This doesn't entirely make sense. I'm sure it's possible to serve adverts on a HTTPS page, and let's encrypt is hardly expensive
MitM Attack against KeePass 2’s Update Check
21–30 of 78 posts
Re: MitM Attack against KeePass 2’s Update Check
#22Re: MitM Attack against KeePass 2’s Update Check
#23"Received response from Dominik Reichl: The vulnerability will not be fixed. The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution." Well the indirect costs of not fixing it just got a lot bigger. Now a lot of people will realize that their passwords are not as safe as KeePass claims they are and will switch to a different product. So this way they loose both their mon…
Re: MitM Attack against KeePass 2’s Update Check
#24"Received response from Dominik Reichl: The vulnerability will not be fixed. The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution." Well the indirect costs of not fixing it just got a lot bigger. Now a lot of people will realize that their passwords are not as safe as KeePass claims they are and will switch to a different product. So this way they loose both their mon…
Re: MitM Attack against KeePass 2’s Update Check
#25The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution. How does HTTPS result in lost ad revenue?
Re: MitM Attack against KeePass 2’s Update Check
#26I was always skeptical of KeePass which is why I've been using KeePassX. It is just a simple Qt app. Unfortunately there is no KeePassHttp support yet, so you can't hook it up to your browser, but there is a fork available with full support. https://github.com/droidmonkey/keepassx_http/
I'd probably switch to KeePassX instead of running KeePass in wine if the password generator were as flexible.
Re: MitM Attack against KeePass 2’s Update Check
#27"Received response from Dominik Reichl: The vulnerability will not be fixed. The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution." Well the indirect costs of not fixing it just got a lot bigger. Now a lot of people will realize that their passwords are not as safe as KeePass claims they are and will switch to a different product. So this way they loose both their mon…
Why would switching to HTTPS cost him any advertising revenue?
Re: MitM Attack against KeePass 2’s Update Check
#28I was always skeptical of KeePass which is why I've been using KeePassX. It is just a simple Qt app. Unfortunately there is no KeePassHttp support yet, so you can't hook it up to your browser, but there is a fork available with full support. https://github.com/droidmonkey/keepassx_http/
I'd probably switch to KeePassX instead of running KeePass in wine if the password generator were as flexible.
Re: MitM Attack against KeePass 2’s Update Check
#29The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution This doesn't entirely make sense. I'm sure it's possible to serve adverts on a HTTPS page, and let's encrypt is hardly expensive
Yes, you can, but you lose a tremendous amount of ad revenue and a number of ad providers still don't support HTTPS.