Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security issues with the persistent key implementation #38

Closed
Angelelz opened this issue Sep 9, 2019 · 5 comments
Closed

Security issues with the persistent key implementation #38

Angelelz opened this issue Sep 9, 2019 · 5 comments

Comments

@Angelelz
Copy link

Angelelz commented Sep 9, 2019

The Plugin never checks if the persistent key has been changed and continues to use it even if it is not a secure one.

I wrote all the details of this issue in my private project due to the sensitivity of information. @sirAndros and @shuffle-c are added as collaborators.

@shuffle-c
Copy link
Collaborator

Thank you for your very profound research, @Angelelz! We've fixed the issue in v3.1.1.

@Angelelz
Copy link
Author

That is the beauty of the open source community! I can confirm this issue is fixed. Thank you for working on it so fast!

@waellus
Copy link

waellus commented Nov 19, 2019

Hey @Angelelz thanks for the update. Is it possible to make a general article or link to an existing one, or if i can have access to your project?
Thanks!

@Angelelz
Copy link
Author

Given the sensitivity of the issue, I would wait for @shuffle-c or @sirAndros approval to make that project public. Anyone using the persistent key that has not updated to KeePassWinHello 3.1.1 could be vulnerable to an attack made with that project.

@Angelelz
Copy link
Author

Angelelz commented Feb 1, 2022

Hey @Angelelz thanks for the update. Is it possible to make a general article or link to an existing one, or if i can have access to your project? Thanks!

I just made the Project public for reference, as enough time has passed since the issue was patched.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants