imglorp 11y agoThen a timing side channel is not relevant, because they won't be watching you operate the vault. Right?
- benedikt 11y agoWhy be OK with bad crypto?
- 11y ago
- xenophonf 11y agoConfidentiality isn't your only concern. You should also be worried about integrity and availability. From "On The Security of Password Manager Database Formats": Unfortunately, [KDBX4] introduces new vulnerabilities. Similarly to KDB, the main problem of this format is the lack of authentication of *hdr*. As such, is it susceptible to modifications... This modification is not detectable by the password manager... if a user alters, and then saves, a corrupted database, all passwords previously affected by the attack are lost forever. This attack highlights a remarkable design flaw. Even an accidental bit-flip in the *pskey* field, e.g., due to a transmission error, cannot be detected, and leads to complete corruption of the database. Such corruption is unlikely to be immediately detected by users, who may subsequently add new entries. Over time, the database will be composed of both correct and corrupted entries, making it difficult to reconstruct the damaged records from a backup. Which reminds me - I need to migrate back to Password Safe as soon as possible.
- negus 11y agoConfidentiality is my only concern in the case of malicious modification. Remember, that availability and integrity of your database can be broken without an attacker, just due to hardware problem, for example. So it is up to you to have a cold backup for such a critical asset.
- xenophonf 11y agoMay I emphasize this sentence? Over time, the database will be composed of both correct and corrupted entries, making it difficult to reconstruct the damaged records from a backup. I don't know enough about cryptography to be able to say whether it's possible to break a particular cryptographic protocol by blindly altering the ciphertext, but I do know plenty about human nature and backups. It's _highly_ unlikely that normal people keep more than a handful of backups. My own personal backup retention limit is on the order of 30 days, and that's with careful planning. Silent, on-going data corruption happening to a password database seems like a very reasonable thing to concern oneself with, especially if one's expectation was that the password manager would throw some kind of data integrity error whenever said database was accessed.
- tptacek 11y agoThe problem is that it's usually not true that you can have confidentiality without integrity, because of chosen ciphertext attacks.