Live data from Hacker News

Non-official site with a tampered version of KeePass

security.infoteam.ch

51–60 of 82 posts

Re: Non-official site with a tampered version of KeePass

#52

Earlier quoted context omitted.

That was worded a bit ambiguously then You're not really going to get around having to install "something" to sync your passwords if you want to have your passwords synced You could use something like Syncthing if you just don't want to trust any company with your data Otherwise, I cant really suggest a solution either

> That was worded a bit ambiguously then Sorry, I hope it's clear now. > You're not really going to get around having to install "something" to sync your passwords if you want to have your passwords synced Huh? This is obviously wrong; I'm doing literally this with KeePass. I haven't installed anything, and it has a plugin to sync directly with Google Drive that doesn't mess with or care about anything in the rest of…

So then you have installed a Google drive agent, or at least you use the service? That is the problem you're discussing.

Re: Non-official site with a tampered version of KeePass

#53
post #15

What are some safety measures you take when downloading a new version of keepass? Checking the digital signature of the binary? Original keepass downloads are hosted on sourceforge which has not had the best history of integrity the way I see it.

I usually just use SHA / MD5 checksum, digital signatures

I think 7zip has a way for you to check the hash signature with just a right click on the file so thats dandy

Re: Non-official site with a tampered version of KeePass

#54
Something I don't understand though is when I do a google search, google sometimes sponsors these phony sites.

One time I downloaded the wrong google chrome which was ironic because I was on google searching it.

Other examples that come to mind with different sites are popcorn.sh vs popcorn-time.to. There not the same repository.

Normally I just do a sanity check by checking the domain URL and checking if it has authority.

If its on sourceforge... I just assume its malware or has bundled PUPware on it, run it through antivirus and SHA/MD5 checks.

Ninite.com is pretty convenient I hope they don't get comprimised one of these days and get sold to a shady vendor

Re: Non-official site with a tampered version of KeePass

#55
post #51

I've had discussions with coworkers on why you shouldn't ve downloading putty from putty.org. Sure, they seem to be linking to the official downloads now , but imho it's just poor hygiene to use such pages. It takes just a moment of carelessness to get pwned

Rather unfortunate that "putty.org" is the first result in searches and looks a lot more legit than "chiark.greenend.org.uk" even if it (currently) links there.

I've had discussions with coworkers on why they shouldn't look up "free online json beautifier" and dump thousands of lines of crown jewels into them (http too). Meanwhile we're doing web dev and JSON responses are autoformatted in Firefox dev tools so there's an amazingly convenient and perfectly safe alternative right there...

How do we impart urgency with this kind of stuff?

Re: Non-official site with a tampered version of KeePass

#56
post #15

What are some safety measures you take when downloading a new version of keepass? Checking the digital signature of the binary? Original keepass downloads are hosted on sourceforge which has not had the best history of integrity the way I see it.

I usually just use SHA / MD5 checksum, digital signatures I think 7zip has a way for you to check the hash signature with just a right click on the file so thats dandy

Are you imparting trust on checksums downloaded from the same source page?

Not implying you are but there is plenty of software where that is how they expect users to verify the integrity of the download. Useful for checking bit errors, but in the event that someone has replaced the binary then they could probably also replace the checksum...

Re: Non-official site with a tampered version of KeePass

#58
post #43
post #20

Earlier quoted context omitted.

doesnt that just imply that these scammers thought the linux userbase to be too small to be worthwhile? the comparatively small userbase is actually an underappreciated security feature of linux ;)

Isn’t that the infamous “security by obscurity”?

More or less.

As I recall, the few Mac home users in the mid-2000s were talking about how Macs couldn't get viruses as a selling point.

Re: Non-official site with a tampered version of KeePass

#59

Earlier quoted context omitted.

That was worded a bit ambiguously then You're not really going to get around having to install "something" to sync your passwords if you want to have your passwords synced You could use something like Syncthing if you just don't want to trust any company with your data Otherwise, I cant really suggest a solution either

> That was worded a bit ambiguously then Sorry, I hope it's clear now. > You're not really going to get around having to install "something" to sync your passwords if you want to have your passwords synced Huh? This is obviously wrong; I'm doing literally this with KeePass. I haven't installed anything, and it has a plugin to sync directly with Google Drive that doesn't mess with or care about anything in the rest of…

Syncthing isn't very intrusive in my experience/opinion.

I created a keepass/syncthing directory somewhere inside my home directory, and I told Syncthing to sync only that directory. And the directory only contains the Keepass database plus a few Syncthing log files and such.

Re: Non-official site with a tampered version of KeePass

#60
post #58
post #43

Earlier quoted context omitted.

Isn’t that the infamous “security by obscurity”?

More or less. As I recall, the few Mac home users in the mid-2000s were talking about how Macs couldn't get viruses as a selling point.

A few home users?

https://www.youtube.com/watch?v=ZwQpPqPKbAw

Post reply on HN