Keepass

KeePassX 2.0 Alpha 5 releasedPosted by by Felix Geyer on 20. December 2013

I’m happy to announce the fifth alpha release of KeePassX 2.0 as an early Christmas present

The most important changes are:

  • Support copying entries and groups using drag’n’drop
  • Open last used databases on startup
  • Made the kdbx file parser more robust
  • Only edit entries on doubleclick (not single) or with enter key
  • Allow removing multiple entries
  • Added option to minimize window when copying data to clipboard
  • Save password generator settings
  • Fixed auto-type producing wrong chars in some keyboard configurations
  • Added some more actions to the toolbar

Special thanks to Albert Weichselbraun for reworking the X11 auto-type code, fixing the bug mentioned above and making it much more maintainable.

Please test the new version and report any issues at https://www.keepassx.org/dev/.

Download:

  • Source code
  • Mac OS X bundle
  • Windows bundle
  • Full list of files includes GPG signatures (signed by 0x83135D45)

You can also checkout the latest source code from our git repository at https://github.com/keepassx/keepassx.

Beware: this is an alpha release. While I believe the code base is already rather stable make sure to regularly backup your database.

Why doesn’t KeePass lock after Auto-Type?

KeePass 1.x Only
I have enabled the «Use alternative auto-type method (minimize window)»
and
«Lock workspace when minimizing the main window» options. Why doesn’t
KeePass lock after auto-typing?

In this very special case, the window minimization only is a way to lose the
focus, i.e. the window below comes to the foreground. The minimization is not
user-initiated (it’s only a side-effect of auto-type),
nor a consequence of an external minimization command, therefore
it is not (and should not be) affected by the automatic workspace locking handler.
If you worry about having KeePass minimized and unlocked, enable the
«Automatically lock workspace after the following number of seconds»
option and specify a reasonable amount.

KeePass 2.x Only
This does not apply to KeePass 2.x.

Why doesn’t printing work in KeePass 1.x?

Symptoms: When trying to print a password list in KeePass 1.x,
nothing happens after clicking OK in the ‘Print Options’ dialog.

Cause: KeePass 1.x uses the application associated with
files to print the password list. If this application doesn’t support the
«print» shell verb (like Mozilla Firefox), nothing happens.

Resolution: Associate files with a different
application that supports the «print» shell verb (like Internet Explorer).

Alternative Resolution / Workaround:
Click ‘File’ → ‘Print Preview’ in KeePass 1.x and
manually print the document in the application that just opened the file.

KeePassX 2.0.3 releasedPosted by by Felix Geyer on 8. October 2016

We’re happy to announce the latest bugfix release of KeePassX.

Full changelog:

  • Improved error reporting when reading / writing databases fails.
  • Display an error message when opening a custom icon fails.
  • Detect custom icon format based on contents instead of the filename.
  • Keep symlink intact when saving databases. .
  • Fix a crash when deleting parent group of recycle bin.
  • Display a confirm dialog before moving an entry to the recycle bin.
  • Repair UUIDs of inconsistent history items.
  • Only include top-level windows in auto-type window list when using gnome-shell.
  • Update translations.

You can fetch the new release from the downloads page.

Key Hashing and Key Derivation

SHA-256 is used for compressing the components
of the composite master key
(consisting of a password, a key file, a Windows user account key
and/or a key provided by a plugin) to a 256-bit key K.

SHA-256 is a cryptographic hash function that is considered to be
very secure. It has been standardized in
NIST FIPS 180-4.
The attack against SHA-1 discovered in 2005 does not affect
the security of SHA-256.

In order to generate the key for the encryption algorithm,
K is transformed using a key derivation function (with
a random salt). This prevents precomputation of keys and makes dictionary
and guessing attacks harder. For details, see the section
».

Printing creates a temporary file. Will it be erased securely?

KeePass creates a temporary HTML file when printing password lists and showing
print previews. This file is securely deleted when closing the database.

You must wait for the file being printed completely before closing KeePass
(and close the print preview before closing KeePass), otherwise it could happen
that the printing application blocks KeePass from deleting the file.

There is no way around the temporary file in the current printing system.
If you want to write a plugin that directly sends the data to the printer, you can
find a plugin development tutorial here:
KeePass 2.x Plugin Development.

How to store and work with large amounts of (formatted) text?

KeePass 1.x Only
There is no direct support for storing and working with large formatted texts.

KeePass 2.x Only

KeePass has a built-in editor that allows working conveniently with
large amounts of (formatted) texts.
To add a large text to an entry, import the file as attachment
(or click ‘Attach’ → ‘Create Empty Attachment’).
The built-in editor supports *.TXT (simple text) and *.RTF (formatted text) files.
In order to edit an attachment, right-click onto the entry in the main window,
point on ‘Attachments’ and click ‘YourFile.*‘. Alternatively,
if the text file
is the only attachment, you can even open it by just double-clicking onto
it in the main window (enable showing the attachment column in ‘View’ →
‘Show Columns’ → ‘Attachments’). Alternatively, it’s also possible to click the name of
the attachment in the entry details view in the main window.
For TXT files, the built-in editor supports standard operations like cut,
copy, paste, undo, word wrap, etc. For RTF files, additionally standard formatting
commands are available: choosing the font, font size, bold, italic, underline,
strikeout, text and background colors, align left/center/right, etc.

General information

When downloading KeePass, you have the choice between 3 different packages:

  • KeePass-2.xx-Setup.exe: An installer program for Windows.
  • KeePass-2.xx.zip: A KeePass ZIP package (portable version).
  • KeePass-2.xx-Source.zip: The source code.

The installer and the portable version are described in detail below.

The source code package contains everything you need to compile KeePass.
It includes the C#/C++ source code and header files, resource files,
sources for building the installer, etc.

Updating KeePass:
When a new KeePass version has been released, you can update your existing KeePass
installation, without losing any configuration settings. The steps are
depending on which package you are using (installer or portable), see below.

Translations should also be updated when you install a new KeePass version.
You can find the latest translation files here:
KeePass Translations.

Как работает менеджер паролей KeePass?

У менеджера много функций для более точной настройки и персонализации, но большая часть из них опциональна.

Студенческое соревнование по кибербезопасности «Кибервызов: новый уровень»

29–31 августа, онлайн, беcплатно

tproger.ru

События и курсы на tproger.ru

Принцип работы прост: у вас есть один мастер-пароль, который нужен для доступа к базе с остальными вашими паролями. В менеджер можно записывать как придуманные вами пароли, так и генерировать их автоматически — тогда они будут представлять собой случайную последовательность символов, например YF2JOekNoozosT8Zl8W1. Второй вариант обычно безопаснее.

Не беспокойтесь, переписывать вручную их не придётся — сохранённые пароли копируются из программы и вставляются в нужное поле.

Why does KeePass 2.x show a FIPS compliance error at startup?

Symptoms: When trying to run KeePass 2.x,
you get an error message like the following:«This implementation is not part of the Windows Platform FIPS validated
cryptographic algorithms.»
.

Cause: KeePass uses the AES/Rijndael encryption and SHA-256
hashing algorithms, for which the Microsoft .NET Framework provides
implementations. These implementations might not be FIPS compliant.
If the local security policy of the system enforces the usage of
FIPS compliant implementations, KeePass cannot run and shows an
error message.

Resolution: Configure the local security policy of the
system to allow FIPS non-compliant algorithm implementations. To
do this, go to Control PanelAdministrative Tools
Local Security Policy, open Local Policies
Security Options, and change the option
‘System cryptography: Use FIPS compliant algorithms for encryption,
hashing, and signing’
to ‘Disabled’.

Alternative resolution: Download and run the following
Windows registry file:
FipsDisable.reg.
By running this file (i.e. importing the modifications in this file
into the registry), FIPS compliance enforcement is disabled.

Note: Currently only weaker cryptographic algorithms
in the Microsoft .NET Framework are FIPS compliant. As security is the
top priority for the KeePass project, an option to use these weaker
FIPS compliant algorithms will not be added.
Future .NET frameworks might have FIPS compliant implementations of
the algorithms that KeePass requires.

Specialized Spyware

This section gives answers to questions like the following:

  • Would encrypting the configuration file increase security by preventing
    changes by a malicious program?
  • Would encrypting the application (executable file, eventually together
    with the configuration file) increase security by preventing changes
    by a malicious program?
  • Would an option to prevent plugins from being loaded increase security?
  • Would storing security options in the database (to override the settings of
    the KeePass instance) increase security?
  • Would locking the main window in such a way that only auto-type is allowed
    increase security?

The answer to all these questions is: no. Adding any of these features
would not increase security.

All security features in KeePass protect against generic threats like
keyloggers, clipboard monitors, password control monitors, etc. (and against
non-runtime attacks on the database, memory dump analyzers, …).
However in all the questions above we are assuming that there is a spyware
program running on the system that is specialized on attacking KeePass.

For example, consider the following very simple spyware specialized
for KeePass: an application that waits for KeePass to be started, then hides
the started application and imitates KeePass itself. All interactions
(like entering a password for decrypting the configuration, etc.) can be
simulated.
The only way to discover this spyware is to use a program that the spyware
does not know about or cannot manipulate (secure desktop);
in any case it cannot be KeePass.

Changes from 2.42.1 to 2.43:

New Features:

  • Added tooltips for certain
    options
    in the password generator dialog.
  • Added option ‘Remember password hiding setting in the main
    window’ (in ‘Tools’ → ‘Options’ → tab ‘Advanced’; the
    option is turned on by default).
  • Added yellow intermediate step in
    password quality progress bars.
  • When the
    field in the entry editing dialog is
    not empty, but the URL field
    is empty, a warning is displayed now.
  • When an explicit request to generate a password fails (for
    instance due to an invalid
    ),
    an error message is displayed now.
  • Added trigger events
    ‘Synchronizing database file’ and ‘Synchronized database file’.
  • Enhanced the Password Agent import
    module to support XML files created by version 3.
  • The »
    configuration setting can now also
    be set to an XSD duration instead of an XSD date (for
    periodic master key change recommendations).
  • KeePass now excludes itself from Windows Error Reporting.
  • On Unix-like systems, file transactions now preserve the Unix
    file access permissions, the user ID and the group ID.
  • Added workaround for .NET initial focus bug.

Improvements:

  • Auto-Type:
    improved sending of modifier keys.
  • Auto-Type: improved sending of characters that are realized
    with Ctrl+Alt/AltGr.
  • Auto-Type: improved compatibility with VMware Remote Console
    and Dameware Mini Remote Control.
  • Improved main window state handling.
  • Improved construction and updates of the main menu and the
    group/entry context menus.
  • Main menu items can now be deselected by pressing the Esc key.
  • Top-level nodes in tree views cannot be collapsed anymore if
    no root lines are displayed.
  • New entries in a group with the e-mail folder icon now have
    the e-mail icon by default.
  • Improved performance of automatic scrolling in the main entry
    list.
  • If user names are hidden in the main window, no user name
    suggestions are displayed in the entry editing dialog anymore.
  • Function keys without modifiers can be registered as system-wide
    hot keys now.
  • For file rename/move web requests, a canonical representation
    of the destination name/path is used now.
  • URL override base placeholders
    can now be used within
    placeholders.
  • Directly after an import, the deleted object information is
    now applied/removed (depending on the last modification time
    and the deletion time).
  • Improved compatibility of the ‘Delete Duplicate Entries’ command with the
    .
  • Improved handling of command lines containing quotes or
    backslashes.
  • Various UI text improvements.
  • Various code optimizations.
  • Minor other improvements.

Bugfixes:

(None).

Is Auto-Type keylogger-safe?

Is the Auto-Type feature resistant to keyloggers?

KeePass 1.x Only
No.
The Auto-Type feature has been designed in a way that it’s impossible for
target applications to distinguish real keys from auto-typed ones. This
on the one hand has the advantage that the feature is really compatible with
all applications out there. On the other hand, the auto-typed keys can of
course be logged by keyloggers.
If you worry about keyloggers, you have to use one of the other
methods (drag&drop, copying to clipboard, KeeForm, …).

KeePass 2.x Only
By default: no. The Auto-Type method in KeePass 2.x works the same as the one in
1.x and consequently is not keylogger-safe.
However, KeePass features an alternative method called
Two-Channel Auto-Type Obfuscation (TCATO),
which renders keyloggers useless. This is an opt-in feature (because it
doesn’t work with all windows) and must be enabled for entries manually.
See the TCATO documentation for details.

Enter Master Key on Secure Desktop (Protection against Keyloggers)

KeePass 2.x has an option (in ‘Tools’ → ‘Options’ → tab ‘Security’)
to show the master key dialog on a different/secure desktop
(supported on Windows 2000 and higher), similar to Windows’
User Account Control (UAC). Almost no keylogger works on a secure desktop.

The option is turned off by default for compatibility reasons.

More information can be found on the
Secure Desktop
help page.

KeePass 2.x Only
Note that auto-type can be secured against keyloggers, too, by using
Two-Channel Auto-Type Obfuscation.

Note: KeePass was one of the first password managers that allow
entering the master key on a different/secure desktop!

Strong Security

  • KeePass supports the Advanced Encryption Standard (AES, Rijndael) and the Twofish
    algorithm to encrypt its password databases.
    Both of these ciphers are regarded as being very secure.
    AES e.g. became effective as a U.S. Federal government standard
    and is approved by the National Security Agency (NSA)
    for top secret information.
  • The complete database is encrypted, not only the password fields.
    So, your user names, notes, etc. are encrypted, too.
  • SHA-256 is used to hash the master key components.
    SHA-256 is a 256-bit cryptographically secure one-way hash function.
    No attacks are known yet against SHA-256.
    The output is transformed using a key derivation function.
  • Protection against dictionary and guessing attacks: by transforming
    the master key component hash using a key derivation function (AES-KDF,
    Argon2, …), dictionary and guessing attacks can be made harder.
  • Process memory protection: your passwords are encrypted while KeePass
    is running, so even when the operating system dumps the KeePass
    process to disk, your passwords aren’t revealed.
  • Protected in-memory streams: when loading the inner XML format,
    passwords are encrypted using a session key.
  • Security-enhanced password edit controls: KeePass is the first password
    manager that features security-enhanced password edit
    controls. None of the available password edit control spies work against these controls.
    The passwords entered in those controls aren’t even visible in the process memory of KeePass.
  • The master key dialog can be shown on a secure desktop, on which almost no
    keylogger works. Auto-Type can be protected against keyloggers, too.
  • See also the security information page.

Changes from 2.43 to 2.44:

New Features:

  • Added option ‘Use file transactions for writing
    configuration
    settings’ (turned on by default).
  • If the option ‘Do not store data in the Windows clipboard
    history and the cloud clipboard’ is turned on (which it is by
    default), KeePass now additionally excludes its clipboard
    contents from processing by Windows’ internal
    ClipboardMonitor component.
  • Added commands to find database files (‘File’ → ‘Open’ →
    ‘Find Files’ and ‘Find Files (In Folder)’).
  • Added ‘Edit’ menu in the

    (including new ‘Select All’ and ‘Find’ commands with keyboard shortcuts).

  • Added keyboard shortcuts for formatting commands in the
    internal text editor.
  • Added ‘Cancel’ button in the save confirmation dialog of the
    internal text editor.
  • Added and
    placeholders, which
    get/set the clipboard content.
  • Added support for importing
    True Key 4 CSV files.
  • Added command line options for adding/removing scheme-specific
    URL overrides.
  • Added an auto-type event for plugins.
  • When loading a plugin on a Unix-like system fails, the error
    message now includes a hint that the ‘mono-complete’ package
    may be required.
  • In order to avoid a Windows Input Method Editor (IME) bug
    (resulting in a black screen and/or an IME/CTF process with
    high CPU usage), KeePass now disables the IME on
    secure desktops.

Improvements:

  • Auto-Type: improved
    compatibility with VMware Workstation.
  • Auto-Type into virtual machines: improved compatibility with
    certain guest systems.
  • The option to use the ‘Clipboard Viewer Ignore’ clipboard
    format is now turned on by default.
  • Improved menu/toolbar item state updating in the internal
    text editor.
  • Improved performance of Spr compilations.
  • Before writing a local configuration file whose path has been
    specified using the »
    command line parameter,
    KeePass now tries to create the parent directory, if it does
    not exist yet.
  • Improved conversion of file URIs to local file paths.
  • Improved compatibility of the list view dialog with plugins.
  • If ChaCha20 is selected as file
    ,
    the database is now saved in the
    KDBX 4 format (thanks to
    AMOSSYS).
  • Minor
    improvements.
  • HTML export/printing: KeePass now generates HTML 5 documents
    (instead of XHTML 1.0 documents).
  • HTML export/printing: improved internal CSS.
  • HTML exports do not contain temporary content identifiers
    anymore.
  • XSL files: HTML output now conforms to HTML 5 instead of
    XHTML 1.0.
  • XSL files: improved internal CSS.
  • CHM pages are now rendered in the highest standards mode
    supported by Internet Explorer (EdgeHTML mode).
  • Migrated most of the documentation from XHTML 1.0 to HTML 5.
  • Various code optimizations.
  • Minor other improvements.

Bugfixes:

  • In the internal text editor, the ‘Delete’ command does not
    reset RTF text formattings anymore.
  • The
    bit 219 (for hiding the passwords) now
    works as intended.

Why does KeePass 2.x crash when starting it from a network drive/share?

Symptoms: When trying to run KeePass 2.x from a network drive/share,
you get an error message like the following:«Application has generated an exception that could not be
handled»
or«KeePass has encountered a problem and needs to close».

Cause: The strict default security policy by the Microsoft .NET
Framework disallows running .NET applications from a network drive/share.

Recommended resolution: Copy/install KeePass 2.x onto a local hard
disk, and run the copy.

Alternative, not recommended resolution:
Configure the security policy to allow running .NET applications from
network drives/shares. Ask your administrator to do this (administrative
rights are required). If you have administrative rights and want to do
it yourself, you can use the

Code Access Security Policy Tool (Caspol.exe)
that ships with the .NET framework (helpful instructions can be found

here and

here).

Can Auto-Type locate child controls?

No. Auto-Type only checks whether the title of the currently active top level
window matches.

Browsers like Mozilla Firefox completely draw the window (all controls)
themselves, without using standard Windows controls. Consequently it is
technically impossible for KeePass to check whether a URL matches (methods
like creating a screenshot and using optical character recognition
are not reliable and secure). Also, it’s impossible to check which child
control currently has the focus. These problems can only be avoided by using
browser integration plugins, i.e. not using auto-type at all.

The user must make sure that the focus
is placed in the correct control before starting auto-type.

Running KeePass under Wine (Linux, Mac OS X, BSD, …)

Although you can run KeePass 2.x more or less natively on Unix-like systems
using Mono (see above), the user interface does not always look pretty.
Some users therefore prefer running KeePass 2.x under Wine.

In order to run KeePass 2.x under Wine, follow these steps:

  1. Make sure that Wine is installed.
    Typically the package to install is called .
  2. Make sure that .NET Framework 4.5 or higher is installed in Wine, see
    WineHQ AppDB: .NET Framework.
    For installing .NET Framework 4.5, can be used, see
    WineHQ AppDB: .NET Framework 4.5.
  3. Download the latest portable package of KeePass 2.x (ZIP file) and unpack it
    into some directory of your choice.
  4. Run .

Theme.
By default, Wine uses the classic Windows theme. If you prefer some other
theme, you can install it in ‘Applications’ → ‘Wine’ → ‘Configure Wine’ →
tab ‘Desktop Integration’.
Links to themes can for instance be found on
Wikipedia: Windows XP visual styles.

Auto-Type.
Wine currently does not implement all Windows API functions required for
auto-type, i.e. auto-type does not work when running KeePass under Wine.

Installer program (KeePass-2.xx-Setup.exe file)

The KeePass development team provides an installer, which copies KeePass
to your hard disk, creates shortcuts in the start menu and associates
KDBX files with KeePass, if desired.

Additionally, KeePass is automatically configured to store its settings in
the application data directory of the current user.
This way multiple users can use one KeePass
installation without overwriting each other’s settings (each user has his
own configuration file).
The setup program must run with administrative
rights, however KeePass runs fine without administrative rights once it
is installed.

Installation:
To install KeePass, run the file
and follow the wizard.

Updating:
Run the file.
You do not need to uninstall the old version first.
Your configuration options will not be lost.

Uninstallation:
In order to uninstall KeePass, run the uninstallation program, which is
accessible by a shortcut in the start menu folder of KeePass, or in
the program section of the system control panel. If you also want
to remove your configuration settings, you need to delete the configuration
file
in the application data directory of your user profile, see
Configuration.

Silent Installation:
The KeePass installer supports command line
switches for silent installation, i.e. the program gets installed without
asking the user for target directory or association options. The default settings
of the installer are used.

The command line switch performs a silent
installation and shows a status dialog during the setup process. No questions
will be asked though.

The command line switch performs a silent
installation and does not show a status dialog during the setup process.

Destination Path:
The installer allows to choose the destination path to which KeePass is
installed.
However, when the installer detects an existing KeePass installation, it
assumes that the user wants to perform an upgrade and thus doesn’t
display the destination path selection page; the old version will be overwritten
by the new version.
If you want to move an existing KeePass installation to a different path,
first uninstall the old version; the installer of the new version will then
display the destination path selection page again.

Options/Components:
The installation options/components are explained in detail here:
.

Translations

Installation:

  1. Left-click the download link of the language of your choice
    (for KeePass 1.x click the » link;
    for KeePass 2.x click the » link).
    Unpack the downloaded ZIP file (to the current directory).
  2. In KeePass, click ‘View’ → ‘Change Language’ → button
    ‘Open Folder’; KeePass now opens a folder called ‘Languages’.
    Move the unpacked file(s) into the ‘Languages’ folder.
  3. Switch to KeePass, click ‘View’ → ‘Change Language’,
    and select your language. Restart KeePass.

If you are using an old version, please have a look in the
1.x /
2.x
translation archives.

Language Author Downloads
Arabic

M. Abdulaziz
(2.x),
S. Al-Farhood

and A. Gharbeia (1.x)

Belarusian Andrew Gavrushenko N/A
Bulgarian I. Georgiev
(2.x),
DonAngel
(1.x)
Burmese T. Hlaing (2.x), R. Kyaw (1.x)
Catalan Albert Morera
Chinese, Simp. Leo Dou
Chinese, Trad. Kao Shiang-Yuan
Croatian I. Bunjevac
(2.x),
D. Vuković (1.x)
Czech M. Pavelka and M. Klíma and R. Tlapák (2.x),
T. Glabasňa and P. Chramosta (1.x)
Danish Christian Staal
Dutch Hilbrand Edskes
English Dominik Reichl Built-in, no download
Estonian A. Kuhlberg (2.x), A. Viiand
(1.x)
Finnish K. Eveli (2.x), A. Tähtinen (1.x)
French Ronan Plantec
Galician Jesús Amieiro N/A
German Dominik Reichl
Greek M. Ntovas-Tzimas
(2.x),
S. Vradelis (1.x)
Hebrew Oded Eli
(2.x),
Tomer Shalev
(1.x)
Hungarian Pc and Pc Szerviz (2.x), Zotius and Herka (1.x)
Icelandic Stefán Örvar Sigmundsson N/A
Indonesian Vaksin.com N/A
Italian

Mauro Rossi

and Luca ‘Hexaae’ Longone

Japanese Hiroki Matsumoto
Korean Airplanez
(2.x),
P. D. Beom
(1.x)
Latin Mikael Hiort af Ornäs
(2.x),
Akkadites (1.x)
Latvian Kārlis Šteinbergs Dev.
Lithuanian Vytautas Rėkus
Macedonian Oliver Noveski N/A
Malay, Bahasa Melayu Khairul Nizam Bin Taha N/A
Norwegian, Bokmål J.-T. Edvardsen
(2.x),
K. Schjønhaug
(1.x)
Norwegian, Nynorsk Yngve Spjeld Landro N/A
Pashto Mostafa Sadat N/A
Persian Iriman (2.x), Torment (1.x)
Polish Marcin Czerwien
Portuguese, BR C. Mantovani
(2.x),
MCHAL (1.x)
Portuguese, PT José Gonçalves
Punjabi, Indian Gurmeet Singh Kochar N/A
Romanian F. C. Russen
,
R. Velcsov
Russian Dmitry Yerokhin
Serbian, Cyrillic Ljuba Ćirović
Serbian, Latin Ljuba Ćirović
Slovak Marián Hikaník
Slovenian P. Klofutar, Z. P. Lipičnik, I. Osredkar
Spanish Marcel Trujillo
Swedish Bo Schöllin (2.x),
J. Boström
(1.x)
Thai L. Suwancharthree, P. Kaephukhieo N/A
Turkish Kaya Zeren
Ukrainian Oleksii Zinchuk
(2.x & 1.x),
Artem Polivanchuk
(2.x)
Vietnamese Hà Mạnh Tuấn ,
Trần Minh Phương

Note: if you want to update an existing translation or create a translation
that doesn’t exist yet, please first contact the current translator(s)!

Thanks to the following people for maintaining translations in the past:
Michael Åström (Swedish up to 0.92a),
Maciej Chojnacki (Polish up to 1.04),
Alexander Pettersson (Swedish),
Henrik Gregersen (Danish up to 1.04),
Carles Millán (Catalan up to 1.04),
Radoslav Bielik (Slovak up to 1.04),
Documan (Hungarian up to 1.04),
Fabio Negri Cicotti (Brazilian Portuguese up to 1.11),
Kees Koenders (Dutch up to 1.07),
Donaldas Apanavicius (Lithuanian up to 1.04),
Johan Adolfsson (Swedish up to 1.09),
Erhan Burhan (Turkish up to 1.11),
Marc Tissot and
Audran Moulard (French up to 1.17),
Wasilis Mandratzis (Greek up to 1.04),
Knut Schjønhaug (Norwegian Bokmål up to 2.15),
Marc Folch
and Securedigital (Catalan up to 1.18),
Jorma Hurtig (Finnish up to 2.18),
Andrew Gavrushenko
(Russian up to 1.31 and 2.35),
Nikolaos J. Kampouridis
(Greek up to 2.21),
Ozzii
(Serbian up to 1.23 and 2.23),
Mikael Hiort af Ornäs
(Swedish up to 2.30),
Paro Uchkunof (Bulgarian up to 2.10).

Where can I find more application icons for Windows shortcuts?

Application icons are icons in Windows ICO format. They can be used in
Windows shortcuts and/or as file association icons. The KeePass executable
contains various application icons which can be used for these purposes.
Additional application icons are available from the «»
directories of the KeePass source code package.
Most of them, shown at right, are slight variations of the main KeePass icon.
Even more, contributed icons (by users) can be found on the
.
If you have multiple KeePass databases, you can use differently colored KeePass
application icons in order to distinguish them.
These icons are not included in the binary distribution because this would make
the application file too large.

Beta slowly approachingPosted by by Felix Geyer on 5. May 2015

Several people asked us by mail or in the comments if the project is still alive.
I can assure you that we haven’t abandoned it!
It is progressing slower than I would like but it is just a hobby project with only few developers after all.
You can follow the development on our tracker or on Github.

That said I hope to be able to release the first beta in the not too distant future.
The main blockers are two features: CSV export and file locking (so you can’t accidentally overwrite a database that has been opened by another user).
After the beta release we will focus on bugfixes in preparation for the final version 2.0.

That’s it for now. I’ll try to post updates about the development progress more regularly from now on.
Thanks for sticking with us!

Установка

Самым сложным шагом в установке было разобраться, какая версия менеджера мне нужна. Я выбрала версию 2.x. Могу смело рекомендовать её, если вам лень разбираться.

Сейчас есть две независимо развивающиеся версии этой программы — 1.x и 2.x, причём 2.x не основана на 1.x. У первой версии меньше возможностей и она работает только на Windows, но зато совместима даже с очень старыми системами. У версии 2.x больше фич и она поддерживает больше ОС: Windows Vista, 7, 8, 10, Mono (Linux, Mac OS X, BSD и т. д.). На сайте есть сравнительная таблица фич этих двух версий.

KeePass написан на английском, но есть много локализаций от коммьюнити, посмотреть и скачать можно на странице Translations. Я пользуюсь английской версией.

В остальном процесс установки интуитивно понятен.

Why doesn’t KeePass lock while a sub-dialog is open?

KeePass has various options to lock its workspace automatically
(after some time of inactivity, when the computer gets locked or the user
is switched, when the computer gets suspended, etc.).
However, the workspace is not locked automatically while a sub-dialog
(like the ‘Edit Entry’ dialog) is open.

To understand why this behavior makes sense, it is first important to know what happens
when the workspace gets locked. When locking, KeePass completely closes the database
and only remembers several view parameters, like the last selected group, the top visible
entry, selected entries, etc. From a security point of view, this achieves the best
security possible: breaking a locked workspace is equal to breaking the database itself.

Now back to the original question. Let’s assume a sub-dialog is open and
one of the events occurs that should automatically lock the workspace.
What should KeePass do now?
In this situation, KeePass cannot ask the user what to do,
and must make an automatic decision. There are several possibilities:

  • Do not save the database and lock.
    In this case, all unsaved data of the database would be lost. This not only applies to
    the data entered in the current dialog, but to all other entries and groups
    that have been modified previously.
  • Save the database and lock.
    In this case, possibly unwanted changes are saved. Often you open files, try something,
    having in mind that you can just close the file without saving the changes.
    KeePass has an option ‘Automatically save database when KeePass closes or the workspace
    is locked’. If this option is enabled and no sub-dialog is open, it’s clear what to do:
    try to save the database and if successful: lock the workspace. But what to do with
    the unsaved changes in the sub-dialog? Should it be saved automatically, taking away the
    possibility of pressing the ‘Cancel’ button?
  • Save to a temporary file and lock.
    This appears to be the best alternative at first glance, but there are several problems with
    it, too. First of all, saving to a temporary file could fail (for example, there could be too
    few free disk space, or some other program like a virus scanner could block it).
    Secondly, saving to a temporary file isn’t uncritical from a security point of view.
    When having to choose a location, typically the user’s temporary directory on the hard
    disk is chosen (because it likely has enough free space, required rights for access, etc.).
    KeePass databases could be leaked and accumulated there.
    It’s not clear what should happen when the computer is being shutdown or crashes while being
    locked. When the database is opened the next time, should it use the database stored in
    the temporary directory instead? What should happen if the ‘real’ database has been modified
    in the meanwhile (a quite realistic situation if you’re carrying your database on an
    USB stick)?

Obviously, none of these alternatives is satisfactory.
Therefore, KeePass implements the following simple and easy to understand behavior:

KeePass doesn’t lock while a sub-dialog is open.

This simple concept avoids the problems above. The user is responsible for the
state of the program.

Note that opening a sub-dialog is typically only required for
editing something; it is not required for using
entries, as the main window provides
various methods for this.

Locking when Windows locks.
On Windows XP and older, the Windows service ‘Terminal Services’
should be enabled. If this service is disabled, locking KeePass
when Windows locks might not work. This service isn’t required on newer
operating systems.

Советы

Продумайте мастер-пароль

Нет смысла использовать менеджер, если ваш мастер-пароль очень простой — qwerty, 1234 и т. п. Вместе с тем, если вы забудете мастер-пароль, вы потеряете все свои пароли, а этого точно хотелось бы избежать. Простой выход: использовать для пароля осмысленную длинную фразу, например:

Причём хорошо, если у вас в пароле будет действующее лицо и что-то, что оно делает — такие предложения запомнить проще всего.

Для большего эффекта можно ещё и сменить раскладку на английскую, но тогда вводить мастер-пароль на смартфоне будет сложно.

Делайте бэкапы

Хранилище всех ваших паролей — небольшой файлик базы данных. Может случиться всякое: компьютер сломается, вы случайно удалите папку с файлом и т. д. Лучше где-то раз в месяц-два (в зависимости от того, как часто вы обновляете пароли) копировать вашу базу и скидывать на другой носитель: флешку, второй компьютер или телефон.

Добавить комментарий

Ваш адрес email не будет опубликован. Обязательные поля помечены *