Hacker News new | past | comments | ask | show | jobs | submit login
KeePass flaw allows retrieval of master password, PoC is public (helpnetsecurity.com)
9 points by pil0u on May 17, 2023 | hide | past | favorite | 2 comments



Also note that KeepassXC is unaffected - https://github.com/keepassxreboot/keepassxc/discussions/9433


Note, this is allows one to "retrieve the master password from the software’s memory", not from disk.

Which means the importance is pretty low.. if you have a malicious program running in your account it is game over anyway, as it can sniff the keyboard or inject code into process or do many other things to steal your password.

Researcher says the big problem is "someone could obtain access to your computer and conduct forensic analysis". I agree with that, and I also thing this is not a big concert for many people.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: