Vulnerable Password Managers.

Off-topic discussion/chat/argue area with special rules of engagement.
Forum rules
The Off-Topic area is a general community discussion and chat area with special rules of engagement.

Enter, read and post at your own risk. You have been warned!
While our staff will try to guide the herd into sensible directions, this board is a mostly unrestricted zone where almost anything can be discussed, including matters not directly related to the project, technology or similar adjacent topics.

We do, however, require that you:
  • Do not post anything pornographic.
  • Do not post hate speech in the traditional sense of the term.
  • Do not post content that is illegal (including links to protected software, cracks, etc.)
  • Do not post commercial advertisements, SEO links or SPAM posts.
We also ask that you keep strongly polarizing topics like politics and religion to a minimum. This forum is not the right place to discuss such things.
Please do exercise some common sense. How you act here will inevitably influence how you are treated elsewhere.
User avatar
Giraffe
Lunatic
Lunatic
Posts: 418
Joined: 2016-11-09, 11:57

Vulnerable Password Managers.

Post by Giraffe » 2025-08-21, 06:57

For those who use these, there's an article worth reading on Bleeping Computer.
https://www.bleepingcomputer.com/news/s ... g-attacks/

Keepass seems to be OK but, as it's not mentioned, there's no certainty.
Windows 7 Pro 32-bit. Comodo Internet security or Comodo Firewall + Avira Anivirus.

User avatar
Gemmaugr
Lunatic
Lunatic
Posts: 468
Joined: 2025-02-03, 07:55

Re: Vulnerable Password Managers.

Post by Gemmaugr » 2025-08-21, 09:42

KeePass has been breached in 2015 and 2019: https://bestreviews.net/which-password- ... en-hacked/

I prefer manual passwords. Static part and dynamic part. Making them both memorable and unique.

User avatar
Moonchild
Project founder
Project founder
Posts: 38923
Joined: 2011-08-28, 17:27
Location: Sweden

Re: Vulnerable Password Managers.

Post by Moonchild » 2025-08-21, 10:09

Keep your third-party password manager out of your browser, I say. Can't clickjack something that isn't in a consistent location relative to web content. And for lower-importance passwords use Pale Moon's built-in one with a master password for convenience if it's too much of a hassle to use shortcut keys from the password manager ;)
"There is no point in arguing with an idiot, because then you're both idiots." - Anonymous
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite