[email protected] - BSI warnt vor KeePassXC-Schwachstellen

Das BSI warnt vor Schwachstellen im Passwort-Manager KeePassXC. Angreifer können Dateien oder das Master-Passwort ohne Authentifzierungsrückfrage manipulieren.

[The BSI warns of vulnerabilities in the password manager KeePassXC. Attackers can manipulate files or the master password without authentication confirmation.]

  • sudo_su
    link
    fedilink
    61 year ago

    Lock the pc, if you leave and lock the db, if pc is locked, lid is closed and this is absolute a non-issue.

    German BSI is sometimes a little bit over motivated ;-)

    • @[email protected]
      link
      fedilink
      English
      11 year ago

      This is also the vulnerability that made many people delete Keepass 2 for XC many months ago so it is very strange that they make an article that sounds like it’s a new vulnerability.

      • Veloxization
        link
        fedilink
        English
        1
        edit-2
        1 year ago

        gotcha

        Added to original comment. Both are recent issues, so confusion is forgivable.

    • @[email protected]
      link
      fedilink
      3
      edit-2
      1 year ago

      On Jerboa(List View) the link is on the thumbail, maybe it’s the same in the browser version. Keep in mind that the article on heise is in german.

    • @[email protected]
      link
      fedilink
      2
      edit-2
      1 year ago

      there is.

      But I agree that the UI distracts from the fundamentals in these early days, still