I recently started using KeePass and I really like it. It's a fantastic upgrade from Abine MaskMe/Blur (I don't know why I was clinging on to that). The CSV import was very smooth.
I really think that http://keepass.info needs SSL and HSTS (HSTS tells a browser to only use HTTPS for a site). It's a site dedicated to security. It's just as legitamte with or without it, but it adds a sense stronger of security to a security related product.
SSL can be had for free now from https://letsencrypt.org/. I use it on several sites and there is no drawback in strength or validation. You can use however strong ciphers you want and browsers validate it as normal. The one drawback is that the issued certificates only last three months. If you host the site with a provider with SSH access, then there are tons of programs/scripts that can renew it for you automatically. If you're using the SourceForge hosting, then it may not be worth the effort. Please conider this proposition.
Thanks!
DaAwesomeP
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
I share this concern, so I always check before I download that the link is actually pointing to SourceForge, and that the resulting download page is actually SourceForge (with valid certificate) after I click the link.
For further safety you could bookmark the sourceforge project page and go there to download updates instead of going to keepass.info. As has been noted, the update check itself, as well as the sourceforge pages, are all served over HTTPS.
The other protection, and the one recommended by Dominik, is that the installer (and app, I think) is digitally signed so that you know it has not been tampered with (if you remember to check).
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
KeePass.info is primarily an information site. It is not the KeePass download site. Links on keepass.info are offered as a convenience, but you don't need to make use of them. Instead download directly from the https download site.
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
I recently started using KeePass and I really like it. It's a fantastic upgrade from Abine MaskMe/Blur (I don't know why I was clinging on to that). The CSV import was very smooth.
I really think that http://keepass.info needs SSL and HSTS (HSTS tells a browser to only use HTTPS for a site). It's a site dedicated to security. It's just as legitamte with or without it, but it adds a sense stronger of security to a security related product.
SSL can be had for free now from https://letsencrypt.org/. I use it on several sites and there is no drawback in strength or validation. You can use however strong ciphers you want and browsers validate it as normal. The one drawback is that the issued certificates only last three months. If you host the site with a provider with SSH access, then there are tons of programs/scripts that can renew it for you automatically. If you're using the SourceForge hosting, then it may not be worth the effort. Please conider this proposition.
Thanks!
DaAwesomeP
There is no need to run the site SSL because downloads / update checks are done via SSL.
See these discussions.
https://sourceforge.net/p/keepass/discussion/329220/thread/e430cc12/
https://sourceforge.net/p/keepass/discussion/329220/thread/29e264b1/
cheers, Paul
This argument is not valid. A man in the middle could redirect you to any page looking similar to soureforge.
I share this concern, so I always check before I download that the link is actually pointing to SourceForge, and that the resulting download page is actually SourceForge (with valid certificate) after I click the link.
For further safety you could bookmark the sourceforge project page and go there to download updates instead of going to keepass.info. As has been noted, the update check itself, as well as the sourceforge pages, are all served over HTTPS.
The other protection, and the one recommended by Dominik, is that the installer (and app, I think) is digitally signed so that you know it has not been tampered with (if you remember to check).
KeePass.info is primarily an information site. It is not the KeePass download site. Links on keepass.info are offered as a convenience, but you don't need to make use of them. Instead download directly from the https download site.
Occam's Razor suggests that such an attack is unlikely at best.
cheers, Paul