We can have a better solution than captcha. Right after main() we will have a function called bot_check() the bot check will find its pid, its ppid and its pppid this should be fine. if the called program is a launcher or OS specific program on that platform, it will just open if ppid is some other app other than OS kernel app, the browser/keypass will alert that some new program has launched and come the user screen to accept with a message OR deny and stop. This will stop 99% program controlled...
Titanic The unsinkable ship by design sunk. There was not one error. I read there was some 27 defects happened on that day there is a official website which logged 10 of the reason. That was a postmortom analysis. IF we can fix one thing at hand now, remaining 26 to be fixed else were which we neither know or even predict or plan now. Just put the CAPTCHA. STOP THE BOTS OR OTHER PROGRAMS. AT LEAST WE WOULD HAVE MADE KeePass 100% PERFECT TODAY. I AM least bothered about the statistical numbers about...
KeePass should never be used to break KeePass. or programmatically call KeePass by other apps I am perfectly fine humans using it. I had a requirement to validate 25 million url. with a 4 line code in unix I did it. it took 15 days by a simple code, but all were checked to be working fine. i just used unix scripts - 4 lines. May be there is a better way. it is not about fast, it is about design. I lived in USA 1997 to 2001 I had a oracle DBA life. I faced the biggest problem in identity theft. Someone...
My Real and ACtual point is, Even if you know the password,- because it leads to other password database machine should not be able to login. It should only be human who can login. THIS IS THE FIX that I am looking for. This is like putting a PIN for a chip credit card, Even if someone gets the card, it is of no use. Note in US they do not have the PIN and online password So if you loose the card logically, you loose everything. This suggestion is like bringing 2nd factor authentication to banks...
My Real and ACtual point is, Even if you know the password,- because it leads to other password database machine should not be able to login. It should only be human who can login. THIS IS THE FIX that I am looking for. This is like putting a PIN for a chip credit card, Even if someone gets the card, it is of no use. Note in US they do not have the PIN and online password So if you loose the card logically, you loose everything. This suggestion is like bringing 2nd factor authentication to banks...
My Real and ACtual point is, Even if you know the password,- because it leads to other password database machine should not be able to login. It should only be human who can login. THIS IS THE FIX that I am looking for. This is like putting a PIN for a chip credit card, Even if someone gets the card, it is of no use. Note in US they do not have the PIN and online password So if you loose the card logically, you loose everything. This suggestion is like bringing 2nd factor authentication to banks...
Thank you for your comments, Slow is fine, Still it is a possibility. That possibility, we need to stop it by design and not by speed. This is my humble request Thank you once again.
I have keypass - unix version. in unix we have awk sed ksh. these tools can be used to try one of 1 million possible passwords - grabbed from other sites in less than 1 minute or even in 1 hour. There should be some option in keePass - because it is a free download so that it can only be opened by humans and not by applications or ksh or bash or gawk with system option. Software should not be launching KeePass. Bots will benefit. That has to be stopped.