Menu

KeePass security audit

DKueche
2015-05-13
2015-06-14
  • DKueche

    DKueche - 2015-05-13

    I was wondering whether KeePass has been audited lately?

    If so how recent was it conducted and what were the results?

     
  • wellread1

    wellread1 - 2015-05-13

    I am not aware of any published audits. However the source code is available for review.

    KeePass has also received recommendations and certifications from various agencies listed on the KeePass Awards, Ratings and Opinion page (e.g. Federal Office for Information Security (Germany) and a Certification Report from ANSSI: French Network and Information Security Agency).

     
  • DKueche

    DKueche - 2015-05-15

    Thanks for the link, but to be perfectly honest with you there, the awards from the various websites don't say much about the security.

    And at least for the Federal Office for Information Security (Germany), I can say that they're not really crypto/programming experts, they're managers.

     
  • Curious

    Curious - 2015-06-08

    I hadn't thought about this but this is an interesting questions. It's great that the source code is open but are there any third party certifications or writeups of examinations of the source code of Keepass out there?

    Thanks

     
  • Paul

    Paul - 2015-06-09

    The problem with code audits is that someone has to spend time doing it and that costs. At present there doesn't seem to be a move to organize an audit.

    cheers, Paul

     
  • Perry Nguyen

    Perry Nguyen - 2015-06-14

    I wouldn't call it much of an audit, but I didn't notice anything glaring when I performed a line by line port of KeePassLib to java (keepassj). There's nothing to say about the rest of keepass however; I didn't look at it as part of the port

     

Log in to post a comment.