{"id":603083,"date":"2023-01-31T07:49:31","date_gmt":"2023-01-31T13:49:31","guid":{"rendered":"https:\/\/news.sellorbuyhomefast.com\/index.php\/2023\/01\/31\/this-huge-password-manager-exploit-may-never-get-fixed\/"},"modified":"2023-01-31T07:49:31","modified_gmt":"2023-01-31T13:49:31","slug":"this-huge-password-manager-exploit-may-never-get-fixed","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2023\/01\/31\/this-huge-password-manager-exploit-may-never-get-fixed\/","title":{"rendered":"This huge password manager exploit may never get fixed"},"content":{"rendered":"<article id=\"dt-post-content\" itemid=\"post-content\" itemprop=\"articleBody\">\n<p>It\u2019s been a bad few months for password managers \u2014 albeit mostly just for LastPass. But after the revelations that LastPass had <a href=\"https:\/\/www.digitaltrends.com\/computing\/stop-using-lastpass-says-security-firm\/\">suffered a major breach<\/a>, attention is now turning to open-source manager KeePass.<\/p>\n<p>Accusations have been flying that a new vulnerability allows hackers to surreptitiously steal a user\u2019s entire password database in unencrypted plaintext. That\u2019s an incredibly serious claim, but KeePass\u2019s developers are disputing it.<\/p>\n<figure id=\"attachment_3028922\" aria-describedby=\"caption-attachment-3028922\"><img src=\"https:\/\/www.digitaltrends.com\/wp-content\/uploads\/2022\/03\/security-breach-warning.jpg?fit=720%2C381&#038;p=1\" onerror=\"dti_load_error(this)\" decoding=\"async\" alt=\"A large monitor displaying a security hacking breach warning.\" previous-src=\"https:\/\/www.digitaltrends.com\/wp-content\/uploads\/2022\/03\/security-breach-warning.jpg?fit=720%2C381&#038;p=1\"><figcaption id=\"caption-attachment-3028922\"><span><a href=\"https:\/\/www.gettyimages.co.uk\/detail\/photo\/security-breach-warning-in-big-monitor-displaying-royalty-free-image\/1321216765\" rel=\"nofollow noskim\">Stock Depot\/Getty Images<\/a><\/span><\/figcaption><\/figure>\n<p>KeePass is an open-source <a href=\"https:\/\/www.digitaltrends.com\/computing\/best-password-managers\/\">password manager<\/a> that stores its contents on a user\u2019s device, rather than in the cloud like rival offerings. Like many other apps, however, its password vault can be protected with a master password.<\/p>\n<p>The vulnerability, logged as <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-24055\" target=\"_blank\" rel=\"noopener\">CVE-2023-24055<\/a>, is available to anyone with write access to a user\u2019s system. Once that\u2019s been obtained, a threat actor can add commands to KeePass\u2019s XML configuration file that automatically export the app\u2019s database \u2014 including all usernames and passwords \u2014 into an unencrypted plaintext file.<\/p>\n<p>Thanks to the changes made to the XML file, the process is all done automatically in the background, so users are not alerted that their database has been exported. The threat actor can then extract the exported database to a computer or server they control.<\/p>\n<h2><a id=\"dt-heading-it-wont-be-fixed\" aria-label=\"It won\u2019t be fixed\"><\/a>It won\u2019t be fixed<\/h2>\n<figure id=\"attachment_3078343\" aria-describedby=\"caption-attachment-3078343\"><img src=\"https:\/\/www.digitaltrends.com\/wp-content\/uploads\/2022\/05\/hacker-breaking-into-a-system-using-computer.jpg?fit=720%2C480&#038;p=1\" onerror=\"dti_load_error(this)\" decoding=\"async\" alt=\"A depiction of a hacker breaking into a system via the use of code.\" previous-src=\"https:\/\/www.digitaltrends.com\/wp-content\/uploads\/2022\/05\/hacker-breaking-into-a-system-using-computer.jpg?fit=720%2C480&#038;p=1\"><figcaption id=\"caption-attachment-3078343\"><span><a href=\"https:\/\/www.gettyimages.co.uk\/detail\/photo\/dangerous-hooded-hacker-breaks-into-government-data-royalty-free-image\/955703042\" rel=\"nofollow noskim\">Getty Images<\/a><\/span><\/figcaption><\/figure>\n<p>However, the developers of KeePass have disputed the classification of the process as a vulnerability, since anyone who has write access to a device can get their hands on the password database using different (sometimes simpler) methods.<\/p>\n<p>In other words, once someone has access to your device, this kind of XML exploit is unnecessary. Attackers could install a keylogger to get the master password, for instance. The line of reasoning is that worrying about this kind of attack is like shutting the door after the horse has bolted. If an attacker has access to your computer, fixing the XML exploit won\u2019t help.<\/p>\n<p>The solution, the developers argue, is \u201ckeeping the environment secure (by using an anti-virus software, a firewall, not opening unknown e-mail attachments, etc.). KeePass cannot magically run securely in an insecure environment.\u201d<\/p>\n<h2><a id=\"dt-heading-what-can-you-do\" aria-label=\"What can you do?\"><\/a>What can you do?<\/h2>\n<figure><img src=\"https:\/\/www.digitaltrends.com\/wp-content\/uploads\/2022\/12\/password-manager-lifestyle-image.jpg?fit=720%2C540&#038;p=1\" onerror=\"dti_load_error(this)\" decoding=\"async\" alt=\"password manager lifestyle image\" previous-src=\"https:\/\/www.digitaltrends.com\/wp-content\/uploads\/2022\/12\/password-manager-lifestyle-image.jpg?fit=720%2C540&#038;p=1\"><\/figure>\n<p>While KeePass\u2019s developers appear unwilling to fix the issue, there are steps you can take yourself. The best thing to do is to create an <a href=\"https:\/\/keepass.info\/help\/kb\/config_enf.html\" target=\"_blank\" rel=\"noopener\">enforced configuration file<\/a>. This will take precedence over other config files, mitigating any malicious changes made by outside forces (such as that used in the database export vulnerability).<\/p>\n<p>You\u2019ll also need to make sure regular users do not have write access to any important files or folders contained within the KeePass directory, and that both the KeePass .exe file and the enforced configuration file are in the same folder.<\/p>\n<p>And if you don\u2019t feel comfortable continuing to use KeePass, there are plenty of other options. Try switching to one of the <a href=\"https:\/\/www.digitaltrends.com\/computing\/best-password-managers\/\">best password managers<\/a> to keep your logins and credit card details safer than ever.<\/p>\n<p>While this is undoubtedly more bad news for the world of password managers, these apps are still worth using. They can help you create <a href=\"https:\/\/www.digitaltrends.com\/computing\/how-to-clean-up-your-passwords\/\">strong, unique passwords<\/a> that are encrypted on all your devices. That\u2019s far safer than <a href=\"https:\/\/www.digitaltrends.com\/computing\/apple-google-microsoft-new-password-standard\/\">using \u201c123456\u201d for every account<\/a>.<\/p>\n<div data-location=\"below-content\">\n<p><img decoding=\"async\" src=\"https:\/\/www.digitaltrends.com\/wp-content\/uploads\/2023\/01\/dt-daily-logo.png?fit=430%2C140&#038;p=1\">\n\t<\/p>\n<div>\n<p>\n\t\t\tToday&#8217;s tech news, curated and condensed for your inbox\t\t<\/p>\n<div data-recipient-list-id=\"63cefa9b42d5ee001edfb994\">\n<p><i><\/i><br \/>\n\t\t\t\t<span><br \/>\n\t\t\t\t\tCheck your inbox!\t\t\t\t<\/span>\n\t\t\t<\/p>\n<div>\n<p>\n\t\t\t\t\tPlease provide a valid email address to continue.\t\t\t\t<\/p>\n<p>\n\t\t\t\t\tThis email address is currently on file. If you are not receiving newsletters, please check your spam folder.\t\t\t\t<\/p>\n<p>\n\t\t\t\t\tSorry, an error occurred during subscription. Please try again later.\t\t\t\t<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<h4>\n\tEditors&#8217; Recommendations<\/h4>\n<ul>\n<li>\n\t\t\t<a href=\"https:\/\/www.digitaltrends.com\/computing\/best-versions-windows-of-all-time\/\"><br \/>\n\t\t\t\tRanking all 12 versions of Windows, from worst to best\t\t\t<\/a>\n\t\t<\/li>\n<li>\n\t\t\t<a href=\"https:\/\/www.digitaltrends.com\/computing\/hackers-dug-deep-in-lastpass-security-breach\/\"><br \/>\n\t\t\t\tHackers dug deep in the massive LastPass security breach\t\t\t<\/a>\n\t\t<\/li>\n<li>\n\t\t\t<a href=\"https:\/\/www.digitaltrends.com\/computing\/paypal-data-breach-leaks-personal-data\/\"><br \/>\n\t\t\t\tIf you use PayPal, your personal data may have been compromised\t\t\t<\/a>\n\t\t<\/li>\n<li>\n\t\t\t<a href=\"https:\/\/www.digitaltrends.com\/computing\/best-password-managers\/\"><br \/>\n\t\t\t\tThe best password managers for 2023\t\t\t<\/a>\n\t\t<\/li>\n<li>\n\t\t\t<a href=\"https:\/\/www.digitaltrends.com\/computing\/character-ai-how-to-use\/\"><br \/>\n\t\t\t\tCharacter.AI: how to use this entertaining ChatGPT alternative\t\t\t<\/a>\n\t\t<\/li>\n<\/ul>\n<p>\t\t\t\t<span id=\"publisher-md\" itemprop=\"publisher\" itemscope itemtype=\"https:\/\/schema.org\/Organization\"><br \/>\n\t\t\t\t\t<span itemprop=\"url\" itemtype=\"https:\/\/schema.org\/Url\" content=\"https:\/\/www.digitaltrends.com\"><br \/>\n\t\t\t\t\t\t<span itemprop=\"logo\" itemscope itemtype=\"https:\/\/schema.org\/ImageObject\"><br \/>\n\t\t\t\t\t\t\t<meta itemprop=\"url\" content=\"https:\/\/cdn.dtcn.com\/dt\/dt-logo-small.png\"><br \/>\n\t\t\t\t\t\t\t<meta itemprop=\"width\" content=\"0\"><br \/>\n\t\t\t\t\t\t\t<meta itemprop=\"height\" content=\"0\"><br \/>\n\t\t\t\t\t\t<\/span><\/p>\n<p>\t\t\t\t\t\t<meta itemprop=\"name\" content=\"Digital Trends\"><br \/>\n\t\t\t\t\t<\/span><\/p>\n<p>\t\t\t\t\t<span itemprop=\"image\" itemscope itemtype=\"https:\/\/schema.org\/ImageObject\"><br \/>\n\t\t\t\t\t\t<meta itemprop=\"url\" content=\"https:\/\/www.digitaltrends.com\/wp-content\/uploads\/2022\/03\/security-breach-warning.jpg?p=1\"><br \/>\n\t\t\t\t\t<\/span><br \/>\n\t\t\t\t<\/span><br \/>\n\t\t\t\t\t\t<br \/><a href=\"https:\/\/www.digitaltrends.com\/computing\/keepass-password-manager-exploit-no-fix\/\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Alex Blake<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It\u2019s been a bad few months for password managers \u2014 albeit mostly just for LastPass. But after the revelations that LastPass had suffered a major breach, attention is now turning to open-source manager KeePass. Accusations have been flying that a new vulnerability allows hackers to surreptitiously steal a user\u2019s entire password database in unencrypted plaintext.<\/p>\n","protected":false},"author":1,"featured_media":603084,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[209,4382,46],"tags":[],"class_list":["post-603083","post","type-post","status-publish","format-standard","has-post-thumbnail","category-manager","category-password","category-technology"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/603083","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=603083"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/603083\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/603084"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=603083"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=603083"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=603083"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}