KeePassXC security audit published, recommends this security setting
#1
Exclamation 
Quote:[Image: security-header.jpg]

KeePassXC is a popular password manager for Windows, Mac and Linux that uses the KDBX file format from the password manager KeePass.

The developers of KeePassXC have published the results of a security audit on their website yesterday. The audit was conducted by Zaur Molotnikov, who is a Munich-based software engineer. Molotnikov's CV is listed on his website.

The audit was conducted free of charge, and while there is some rumbling about potential conflicts of interests on Hacker News, it is irrelevant for the purpose of the article that you are reading now.

Interested users may check out the full audit report here. The author makes several suggestions to the KeePassXC development team and also to users of the application. A core suggestion is to make sure that the latest database format is being used.

How to verify the KeePAssXC database format

[Image: keepassxc-encryption.png]

KeePassXC users have two options during the creation of a new database in regards to the format. The application supports KBSX 3 and KBDX 4, with version four the more advanced format.

The makers suggest to users to use the latest format, by marking it as recommended. This is also the recommendation of KeePass. In fact, the only reason for selecting KDBX 3 is backwards compatibility.

KeePass users, regardless of which port they use, often use different applications to bring support to their other devices. There are several Android apps available, and if one of these does not support the KDBX 4 database format, the less secure database format three needs to be used.

Long-time users of KeePassXC may also use the older format. The new format includes major security improvements, such as support for Argon2 or improved header and data authentication.

KeePassXC users may verify the used database format in the following way:
  1. Open KeePassXC and unlock the password database that you want to check.
  2. Select Database > Database Security.
  3. Switch to Encryption Settings.
  4. Check the Database format option.
If you see KDBX 3, the old format is used. Switching to the new format is a matter of a few clicks. You may copy the database file on the computer's hard drive first for backup purposes. All data should remain accessible though and the process is quick.
  1. Select KDBX 4 (recommended) from the menu.
  2. Select OK.
That is all to it. The new database format offers better security and should be used, unless compatibility stands in the way; this is actually true for all applications that use the KeePass database format to protect user secrets.

Now You: do you use KeePassXC, KeePass, or another program?
...
Continue Reading
Reply


Messages In This Thread
KeePassXC security audit published, recommends this security setting - by harlan4096 - 16 April 23, 08:10

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Surfshark VPN : Award-winning VPN servi...
Surfshark Apps Ver...jasonX — 04:41
Surfshark VPN : Award-winning VPN servi...
Surfshark launches...jasonX — 03:43
ESET 19.1.12.0
Changes in 19.1.12...harlan4096 — 14:49
Vivaldi 7.9 Build 3970.47
Vivaldi 7.9 Build ...harlan4096 — 07:31
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 07:25

[-]
Birthdays
Today's Birthdays
avatar (41)alapesihy
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (48)cticigges
avatar (50)ecoFit
avatar (44)soccejeS
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (46)JamesZic
avatar (43)Sanfordbup
avatar (38)Der.Reisende
avatar (36)Kiran78

[-]
Online Staff
mjcn19's profile mjcn19

>