📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Taking passwords abroad safely?

2»

Comments

  • TUVOK
    TUVOK Posts: 530 Forumite
    Sixth Anniversary 100 Posts Name Dropper
    Thanks for all replies.
    my son's partner only yesterday told me that she use's Keepass, I'll be having a look at it.
  • TUVOK
    TUVOK Posts: 530 Forumite
    Sixth Anniversary 100 Posts Name Dropper
    Thanks for all replies.
    Speaking to a friend yesterday who is tech savvy and he recommended Keepass too.
    Thanks for the link to Keepass for Android phones, hopefully look at it today.
  • PHK
    PHK Posts: 2,302 Forumite
    Eighth Anniversary 1,000 Posts Photogenic Name Dropper
    A couple of points to consider. There are some known flaws in Keepass that mean a determined hacker could recover passwords from local storage.

    It also worth considering that if you have them stored on  a physical medium like a hard drive or USB then you need to secure that both physically and electronically. You should also have a copy off-site as it were in case of hardware failure.

    For personal home use, Cloud based that's encrypted ( so that neither the security company or cloud provider can access it ) is usually a better option. 
  • Micron
    Micron Posts: 95 Forumite
    Part of the Furniture 10 Posts Name Dropper Combo Breaker
    edited 12 November 2023 at 4:41PM
    Have the new 2.54/2.55 releases addressed the memory exploit you may have been referring to ?

    Or are there other security problems?

    Please tell us more PHK.
  • TMSG
    TMSG Posts: 230 Forumite
    Fourth Anniversary 100 Posts Name Dropper
    edited 12 November 2023 at 2:54PM
    PHK said:
    A couple of points to consider. There are some known flaws in Keepass that mean a determined hacker could recover passwords from local storage.

    It also worth considering that if you have them stored on  a physical medium like a hard drive or USB then you need to secure that both physically and electronically. You should also have a copy off-site as it were in case of hardware failure.

    For personal home use, Cloud based that's encrypted ( so that neither the security company or cloud provider can access it ) is usually a better option. 
    Any evidence for claiming there are "some known flaws in Keepass"? The only thing I am aware of is the recent discussion about https://nvd.nist.gov/vuln/detail/CVE-2023-32784 which many security experts think wasn't a flaw to start with... once an attacker has physical access to the PC involved then no app is safe against this sort of breach if it's currently running and unlocked. The KeePass2 dev has included a sort of work-around in v2.54 but this does not address the fundamental issue of security breakdown once the attacker has physical access to the hardware.

    Any evidence for claiming that "Cloud based... is usually a better option"? If you use a trusted and audited app to store passwords locally, use a safe master password* (and preferably also a keyfile as a second factor) this is safer than storing passwords on somebody else's cloud server. Bitwarden is, as I wrote, probably the best option here, because they open-source their code but even there the user has no control over their security arrangements, bug handling etc. If you store stuff yourself, you have more of a responsibility but you also can make sure it's as safe as possible. 100% security doesn't exist.

    * That's a topic in its own right.
  • Micron said:
    I've been using KeePass2 for many years on my PC and more recently Keepass2Android Password Safe on an Android phone.

    It's free, open source, no need to open an account, works locally without internet access and works well for me.

    You can also run a portable version of KeePass2 from a USB stick, it's said to be secure as it doesn't store any sensitive information on to the running system.
    I use exactly this combination and frankly can't understand why anyone would choose any other option.

  • PHK said:
    A couple of points to consider. There are some known flaws in Keepass that mean a determined hacker could recover passwords from local storage.

    It also worth considering that if you have them stored on  a physical medium like a hard drive or USB then you need to secure that both physically and electronically. You should also have a copy off-site as it were in case of hardware failure.

    For personal home use, Cloud based that's encrypted ( so that neither the security company or cloud provider can access it ) is usually a better option. 
    You need to provide some evidence to back up that assertion.

Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.2K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.7K Spending & Discounts
  • 244.2K Work, Benefits & Business
  • 599.3K Mortgages, Homes & Bills
  • 177.1K Life & Family
  • 257.7K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.