Live data from Hacker News

MitM Attack against KeePass 2’s Update Check

bogner.sh

21–30 of 78 posts

Re: MitM Attack against KeePass 2’s Update Check

#23
post #10

"Received response from Dominik Reichl: The vulnerability will not be fixed. The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution." Well the indirect costs of not fixing it just got a lot bigger. Now a lot of people will realize that their passwords are not as safe as KeePass claims they are and will switch to a different product. So this way they loose both their mon…

Maybe, maybe not. People might not notice or care. (Of course I agree that this is a poor decision security-wise.)

Re: MitM Attack against KeePass 2’s Update Check

#24
post #10

"Received response from Dominik Reichl: The vulnerability will not be fixed. The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution." Well the indirect costs of not fixing it just got a lot bigger. Now a lot of people will realize that their passwords are not as safe as KeePass claims they are and will switch to a different product. So this way they loose both their mon…

Why would switching to HTTPS cost him any advertising revenue?

Re: MitM Attack against KeePass 2’s Update Check

#25
post #6

The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution. How does HTTPS result in lost ad revenue?

1. Many ad networks do not support serving over HTTPS. 2. Serving HTTP ads only your HTTPS-only site will show scary mixed-content warnings in many browsers, driving away users.

Re: MitM Attack against KeePass 2’s Update Check

#26
post #8

I was always skeptical of KeePass which is why I've been using KeePassX. It is just a simple Qt app. Unfortunately there is no KeePassHttp support yet, so you can't hook it up to your browser, but there is a fork available with full support. https://github.com/droidmonkey/keepassx_http/

I'd probably switch to KeePassX instead of running KeePass in wine if the password generator were as flexible.

[deleted]

Re: MitM Attack against KeePass 2’s Update Check

#27
post #10

"Received response from Dominik Reichl: The vulnerability will not be fixed. The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution." Well the indirect costs of not fixing it just got a lot bigger. Now a lot of people will realize that their passwords are not as safe as KeePass claims they are and will switch to a different product. So this way they loose both their mon…

Why would switching to HTTPS cost him any advertising revenue?

See https://news.ycombinator.com/item?id=11803716 from yesterday

Re: MitM Attack against KeePass 2’s Update Check

#28
post #8

I was always skeptical of KeePass which is why I've been using KeePassX. It is just a simple Qt app. Unfortunately there is no KeePassHttp support yet, so you can't hook it up to your browser, but there is a fork available with full support. https://github.com/droidmonkey/keepassx_http/

I'd probably switch to KeePassX instead of running KeePass in wine if the password generator were as flexible.

Why are you running KeePass in wine?

Re: MitM Attack against KeePass 2’s Update Check

#29

The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution This doesn't entirely make sense. I'm sure it's possible to serve adverts on a HTTPS page, and let's encrypt is hardly expensive

> I'm sure it's possible to serve adverts on a HTTPS page

Yes, you can, but you lose a tremendous amount of ad revenue and a number of ad providers still don't support HTTPS.

Post reply on HN