• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / Software / KeePass 2.34 update brings https update check

KeePass 2.34 update brings https update check

2016-06-13 by Jason

KeePass, my preferred password manager, released version 2.34 this weekend. The changelog includes:

New Features:

The version information file (which the optional update check downloads to see if there exists a newer version) is now digitally signed (using RSA-4096 / SHA-512); furthermore, it is downloaded over HTTPS.
Added option ‘Lock workspace when minimizing main window to tray’.
Added option ‘Esc minimizes to tray instead of locking the workspace’.
Added Ctrl+Q shortcut for closing KeePass (as alternative to Alt+F4).
Added UIFlags bit for disabling the ‘Check for Updates’ menu item.
The installers (regular and MSI) now create an empty ‘Plugins’ folder in the application directory, and the portable package now also contains such a folder.
Plugins: added support for digitally signed version information files.

Improvements:

Plugins are now loaded only directly from the application directory and from any subdirectory of the ‘Plugins’ folder in the application directory.
Improved startup performance (by filtering plugin candidates).
When closing a database, KeePass now searches and deletes any temporary files that may have been created and forgotten by MSHTML when printing failed.
CHM help file: improved high DPI support.
Various code optimizations.
Minor other improvements.

Bugfixes:

(None).

The point worth discussing with this update is the first new feature. The version information file is now digitally signed and the file downloaded to compare versions is now downloaded over HTTPS.

The attention to this particular issue came from a bug report in early March that found the update check to happen over HTTP, leaving the software susceptible to a man-in-the-middle attack. If you controlled a WiFi AP that somebody utilized, you could intercept the traffic and provide the information that an update is available. The update checker, however, does not download the update. The KeePass website is over HTTP as well, so the bug report speculates that the update download could also be intercepted and manipulated. For a security-oriented utility trusted with protecting important accounts and passwords, this is a bit concerning.

A thread on the KeePass SourceForge forums discussed the issue and the developer stated that the issue would not be fixed due to cost to implement. That stance has now apparently been reversed as the fix has been implemented with the latest version of KeePass Professional Edition, both the installer and the portable versions.

The controversy surrounding this implementation seems to have been ‘making a mountain out of a mole hill’ and it is still recommended to check the file’s hash and AuthentiCode signature on the file through File Explorer, Properties, and the Digital Signatures tab.

Filed Under: Security and Privacy, Software Tagged With: keepass

Trending

  • How to File a CAN-SPAM Complaint with the FTC
    In Media, Security and Privacy, Tech Solutions
  • Samsung reveals their Galaxy S5 Android smartphone and three new Gear
    In Hardware, Gadgets, and Products
  • Hands-On With OnLive: The Console For Gaming In The Cloud
    In Entertainment, Hardware, Gadgets, and Products

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • Access to the resource [servershare] has been disallowed Access to the resource [servershare] has been disallowed
  • Read the Event Logs on Windows Server Core Read the Event Logs on Windows Server Core
  • What is the AllJoyn Router Service on Windows 10? What is the AllJoyn Router Service on Windows 10?
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • SOLVED: “This modification is not allowed because the selection is locked.” SOLVED: "This modification is not allowed because the selection is locked."
  • How Virtual Reality Supports Mental Health Therapy How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting
  • Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams
  • customer contactless payment for drink with mobile phon at cafe counter bar,seller coffee shop accept payment by mobile.new normal lifestyle concept The Latest Innovations In Payment Technology
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in