Live data from Hacker News

MitM Attack against KeePass 2’s Update Check

bogner.sh

1–10 of 78 posts

Re: MitM Attack against KeePass 2’s Update Check

#3
post #2

It's free software; You have no right to complain or dictate priorities when you aren't paying for it. You aren't the customer, KeePass 2 advertisers are. Use 1password and pay $5 a month if you want the right to complain.

Projects should not be exempt from criticism just because they're free. That's a terrible attitude. The article does not attempt to dictate anything, I would not even call it a complaint. It merely points out unsafe practices and recommends a solution, in a very objective tone.

Re: MitM Attack against KeePass 2’s Update Check

#4
post #2

It's free software; You have no right to complain or dictate priorities when you aren't paying for it. You aren't the customer, KeePass 2 advertisers are. Use 1password and pay $5 a month if you want the right to complain.

That's a justifiable sentiment when people are complaining about missing features or mundane bugs, but security vulnerabilities are a whole different matter. That's causing harm, not just failing to provide value. You're still allowed to complain about a mugging you didn't pay for, after all.

Re: MitM Attack against KeePass 2’s Update Check

#5
post #2

It's free software; You have no right to complain or dictate priorities when you aren't paying for it. You aren't the customer, KeePass 2 advertisers are. Use 1password and pay $5 a month if you want the right to complain.

How about those who donate? Aren't they kind of customers? And what would you say if Linux updates could be easily changed with MitM?

Re: MitM Attack against KeePass 2’s Update Check

#7
That's wild, I didn't expect any security-centric website in 2016 to be HTTP-only! The reasoning for not doing it is weird too, they could at the very least move the update logic over to a separate SSL endpoint.

Anyway, I'm not quite sure on the differences between them but I've been using KeePassX for years and recommend it thoroughly (as long as you're not looking for a easily synced or multi-user product): https://www.keepassx.org/

Re: MitM Attack against KeePass 2’s Update Check

#8
I was always skeptical of KeePass which is why I've been using KeePassX. It is just a simple Qt app.

Unfortunately there is no KeePassHttp support yet, so you can't hook it up to your browser, but there is a fork available with full support.

https://github.com/droidmonkey/keepassx_http/

Re: MitM Attack against KeePass 2’s Update Check

#10
"Received response from Dominik Reichl: The vulnerability will not be fixed. The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution."

Well the indirect costs of not fixing it just got a lot bigger. Now a lot of people will realize that their passwords are not as safe as KeePass claims they are and will switch to a different product. So this way they loose both their money and their users' trust. Not a very good business decision.

Post reply on HN