Non-official site with a tampered version of KeePass
51–60 of 82 posts
Re: Non-official site with a tampered version of KeePass
#52Earlier quoted context omitted.
That was worded a bit ambiguously then You're not really going to get around having to install "something" to sync your passwords if you want to have your passwords synced You could use something like Syncthing if you just don't want to trust any company with your data Otherwise, I cant really suggest a solution either
> That was worded a bit ambiguously then Sorry, I hope it's clear now. > You're not really going to get around having to install "something" to sync your passwords if you want to have your passwords synced Huh? This is obviously wrong; I'm doing literally this with KeePass. I haven't installed anything, and it has a plugin to sync directly with Google Drive that doesn't mess with or care about anything in the rest of…
Re: Non-official site with a tampered version of KeePass
#53What are some safety measures you take when downloading a new version of keepass? Checking the digital signature of the binary? Original keepass downloads are hosted on sourceforge which has not had the best history of integrity the way I see it.
I think 7zip has a way for you to check the hash signature with just a right click on the file so thats dandy
Re: Non-official site with a tampered version of KeePass
#54One time I downloaded the wrong google chrome which was ironic because I was on google searching it.
Other examples that come to mind with different sites are popcorn.sh vs popcorn-time.to. There not the same repository.
Normally I just do a sanity check by checking the domain URL and checking if it has authority.
If its on sourceforge... I just assume its malware or has bundled PUPware on it, run it through antivirus and SHA/MD5 checks.
Ninite.com is pretty convenient I hope they don't get comprimised one of these days and get sold to a shady vendor
Re: Non-official site with a tampered version of KeePass
#55I've had discussions with coworkers on why you shouldn't ve downloading putty from putty.org. Sure, they seem to be linking to the official downloads now , but imho it's just poor hygiene to use such pages. It takes just a moment of carelessness to get pwned
I've had discussions with coworkers on why they shouldn't look up "free online json beautifier" and dump thousands of lines of crown jewels into them (http too). Meanwhile we're doing web dev and JSON responses are autoformatted in Firefox dev tools so there's an amazingly convenient and perfectly safe alternative right there...
How do we impart urgency with this kind of stuff?
Re: Non-official site with a tampered version of KeePass
#56What are some safety measures you take when downloading a new version of keepass? Checking the digital signature of the binary? Original keepass downloads are hosted on sourceforge which has not had the best history of integrity the way I see it.
I usually just use SHA / MD5 checksum, digital signatures I think 7zip has a way for you to check the hash signature with just a right click on the file so thats dandy
Not implying you are but there is plenty of software where that is how they expect users to verify the integrity of the download. Useful for checking bit errors, but in the event that someone has replaced the binary then they could probably also replace the checksum...
Re: Non-official site with a tampered version of KeePass
#57There are quite a few of these: https://keepass.fr/ https://7zip.fr https://audacity.fr https://gparted.fr https://keepass.fr https://nc3354.nexylan.net https://paintnet.fr
Re: Non-official site with a tampered version of KeePass
#58Earlier quoted context omitted.
doesnt that just imply that these scammers thought the linux userbase to be too small to be worthwhile? the comparatively small userbase is actually an underappreciated security feature of linux ;)
Isn’t that the infamous “security by obscurity”?
As I recall, the few Mac home users in the mid-2000s were talking about how Macs couldn't get viruses as a selling point.
Re: Non-official site with a tampered version of KeePass
#59Earlier quoted context omitted.
That was worded a bit ambiguously then You're not really going to get around having to install "something" to sync your passwords if you want to have your passwords synced You could use something like Syncthing if you just don't want to trust any company with your data Otherwise, I cant really suggest a solution either
> That was worded a bit ambiguously then Sorry, I hope it's clear now. > You're not really going to get around having to install "something" to sync your passwords if you want to have your passwords synced Huh? This is obviously wrong; I'm doing literally this with KeePass. I haven't installed anything, and it has a plugin to sync directly with Google Drive that doesn't mess with or care about anything in the rest of…
I created a keepass/syncthing directory somewhere inside my home directory, and I told Syncthing to sync only that directory. And the directory only contains the Keepass database plus a few Syncthing log files and such.
Re: Non-official site with a tampered version of KeePass
#60Earlier quoted context omitted.
Isn’t that the infamous “security by obscurity”?
More or less. As I recall, the few Mac home users in the mid-2000s were talking about how Macs couldn't get viruses as a selling point.