I use chat, GoogleTalk, Pidgin.. and if receive message new windows open and focus!
Problem if in same time I make Auto-Type Perform… name and password not paste in GoogleChrome but chat windows and use Enter in default auto-type, that send username and password to contact in chat! :(
I not found security option to authorize only specified windows (by tittle) to work with AutoType.
If not exist it's feature request, but perhaps I not found or not understand…
Only solution found is delete default auto-type (must specified one characters), and specified for each entry windows title with special auto-type!
Can you add option for each group to specify windows title for autotype, and if not specified disable auto-type (more security), (* for authorize for all windows = same now)
and for each entry just windows title to enable autotype if inherit default auto-type, with option to inherit windows title from parent group.
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
KeePass doesn't know anything about the window into which it types characters, it just types and checks nothing.
It may be possible to check that the window title has not changed after each keystroke, but that would make things like 2 window logins fail.
cheers, Paul
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
Keepass know the window for AutoType; I can specify windows in rule!! I not understand.
If change default autotype, and for one entry, specify special auto-type for specific Windows it's work, Keepass not send same Auto-type for this specified windows and other.
But this problem is big security problem, Auto-type must be limited for specific windows, not for all. (or same my bidouille: send nothing to all windows, but send username/password auto-type for specified windows)
I have already sended 2times password via chat (GoogleTalk), just before clic auto-type, I receive chat, and googletalk open new windows and focus it..
perhaps not explain correctly, I'm not english, and will just help to secure this good soft to not send password to all
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
Why Keepass use special method to type username/password to windows? not for better secure and block bad software intercept this copy/paste ? My suggest is just to help Keepass to going better, and share my bad adventure with chat popup (I can't disable this popub and focus function :( )
But you are right!! and why use keepass? I can use notepad!
Why try to secure their passwords, the problem is Internet!
Why have belts and doors to cars, the problem is the corners!
but thanks for your response.
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
1. KeePass is able to recognize the window, auto-type can be different for specified window!
2. KeePass uses protection during the self-auto-type called: "Two channel auto-type obfuscation"
I have changed Auto-Type seq to "Q" (must be one characters to work) and must add for each entry, Windows title and specify special Auto-Type: "{USERNAME}{TAB}{PASSWORD}{TAB} " (to secure better)
Keepass is the better password manager, with or without Auto-Type.
Perhaps you not understand my bad english. I'll wait for future releases.
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
yes, that's why, if we could define one or more windows for default Auto-type on each group with ihnerit,
would solve the problem. Can set window to "*Chrome or *Firefox….." and resolve definitively problem with window focus appear unexpectedly.
Instead of having an auto-default type for all windows is to have a specified window for each entry. and for all windows just use "*"
Just respond me to say if you not understand, If this is bad idea, I not wait update and edit all entry to add Auto-Type for specified windows. It's work but do not have the best approach.
If you would like to refer to this comment somewhere else in this project, copy and paste the following link:
I've now implemented an option to cancel auto-type when the target window changes ('Tools' -> 'Options' -> tab 'Advanced').
The option will be disabled by default, because it prevents multi-window logins from working. Note the option checks the target window handle, not its title, so multi-page logins in a browser window might work even when the option is enabled.
I use chat, GoogleTalk, Pidgin.. and if receive message new windows open and focus!
Problem if in same time I make Auto-Type Perform… name and password not paste in GoogleChrome but chat windows and use Enter in default auto-type, that send username and password to contact in chat! :(
I not found security option to authorize only specified windows (by tittle) to work with AutoType.
If not exist it's feature request, but perhaps I not found or not understand…
Only solution found is delete default auto-type (must specified one characters), and specified for each entry windows title with special auto-type!
Can you add option for each group to specify windows title for autotype, and if not specified disable auto-type (more security), (* for authorize for all windows = same now)
and for each entry just windows title to enable autotype if inherit default auto-type, with option to inherit windows title from parent group.
KeePass doesn't know anything about the window into which it types characters, it just types and checks nothing.
It may be possible to check that the window title has not changed after each keystroke, but that would make things like 2 window logins fail.
cheers, Paul
Keepass know the window for AutoType; I can specify windows in rule!! I not understand.
If change default autotype, and for one entry, specify special auto-type for specific Windows it's work, Keepass not send same Auto-type for this specified windows and other.
But this problem is big security problem, Auto-type must be limited for specific windows, not for all. (or same my bidouille: send nothing to all windows, but send username/password auto-type for specified windows)
I have already sended 2times password via chat (GoogleTalk), just before clic auto-type, I receive chat, and googletalk open new windows and focus it..
perhaps not explain correctly, I'm not english, and will just help to secure this good soft to not send password to all
The security risk is only because you have windows that pop up. It is not a risk because of KeePass.
cheers, Paul
Why Keepass use special method to type username/password to windows? not for better secure and block bad software intercept this copy/paste ? My suggest is just to help Keepass to going better, and share my bad adventure with chat popup (I can't disable this popub and focus function :( )
But you are right!! and why use keepass? I can use notepad!
Why try to secure their passwords, the problem is Internet!
Why have belts and doors to cars, the problem is the corners!
but thanks for your response.
KeePass does not use a special method, it just types characters.
Change the Auto-Type sequence to {USERNAME}{TAB}{PASSWORD}. Then it is up to you to press Enter and send the information.
cheers, Paul
1. KeePass is able to recognize the window, auto-type can be different for specified window!
2. KeePass uses protection during the self-auto-type called: "Two channel auto-type obfuscation"
I have changed Auto-Type seq to "Q" (must be one characters to work) and must add for each entry, Windows title and specify special Auto-Type: "{USERNAME}{TAB}{PASSWORD}{TAB} " (to secure better)
Keepass is the better password manager, with or without Auto-Type.
Perhaps you not understand my bad english. I'll wait for future releases.
KeePass does not check the window title during Auto-Type, only when you press the hot keys.
cheers, Paul
yes, that's why, if we could define one or more windows for default Auto-type on each group with ihnerit,
would solve the problem. Can set window to "*Chrome or *Firefox….." and resolve definitively problem with window focus appear unexpectedly.
Instead of having an auto-default type for all windows is to have a specified window for each entry. and for all windows just use "*"
Just respond me to say if you not understand, If this is bad idea, I not wait update and edit all entry to add Auto-Type for specified windows. It's work but do not have the best approach.
I've now implemented an option to cancel auto-type when the target window changes ('Tools' -> 'Options' -> tab 'Advanced').
The option will be disabled by default, because it prevents multi-window logins from working. Note the option checks the target window handle, not its title, so multi-page logins in a browser window might work even when the option is enabled.
Here's the latest development snapshot for testing (only!):
http://keepass.info/filepool/KeePass_110306c.zip
Thanks and best regards
Dominik