Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Password Manager KeePass 2.55 warns users about weak security settings
#1
Information 
Quote:A new version of the password manager KeePass is now available. KeePass 2.55 is a smaller release that improves security, imports and introduces some new features to the application.

The new version is already available for download. Users still have the choice between an installer and a portable version. The installer may update any existing installation to the latest version.

Selecting Help > About KeePass in the interface displays the current version. There is also Help > Check for updates, which runs a check for updates. KeePass does not include automatic update capabilities though.

[Image: keepass-2.55.png]

KeePass 2.55

KeePass users who create new encrypted password databases using AES-KDF, one of the supported algorithms, benefit from an increased default number; this improves protection against brute force and guessing attacks. The new number of iterations is 600000.

[Image: key-transformation-settings-weak.png]

Existing users may get a notification when they open one of their databases.  This happens if the value of iterations is smaller than the new default value. A click on yes upgrades iterations immediately.

The new setting can be turned off under Tools > Options > Security > Show warning when the key transformation settings are weak.

Selecting File > Database Settings > Security in KeePass displays the current  encryption algorithm that is used and an option to change its iterations or migrate to another algorithm entirely.  We recommended changing the number of iterations for AES-KDF back in February or switching to Argon instead.

Password imports from several third-party password managers have also been improved. Google Chrome and mSecure CSV imports support new formats now, and imports from 1Password support the new password field/type as well.

KeePass makes a few usability improvements next to that. Changes made to the HTML export and print dialog are remembered now by the application. KeePass is now also highlighting the option that it will use when users select "do not show this dialog again". Report dialogs may be closed with a tap on the Esc-key in the new version.

A new feature is the compare entries command, which enables users of the software to compare two entries.

You can check out the full changelog here.

Verdict

KeePass 2.55 may be a lighter release, but it improves default iterations for one of its core algorithms and informs users if the current iteration count is smaller than the new default. A single-click on "yes" updates the iteration count of the database, which improves security against brute force and guessing attacks.
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Adobe Acrobat Reader DC 2024.002.20736
Adobe Acrobat Reade...harlan4096 — 05:46
AV-TEST - Defense Against the Latest Att...
Cybersecurity: Def...harlan4096 — 05:45
Internet Download Manager 6.42 Build 10
Changes in 6.42 Bu...harlan4096 — 08:52
FastCopy 5.7.10
v5.7.10: * Fixe...harlan4096 — 08:51
Thunderbird Supernova 115.10.2
Thunderbird Supern...harlan4096 — 15:31

[-]
Birthdays
Today's Birthdays
avatar (43)xclubDum
avatar (39)Stewartanilm
Upcoming Birthdays
avatar (26)akiratoriyama
avatar (46)Jerrycix
avatar (38)awedoli
avatar (80)WinRARHowTo
avatar (36)owysykan
avatar (47)beautgok
avatar (37)axuben
avatar (43)talsmanthago
avatar (29)mocetor
avatar (44)piomaibhaict
avatar (49)kingbfef
avatar (36)izenesiq
avatar (38)ihijudu
avatar (43)tiojusop
avatar (40)Damiennug
avatar (38)acoraxe
avatar (47)contjrat
avatar (39)axylisyb
avatar (42)tukrublape
avatar (39)iruqi
avatar (40)saitetib
avatar (34)ypasodiny
avatar (37)omapek
avatar (46)Geraldtuh
avatar (42)knigiJow
avatar (44)1stOnecal
avatar (48)Mirzojap
avatar (34)idilysaju
avatar (38)GregoryRog
avatar (43)mediumog
avatar (38)odukoromu
avatar (44)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>