Menu

My Keepass v2.28 has been compromised

Alicia
2015-03-13
2015-03-14
  • Alicia

    Alicia - 2015-03-13

    Slightly over six weeks ago I flew into Singapore to interview some Singaporeans who had suffered alleged human rights abuses.

    As I was leaving the country's airport to return to my home country in which my UN-affliated NGO is based, I was stopped by its homeland security officers and taken to a special interrogation room. I was held for about three hours during which I was forced to undergo a thorough body search by a female officer, empty my luggage and switch on my laptop computer. One of the officers then copied the contents of my computer onto his device. To cap it all, I had to sign a form declaring that I would not publish the results of my interview in any part of the world.

    A few days after my return, I was shocked to discover that some of the web-based email providers had reported unauthorized logins to my email accounts. Moreover I received emails from human rights organisations advising me to reset my login passwords.

    To clarify, I store all my passwords in Keepass v2.28 and I am using Microsoft Windows 8.1 Pro. Each time before I open it, I need to locate the key-file and then type in my password.

    It is clear that the Singaporean authorities who copied the contents of my laptop computer had managed to decipher, that is, decrypt my password.

    I hope my experience will serve as a warning to Keepass users to not be complacent into thinking their passwords and key-files are secure.

     
  • wellread1

    wellread1 - 2015-03-13

    It is clear that the Singaporean authorities who copied the contents of my laptop computer had managed to decipher, that is, decrypt my password.

    KeePass does not store the master password or a encrypted version of it. The master password can't be deciphered/decrypted as long as you don't store it on the computer or use it to protect something that does store it. However, a password can be guessed, which is why it is important to use a strong password that is resistant to being discovered by guessing.

    I was shocked to discover that some of the web-based email providers had reported unauthorized logins to my email accounts.

    Your observation does not mean KeePass was compromised. Your email passwords may be stored in an email client, or a browser password cache.

    I need to locate the key-file and then type in my password.

    Hiding a key file on your computer is like hiding your house key under a rock. A determined searcher is likely to find it.

    I hope my experience will serve as a warning to Keepass users to not be complacent into thinking their ... key-files are secure.

    KeePass does not protect key files. Key files protect a KeePass password database. To provide security, a key file must be kept secure. If a key file is stored on the computer it does not provide any protection to KeePass password database. In your case (where your possessions were seized) it may not have been possible keep the key file away from security. This is a well known fundamental problem of relying on something you have to provide security as opposed to something you know.

     

    Last edit: wellread1 2015-03-13
    • Alicia

      Alicia - 2015-03-13

      Thanks a lot for taking the time to answer my post.

      The master password can't be deciphered/decrypted as long as you don't store it on the computer or use it to protect something that does store it.

      I never store my master password on my computer. I memorise it.

      I also do not use it to protect stuff that does store it.

      However, a password can be guessed, which is why it is important to use a strong password that is resistant to being discovered by guessing.

      My compromised master password can never be guessed at all. It does not have anything to do with my personal particulars (date of birth, date of marriage, social security number) or those of my husband or children. It is not based on my pet animals either.

      Your email passwords may be stored in an email client, or a browser password cache.

      I never store my email passwords in an email client. My browser is Mozilla Firefox and under the "Privacy" tab, my settings are to "Never store history" and to "Clear all current history" when exiting Firefox.

      Key files protect a KeePass password database.

      I am confused. I thought both the master password and the key-file protect a Keepass password database??

      To provide security, a key file must be kept secure.

      What do you mean? What are the ways to keep a key file secure?

      If a key file is stored on the computer it does not provide any protection to KeePass password database.

      I am confused. Both the master password and the key-file are needed to protect the Keepass password database, right? You cannot open the Keepass password database with just the key-file alone, you need the master password as well, yes?

      Or, do you mean to tell me that the key-file contains the master password?

      N.B.: Just so that we are on the same wavelength, my definition of "Keepass password database" is the database that contains all my passwords.

       
  • wellread1

    wellread1 - 2015-03-13

    I never store my master password on my computer. I memorise it.
    I also do not use it to protect stuff that does store it.
    I never store my email passwords in an email client. My browser is Mozilla Firefox and under the "Privacy" tab, my settings are to "Never store history" and to "Clear all current history" when exiting Firefox.

    That is good, if the officials did not guess your master password and find your key file, and your KeePass password database was not already open on the seized computer, then the officials could not open your KeePass password database. If the officials discovered your email credentials, they found them by some means other than opening your KeePass password database.

    Both the master password and the key-file are needed to protect the Keepass password database, right?

    Correct. However if the key file is found by an attacker it contributes nothing to securing your database. For the key file to be effective you must secure it (or be in a position to destroy it). In the instance you describe, you could not secure your key file (it was on the copied computer). If officials found the key file, you were relying on your master password alone to secure the password database.

     

    Last edit: wellread1 2015-03-13
  • Steven Campbell

    Steven Campbell - 2015-03-14

    As soon as the officer touched your laptop and connected something to it, it was game over. That laptop was potentially compromised and anything you typed or viewed after that point could have been exposed.

    Another very real possibility is that you connected to an open wifi, e.g. in the airport or at the hotel or a mall. The wifi may have presented what appeared to be a login to your email website, but was actually a fake. Attackers may have gained your email passwords that way.

    If I suspected the security officer, I would assume that any accounts on web-sites or applications that I had logged into on that laptop since the trip are compromised. Depending on the sophistication, the infection could also have spread to other PCs on a home network.

    I would aggressively check for malware (e.g. download malwarebytes), and change all my passwords (on a different device), starting with email. Depending on how paranoid I was feeling, I might even do a full wipe of the laptop and sell it on ebay.

     
  • Alicia

    Alicia - 2015-03-14

    That is good, if the officials did not guess your master password and find your key file,

    I can safely assume that the officials would not be able to guess my master password. It consisted of 20 characters with empty spaces in between and is not based on my personal particulars (date of birth, date of marriage, social security number) or those of my husband or children. It is not based on my pet animals either.

    But I have to assume they managed to locate my key-file because they copied all the contents of my laptop computer.

    and your KeePass password database was not already open on the seized computer,

    No, it wasn't already open. My laptop computer was in my bag that I was carrying. I was not sitting in a cafe working on my machine when approached by some Singaporean homeland security officers.

    If officials found the key file, you were relying on your master password alone to secure the password database.

    Is relying on my master password alone enough to secure my Keepass password database?

    Moreover as soon as I suspected that my Keepass database might have been compromised, I quickly changed my master password-key file combination to one with at least 300 bits. Is that the correct procedure?

     
  • Alicia

    Alicia - 2015-03-14

    As soon as the officer touched your laptop and connected something to it, it was game over. That laptop was potentially compromised and anything you typed or viewed after that point could have been exposed.

    I suppose you were referring to the malware discovered by Kaspersky Labs. Kaspersky named the malicious people as "The Equation Group" affiliated with the American National Security Agency. (cf. https://www.reddit.com/r/news/comments/2w4ihb/kaspersky_labs_has_uncovered_a_malware_publisher/)

    Well, for your info, I did research a bit about the malware and read extensively on Kaspersky's website. It appears that Kaspersky's antivirus and anti-malware program is able to detect the presence of the NSA's malware. But the aforementioned software only works on Microsoft Windows OS.

    Kaspersky provides a trial version of its antivirus and anti-malware software. I downloaded it and scanned my machine for malware. Nothing came up.

    Can I assume that the homeland security officer did not compromise my machine?

    Moreover I re-flashed my machine's BIOS. Is this move sufficient to remove any malware that might reside in my machine's BIOS?

    Another very real possibility is that you connected to an open wifi, e.g. in the airport or at the hotel or a mall.

    I don't make use of open wifi at the airport or a shopping mall. But I do connect to open wifi at my hotel where I was staying during the duration of my assignment.

    My hotel only provided wifi and it had a captive portal into which I must typed the login credentials provided by the hotel before I could access the internet. After logging in, I was then able to surf the internet and to access my web-based email inboxes.

    The wifi may have presented what appeared to be a login to your email website, but was actually a fake.

    I would think that's very improbable because I manually type in the URL of the web-based email provider each time I wish to access my email inbox.

    Depending on the sophistication, the infection could also have spread to other PCs on a home network.

    Kaspersky's report on the NSA's "Equation Group" gave me the impression that only machines using the Microsoft Windows OS can be compromised. Further examples include Stuxnet and Flame viruses that only wreak havoc on Microsoft Windows-based machines. The machines on which Stuxnet caused mayhem to the Iranians were all using Microsoft Windows OS.

    Suppose I switch to using a FOSS Unix-like operating system such as Ubuntu, Debian, Gentoo, Arch Linux, FreeBSD or OpenBSD. Can I assume that whatever the Singaporean homeland security officer had introduced to surreptitiously infect my laptop computer would be rendered impotent?

    I would aggressively check for malware (e.g. download malwarebytes),

    Kaspersky provides a trial version of its antivirus and anti-malware software. I downloaded it and scanned my machine for malware. Nothing came up.

    The reason I scanned my compromised machine with a Kaspersky product is the said company informed the world that "The Equation Group" had been infecting computers. It wasn't malwarebytes, McAfee, Trend Micro or Symantec that first drew our attention to the dirty tricks of the NSA.

    Depending on how paranoid I was feeling, I might even do a full wipe of the laptop and sell it on ebay.

    Let me offer a better alternative to selling an infected computer to an unsuspecting customer.

    I would give it to my young son to use it. If the NSA is snooping on what they thought are my online activities, they will soon find out that the online activities are those of a typical young boy. They will be so awesomely bored and disappointed. It will be an awesome victory for me.

     
  • Paul

    Paul - 2015-03-14

    To be sure it's not your computer that has been compromised I would transfer the KeePass database to another computer and use that to reset your passwords. Then I would replace the hard disk on your laptop with a new one and re-install everything from scratch.

    It is more likely that your email was compromised using the copy of your data, assuming you don't actively log out of your email after use, or use a timeout.

    cheers, Paul

    p.s. Given your security requirements you should run all internet connections through a VPN, then there can be no man-in-the-middle issues.

     
  • Steven Campbell

    Steven Campbell - 2015-03-14

    This is getting off-topic for this forum so out of respect for others, this will my last post on this thread.

    I was not referring to any particular attack, only that physical access to a logged-in laptop typically trumps software defense. I am not a hacker and would not do this, but if I was and I had malicious intentions and access to your logged in Windows laptop for 10 minutes, chances are good that I would have installed a keylogger, a rootkit, and whatever else I could. The rootkit would bypass your security software, and the keylogger would send everything you typed to one of my servers on the Internet.

    It was not clear to me if the security officer made you log-in to the laptop. If not, they would have had far less options, and then the best they could do would be to make a copy of your hard drive. If that is the scenario then your laptop may be clean.

    The wifi attack is statistically more likely to have been the problem. For wifi attacks where the attacker has gained control over the wifi access point, it does not matter what url you typed - the wifi can return a different url, and it is easy to miss. The only clue would be in the browser address bar, which would not be showing a green lock, and would show a different url than the one you typed. As Paul mentioned, a VPN tunnel can protect against this.

    Regarding KeePass, it is possible to brute force attack (i.e. guess the password) if the password is weak, but for your scenario of a strong password + keyfile, brute force is not feasible on today's hardware. There are just too many possibilities to guess.

    With a key file known only to you, in theory you could expose your KeePass database file to everyone in the world and the contents would still be totally unreadable. Personally I wouldn't do it, but I am quite comfortable storing my KeePass database in the cloud, which is almost the same.

    Regarding OS - yes, Windows is undoubtably the easiest OS for attackers to target. Switching to just about any alternative is more secure. This is just my opinion, but ranked from easiest to attack to least: Windows, Android (phone/tablet), MacBook, iOS (iPhone, iPad), Linux, ChromeBook.

    For ebay, I did not mean that I would sell the computer while still infected - that would be irresponsible. I would secure-wipe it first, i.e. zero out the hard disk and reinstall the OS.

     

Log in to post a comment.