Menu

#2773 Improve the security of password exports

KeePass_2.x
closed
nobody
None
5
2023-01-29
2022-12-09
Chris
No

can you better protect keepass for windows by disabling export in clear text without user confirmation ? Because, by default, Notepad is enough to add an export trigger in the configuration file so that an attacker can easily access all my passwords, at once without me knowing it.
Thanks

Discussion

  • Dominik Reichl

    Dominik Reichl - 2022-12-09
    • status: open --> closed
    • Group: KeePass --> KeePass_2.x
     
  • Chris

    Chris - 2022-12-09

    Why people trust keepass so they use it instead of a spreadsheet ? perhaps because it is supposed to provide additional security, simply by clicking on the 'install' button.
    And how many know that by default a simple text editor (not a spyware) will configure keepass to export, the next time they open it, all passwords in clear text without notification or confirmation?

    And above all why don't you say on your homepage : "An attacker who has write access to the KeePass configuration file can modify it maliciously and can access all your passwords" ?

    If you write "These attacks can only be prevented by keeping the environment secure", in this case why do I need keepass ?

     
    👍
    1

Log in to post a comment.