KeeWeb: Unofficial KeePass web and desktop client
121–125 of 125 posts
Re: KeeWeb: Unofficial KeePass web and desktop client
#122Re: KeeWeb: Unofficial KeePass web and desktop client
#123The reference implementation's domain is vulnerable to MITM attacks between KeeWeb and CloudFlare until they set their CloudFlare crypto settings to "strict" and get some real certificates of their own (e.g. Let's Encrypt). I submitted an issue here: https://github.com/antelle/keeweb/issues/111 Of course exploiting this would be very difficult, but it is possible to MITM the connection between the CloudFlare proxy an…
Re: KeeWeb: Unofficial KeePass web and desktop client
#124Earlier quoted context omitted.
No, it's not worse for your scenario. (That wasn't my assertion) However, this is an alternative to KeePass/KeePassX, so the typical behavior of KeePass users is to generate passwords with it, not reuse bad passwords. For example, I use KeePassX to generate strong passwords for long-term encrypted archives, and if I switched to this app, I wouldn't get the same security. I'm confused, though, should I say: "All right…
I use KeePass and I don't use it to generate passwords. It's a pain to open and close every time I need to login somewhere, especially if I'm on mobile. I use it for when I forget my passwords, and I honestly believe that is the common use case, but who knows?
I use KeePass across a range of devices, including my phone and laptop. I keep the dictionary synced with Syncthing.
I use it regularly to generate new passwords for websites, refreshing old website passwords (hello Heartbleed!) and logging into existing accounts. I also lock down the security questions so they can't be guessed. I'm now logged out of most services by default, especially banking, and the dictionary auto-locks after a short time.
Once I accepted a small price of inconvenience in setup and use, it has a positive impact. Now I remember only one password and updates are kept in sync across all my stuff.