It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
avatar
nightcraw1er.488: Where is the evidence for that? I have used keepass for ages both on main computer and portable apps. Never had any issue with it. That post you link to mainly seems to deal with this dropbox. And my recommendation is, always, don't use online services. They are always the weak link in anything you do and requires the vendor to continue to provide access. Under no circumstances would I use an online storage for anything, even synchronising favourites, do it yourself, organse it, and above all keep it away from the internet.
avatar
Lin545: ... But static data file is less probable to be corrupted than running code file. ...
Actually KeePass uses a sort of static data file. The database is, as far as I can tell, an xml file which is then encrypted.
Sure running known software means you're more likely to get pwned. But for cracking KeePass someone would most likely need to either a) get your keepass file and password or b) get malware on your computer which includes a keylogger.

Either way, if you get that far, you're SOL. If your passwords reside in a plain text file somewhere, anyone with malware monitoring your computer could likely tell the file is opened shortly before password entries are made and certainly read the passwords for various things as you enter/paste them.

Security through obscurity is oft cited as a horrible thing. If it's your only line of defense (password file) then yes it's horrible. If it's combined with some good actual security it suddenly starts making more sense. A way to increase security for KeePass and other security softwares would be for people to compile it themself, having a buildscript create executables with different names and locations for different people, maybe some code-based salt added to the file scheme. That's about as safe as you can get unless you take it completely off your computer.
Thanks for the help!
I'm using KeePass now.
Is there any must-have plugin I should install, or I should be fine just using the program without them?
I'm using version 1.29 (KeePass Classic Edition).
http://keepass.info/plugins.html
avatar
Lin545: Its just - KeePass and similar - are software. Unlike data file or piece of paper. They function like, within and depend upon software stack, require to function and are expoitable via hardware.
For fun.
avatar
_Slaugh_: These are probably the best ones...
 
 
<span class="bold">KeePass Password Safe</span>
Free and open source

<span class="bold">LastPass</span>
Free, but you need a Premium account if you want to synchronize with other devices ( $ 12 / year )

<span class="bold">1Password</span>
$ 49.99 for Windows or Mac / $ 69.99 for Windows and Mac / $ 5.99 for iOS / $ 6.49 for Android.

<span class="bold">Dashlane</span>
$ 39.99 / year

Take a look at <span class="bold">this article</span> for more info.
Hey, Slaugh!

I use lastpass free and I use it on all my devices. I'm not sure what premium gets you.
avatar
Gydion: For fun.
lol, thanks. Looks complex to use =/
avatar
misteryo: Hey, Slaugh!

I use lastpass free and I use it on all my devices. I'm not sure what premium gets you.
1)  No sync limit, can be used on unlimited devices.
2)  Joint account management.
3)  Additional authentication options, including YubiKey, Sesame and biometric authentication.
4)  Full Web access on locked-down computers.
5)  Priority support.
avatar
misteryo: Hey, Slaugh!

I use lastpass free and I use it on all my devices. I'm not sure what premium gets you.
avatar
_Slaugh_: 1) No sync limit, can be used on unlimited devices.
2) Joint account management.
3) Additional authentication options, including YubiKey, Sesame and biometric authentication.
4) Full Web access on locked-down computers.
5) Priority support.
ah! Thanks. Good to know I ain't missing anything I need at the moment