User Activity

  • Posted a comment on ticket #2845 on KeePass

    As much as I hate to say this, we should just let this thread die. @dreichl is providing a great service here but, history has shown us that they do not take input and they do not reverse their decisions even when the the impacted community does not agree with a change. And as good a programmer as they are, they are still just one person and having one person in control will means you need to be comfortable living in a dictatorship no matter how benevolent. No one can make the argument that putting...

  • Posted a comment on discussion Open Discussion on KeePass

    This is a new "feature" that is getting some pushback. It requires standard users to have administrator privileges to save some KeePass configuration options.

  • Posted a comment on discussion Open Discussion on KeePass

    @wellread1 I missed in my testing that password generators still try to save back to the enforced config file even with the MergeContentMode="Merge" configuration set, so some of my previous comments about having triggers acts the same as the password generator setting are not valid. That said, I still stand by my statement that system administrators/information security administrators are in the best position to weigh the risk and benefits of any configuration and allowing them the choice via a...

  • Modified a comment on discussion Open Discussion on KeePass

    The password profile issue is a bit of a mute point I think for this thread, since there is a configuration that allows an admin to either. 1. Enforce a set of profiles that the user cannot change. 2. Allow the user to set their own profiles. 3. Combine items #1 and #2. In cases #2 and #3 KeePass continues with no change in behavior visible to the end user, which is I think where some of us are having issues with how the Triggers now function. I agree with @wellread1 that "The KeeAutoExec plugin...

  • Posted a comment on discussion Open Discussion on KeePass

    The password profile issue is a bit of a mute point I think for this thread, since there is a configuration that allows an admin to either. 1. Enforce a set of profiles that the user cannot change. 2. Allow the user to set their own profiles. 3. Combine items #1 and #2. In cases #2 and #3 KeePass continues with no change in behavior visible to the end user, which is I think where some of us are having issues with how the Triggers now function. I agree with @wellread1 that "The KeeAutoExec plugin...

  • Posted a comment on discussion Open Discussion on KeePass

    I can see some benefits to moving the triggers, but I also see little to no value in moving the password generators options. I reserve the right to be educated but so far I have not seen a valid use case or attack scenario described that warrants this change. The argument that an attacker can force a weak or known password into the configuration is a red herring. If an attacker has enough access to change your configuration files, that resides in the user space, they most likely already have all...

  • Posted a comment on discussion Open Discussion on KeePass

    @dreichl, Thanks for your continued effort to providing a high-quality well thought-out security application. Would you please update https://keepass.info/help/kb/config_enf.html to contain the entire list of settings moved to the "Enforced Configuration" file? The 2.54 release notes mention three specific settings but also states "and a few more settings are now stored in the enforced configuration file." We admins would like to make adjustments to our enterprise configurations before our end user...

  • Modified a comment on ticket #2168 on KeePass

    I get your point, but this is a ticket not a duplicate post to a discussion. I first created the post in the discussions since the site here directs you to the discussion forums for support but then I realized you could create a ticket, since I think there is actually a bug here e.g., two components that should operate in the same way showing different behaviors. In my experience, mostly on Github, discussions and forum posts are used for two very different purposes. If that is not how SourceForge...

View All

Personal Data

Username:
sf-42
Joined:
2005-09-08 00:31:17
Location:
United States / PDT

Projects

  • No projects to display.

Personal Tools