Live data from Hacker News

MitM Attack against KeePass 2’s Update Check

bogner.sh

41–50 of 78 posts

Re: MitM Attack against KeePass 2’s Update Check

#41
post #28

Earlier quoted context omitted.

Why are you running KeePass in wine?

I have very complex password generation requirements for some of the services I need to access and KeePassX does not: 1) have nearly the same level of support for defining complex password generation rules 2) have support for saving said custom password generation as a profile So, KeePass + wine it is until I have a better alternative. :)

But why Wine?

http://packages.ubuntu.com/xenial/keepass2

Re: MitM Attack against KeePass 2’s Update Check

#42
post #28

Earlier quoted context omitted.

Why are you running KeePass in wine?

I have very complex password generation requirements for some of the services I need to access and KeePassX does not: 1) have nearly the same level of support for defining complex password generation rules 2) have support for saving said custom password generation as a profile So, KeePass + wine it is until I have a better alternative. :)

Do you have to change those passwords so frequently? You could just use an external service for creating these when needed.

Re: MitM Attack against KeePass 2’s Update Check

#43

Earlier quoted context omitted.

Why would switching to HTTPS cost him any advertising revenue?

See https://news.ycombinator.com/item?id=11803716 from yesterday

That's if they switch the entire site to https. They could just switch the update check to https and have no problems with ads (although it would be admittedly less secure).

Re: MitM Attack against KeePass 2’s Update Check

#45

The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution This doesn't entirely make sense. I'm sure it's possible to serve adverts on a HTTPS page, and let's encrypt is hardly expensive

https://news.ycombinator.com/item?id=11803716

Too many ad buyers don't have https support, so the number of bidders for the ad space is lower, meaning a lower price per ad.

Re: MitM Attack against KeePass 2’s Update Check

#46

Earlier quoted context omitted.

I have very complex password generation requirements for some of the services I need to access and KeePassX does not: 1) have nearly the same level of support for defining complex password generation rules 2) have support for saving said custom password generation as a profile So, KeePass + wine it is until I have a better alternative. :)

Do you have to change those passwords so frequently? You could just use an external service for creating these when needed.

Often enough that I don't want to have to rely on a separate script or service to generate the passwords for me and save the profiles and then copy the result into KeePass entries.

Re: MitM Attack against KeePass 2’s Update Check

#47
post #2

It's free software; You have no right to complain or dictate priorities when you aren't paying for it. You aren't the customer, KeePass 2 advertisers are. Use 1password and pay $5 a month if you want the right to complain.

Giving something away for free is not an excuse for it to provide negative value by exposing its users to MitM attacks.

Negative value is a subjective judgement.

Updates themselves are signed packages. While it's not ideal, careful users do gain value in an open, free, and mature solution.

Full disclosure: I sell a plugin for KeePass 2.

Re: MitM Attack against KeePass 2’s Update Check

#48
post #41

Earlier quoted context omitted.

I have very complex password generation requirements for some of the services I need to access and KeePassX does not: 1) have nearly the same level of support for defining complex password generation rules 2) have support for saving said custom password generation as a profile So, KeePass + wine it is until I have a better alternative. :)

But why Wine? http://packages.ubuntu.com/xenial/keepass2

Inertia. I've been using KeePass for years and I'm still on v1 because at the time the v1 database format was more well supported across all the "keepass" compatible apps on iOS, OS X, Android, etc.

What I have works for me very well although I will admit that the v2 database format is supported well enough these days that I could migrate.

Re: MitM Attack against KeePass 2’s Update Check

#50
Many years ago I reported two bugs in KeePass, one related to the tray icon, and the other related to some bad rendering in the GUI.

Both were closed, with reasons like "this is a bug in .NET", "this is a bug in Windows". Maybe they were, but somehow other applications didn't expose them. The bugs were annoying, and if it were my software I would have fixed them somehow, even if they were not my fault.

Long story short, the author gave me a bad impression, the kind of "know it all, know it best" attitude. So his refusal to fix this MITM problem doesn't surprise me one bit.

Post reply on HN