Jump to content
  • Password Manager KeePass 2.55 warns users about weak security settings


    Karlston

    • 302 views
    • 3 minutes
     Share


    • 302 views
    • 3 minutes

    A new version of the password manager KeePass is now available. KeePass 2.55 is a smaller release that improves security, imports and introduces some new features to the application.

     

    The new version is already available for download. Users still have the choice between an installer and a portable version. The installer may update any existing installation to the latest version.

     

    Selecting Help > About KeePass in the interface displays the current version. There is also Help > Check for updates, which runs a check for updates. KeePass does not include automatic update capabilities though.

     

    keepass-2.55.png

    KeePass 2.55

    KeePass users who create new encrypted password databases using AES-KDF, one of the supported algorithms, benefit from an increased default number; this improves protection against brute force and guessing attacks. The new number of iterations is 600000.

     

    key-transformation-settings-weak.png

     

    Existing users may get a notification when they open one of their databases.  This happens if the value of iterations is smaller than the new default value. A click on yes upgrades iterations immediately.

     

    The new setting can be turned off under Tools > Options > Security > Show warning when the key transformation settings are weak.

     

    Selecting File > Database Settings > Security in KeePass displays the current  encryption algorithm that is used and an option to change its iterations or migrate to another algorithm entirely.  We recommended changing the number of iterations for AES-KDF back in February or switching to Argon instead.

     

    Password imports from several third-party password managers have also been improved. Google Chrome and mSecure CSV imports support new formats now, and imports from 1Password support the new password field/type as well.

     

    KeePass makes a few usability improvements next to that. Changes made to the HTML export and print dialog are remembered now by the application. KeePass is now also highlighting the option that it will use when users select "do not show this dialog again". Report dialogs may be closed with a tap on the Esc-key in the new version.

     

    A new feature is the compare entries command, which enables users of the software to compare two entries.

     

    You can check out the full changelog here.

    Verdict

    KeePass 2.55 may be a lighter release, but it improves default iterations for one of its core algorithms and informs users if the current iteration count is smaller than the new default. A single-click on "yes" updates the iteration count of the database, which improves security against brute force and guessing attacks.

     

     

    Source

     

    • Like 2
    • Thanks 1

    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...