Live data from Hacker News

MitM Attack against KeePass 2’s Update Check

bogner.sh

51–60 of 78 posts

Re: MitM Attack against KeePass 2’s Update Check

#51
post #49

Couldn't this be solved by signing the update file? But the excuse of the dev is bogus in any case. In is trivial to have that single file transferred via HTTPS. His ad revenue excuse makes me thing something fishy is going on here.

That would help, but an attacker being able to deliver an arbitrary website by MITM is still something that should be avoided.

Re: MitM Attack against KeePass 2’s Update Check

#52
post #41

Earlier quoted context omitted.

But why Wine? http://packages.ubuntu.com/xenial/keepass2

Inertia. I've been using KeePass for years and I'm still on v1 because at the time the v1 database format was more well supported across all the "keepass" compatible apps on iOS, OS X, Android, etc. What I have works for me very well although I will admit that the v2 database format is supported well enough these days that I could migrate.

Oh right, I didn't realize that people were still hanging on the legacy version. Then I suppose Wine does actually make sense

Re: MitM Attack against KeePass 2’s Update Check

#53

Earlier quoted context omitted.

Giving something away for free is not an excuse for it to provide negative value by exposing its users to MitM attacks.

Negative value is a subjective judgement. Updates themselves are signed packages. While it's not ideal, careful users do gain value in an open, free, and mature solution. Full disclosure: I sell a plugin for KeePass 2.

I'm not necessarily saying that Keepass2 provides a negative value overall. As you say, that's a subjective judgement. However, the unnecessary MitM exposure is certainly a negative value.

Re: MitM Attack against KeePass 2’s Update Check

#55
post #41

Earlier quoted context omitted.

I have very complex password generation requirements for some of the services I need to access and KeePassX does not: 1) have nearly the same level of support for defining complex password generation rules 2) have support for saving said custom password generation as a profile So, KeePass + wine it is until I have a better alternative. :)

But why Wine? http://packages.ubuntu.com/xenial/keepass2

Unfortunately, the package is just a mono-wrapped version of keepass2, and in my experience runs equally as bad, if not worse, than keepass2 under WINE.

Having used both for several months, I found the only workable option for myself was converting the database to KDB 1.x and using KeePassX.

Re: MitM Attack against KeePass 2’s Update Check

#56
post #7

That's wild, I didn't expect any security-centric website in 2016 to be HTTP-only! The reasoning for not doing it is weird too, they could at the very least move the update logic over to a separate SSL endpoint. Anyway, I'm not quite sure on the differences between them but I've been using KeePassX for years and recommend it thoroughly (as long as you're not looking for a easily synced or multi-user product): https:/…

> That's wild, I didn't expect any security-centric website in 2016 to be HTTP-only!

Both of the websites for PuTTY (www.putty.org and www.chiark.greenend.org.uk) are also non-encrypted. At least the downloads are hosted on a third server (the.earth.li) which does use HTTPS and 2048-bit GPG signatures are provided.

Re: MitM Attack against KeePass 2’s Update Check

#57
post #7

That's wild, I didn't expect any security-centric website in 2016 to be HTTP-only! The reasoning for not doing it is weird too, they could at the very least move the update logic over to a separate SSL endpoint. Anyway, I'm not quite sure on the differences between them but I've been using KeePassX for years and recommend it thoroughly (as long as you're not looking for a easily synced or multi-user product): https:/…

Thanks for the recommendation. I just switched.

Re: MitM Attack against KeePass 2’s Update Check

#58
post #10

"Received response from Dominik Reichl: The vulnerability will not be fixed. The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution." Well the indirect costs of not fixing it just got a lot bigger. Now a lot of people will realize that their passwords are not as safe as KeePass claims they are and will switch to a different product. So this way they loose both their mon…

Maybe, maybe not. People might not notice or care. (Of course I agree that this is a poor decision security-wise.)

Sure, but it seems as though the type of person who would use KeePass in the first place is the sort who would care.

Re: MitM Attack against KeePass 2’s Update Check

#59
post #2

It's free software; You have no right to complain or dictate priorities when you aren't paying for it. You aren't the customer, KeePass 2 advertisers are. Use 1password and pay $5 a month if you want the right to complain.

>You aren't the customer, KeePass 2 advertisers are.

Well certainly those advertisers will leave along with the user base. This sort of silly attitude is what keeps a lot of people from using free software to begin with.

Re: MitM Attack against KeePass 2’s Update Check

#60
post #34
post #2

It's free software; You have no right to complain or dictate priorities when you aren't paying for it. You aren't the customer, KeePass 2 advertisers are. Use 1password and pay $5 a month if you want the right to complain.

> It's free software; It is not free software, it's proprietary. Please don't use the phrase "free software" in this context, as it confuses people. It has a very specific meaning in the context of software.

'Free' has exactly two specific meanings on the context of software. Sorry to burst your bubble. The version you are referring to is irrelevant in the minds of the vast majority of people who use software.
Post reply on HN