Earlier quoted context omitted.
Why are you running KeePass in wine?
I have very complex password generation requirements for some of the services I need to access and KeePassX does not: 1) have nearly the same level of support for defining complex password generation rules 2) have support for saving said custom password generation as a profile So, KeePass + wine it is until I have a better alternative. :)
MitM Attack against KeePass 2’s Update Check
41–50 of 78 posts
Re: MitM Attack against KeePass 2’s Update Check
#42Earlier quoted context omitted.
Why are you running KeePass in wine?
I have very complex password generation requirements for some of the services I need to access and KeePassX does not: 1) have nearly the same level of support for defining complex password generation rules 2) have support for saving said custom password generation as a profile So, KeePass + wine it is until I have a better alternative. :)
Re: MitM Attack against KeePass 2’s Update Check
#43Earlier quoted context omitted.
Why would switching to HTTPS cost him any advertising revenue?
See https://news.ycombinator.com/item?id=11803716 from yesterday
Re: MitM Attack against KeePass 2’s Update Check
#44I've already been slowly migrating from KeePass to https://www.passwordstore.org/ and this is just one more reason why.
Re: MitM Attack against KeePass 2’s Update Check
#45The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution This doesn't entirely make sense. I'm sure it's possible to serve adverts on a HTTPS page, and let's encrypt is hardly expensive
Too many ad buyers don't have https support, so the number of bidders for the ad space is lower, meaning a lower price per ad.
Re: MitM Attack against KeePass 2’s Update Check
#46Earlier quoted context omitted.
I have very complex password generation requirements for some of the services I need to access and KeePassX does not: 1) have nearly the same level of support for defining complex password generation rules 2) have support for saving said custom password generation as a profile So, KeePass + wine it is until I have a better alternative. :)
Do you have to change those passwords so frequently? You could just use an external service for creating these when needed.
Re: MitM Attack against KeePass 2’s Update Check
#47It's free software; You have no right to complain or dictate priorities when you aren't paying for it. You aren't the customer, KeePass 2 advertisers are. Use 1password and pay $5 a month if you want the right to complain.
Giving something away for free is not an excuse for it to provide negative value by exposing its users to MitM attacks.
Updates themselves are signed packages. While it's not ideal, careful users do gain value in an open, free, and mature solution.
Full disclosure: I sell a plugin for KeePass 2.
Re: MitM Attack against KeePass 2’s Update Check
#48Earlier quoted context omitted.
I have very complex password generation requirements for some of the services I need to access and KeePassX does not: 1) have nearly the same level of support for defining complex password generation rules 2) have support for saving said custom password generation as a profile So, KeePass + wine it is until I have a better alternative. :)
But why Wine? http://packages.ubuntu.com/xenial/keepass2
What I have works for me very well although I will admit that the v2 database format is supported well enough these days that I could migrate.
Re: MitM Attack against KeePass 2’s Update Check
#49But the excuse of the dev is bogus in any case. In is trivial to have that single file transferred via HTTPS. His ad revenue excuse makes me thing something fishy is going on here.
Re: MitM Attack against KeePass 2’s Update Check
#50Both were closed, with reasons like "this is a bug in .NET", "this is a bug in Windows". Maybe they were, but somehow other applications didn't expose them. The bugs were annoying, and if it were my software I would have fixed them somehow, even if they were not my fault.
Long story short, the author gave me a bad impression, the kind of "know it all, know it best" attitude. So his refusal to fix this MITM problem doesn't surprise me one bit.