• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / Software / KeePass 2.34 update brings https update check

KeePass 2.34 update brings https update check

2016-06-13 by Jason

KeePass, my preferred password manager, released version 2.34 this weekend. The changelog includes:

New Features:

The version information file (which the optional update check downloads to see if there exists a newer version) is now digitally signed (using RSA-4096 / SHA-512); furthermore, it is downloaded over HTTPS.
Added option ‘Lock workspace when minimizing main window to tray’.
Added option ‘Esc minimizes to tray instead of locking the workspace’.
Added Ctrl+Q shortcut for closing KeePass (as alternative to Alt+F4).
Added UIFlags bit for disabling the ‘Check for Updates’ menu item.
The installers (regular and MSI) now create an empty ‘Plugins’ folder in the application directory, and the portable package now also contains such a folder.
Plugins: added support for digitally signed version information files.

Improvements:

Plugins are now loaded only directly from the application directory and from any subdirectory of the ‘Plugins’ folder in the application directory.
Improved startup performance (by filtering plugin candidates).
When closing a database, KeePass now searches and deletes any temporary files that may have been created and forgotten by MSHTML when printing failed.
CHM help file: improved high DPI support.
Various code optimizations.
Minor other improvements.

Bugfixes:

(None).

The point worth discussing with this update is the first new feature. The version information file is now digitally signed and the file downloaded to compare versions is now downloaded over HTTPS.

The attention to this particular issue came from a bug report in early March that found the update check to happen over HTTP, leaving the software susceptible to a man-in-the-middle attack. If you controlled a WiFi AP that somebody utilized, you could intercept the traffic and provide the information that an update is available. The update checker, however, does not download the update. The KeePass website is over HTTP as well, so the bug report speculates that the update download could also be intercepted and manipulated. For a security-oriented utility trusted with protecting important accounts and passwords, this is a bit concerning.

A thread on the KeePass SourceForge forums discussed the issue and the developer stated that the issue would not be fixed due to cost to implement. That stance has now apparently been reversed as the fix has been implemented with the latest version of KeePass Professional Edition, both the installer and the portable versions.

The controversy surrounding this implementation seems to have been ‘making a mountain out of a mole hill’ and it is still recommended to check the file’s hash and AuthentiCode signature on the file through File Explorer, Properties, and the Digital Signatures tab.

Filed Under: Security and Privacy, Software Tagged With: keepass

Trending

  • Ensuring Consent and Revocation When Your Info is Their Business
    In Media, Security and Privacy
  • Is Your Firefox Genuine? Phishing at its Phinest!
    In Media, Security and Privacy, Software, Tech Solutions
  • Java 7u7 and 6u35 updates address prominent vulnerabilities
    In Security and Privacy, Software

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • How to ‘Unblock’ multiple files at a time with PowerShell How to 'Unblock' multiple files at a time with PowerShell
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • SOLVED: “This modification is not allowed because the selection is locked.” SOLVED: "This modification is not allowed because the selection is locked."
  • Configure Outlook to recurring appointments for the last weekday of the month Configure Outlook to recurring appointments for the last weekday of the month
  • Creating and editing views in phpMyAdmin Creating and editing views in phpMyAdmin
  • 3d rendering circuit cloud for cloud computing technology Build and Deploy a Modern Web 3.0 Blockchain App in 2022
  • Telecom Application Development: When to Outsource Telecom Application Development: When to Outsource
  • Printer printing document wirelessly from mobile phone or smartphone wifi connection vector flat cartoon illustration, file air print on fax or ink jet via cellphone bluetooth modern design Why Your Business Needs Online Fax Services In 2022
  • 6 Best Ways to Protect Your Business Account 6 Best Ways to Protect Your Business Account
  • How to download videos from Instagram How to download videos from Instagram
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • Build and Deploy a Modern Web 3.0 Blockchain App in 2022
  • Telecom Application Development: When to Outsource
  • Why Your Business Needs Online Fax Services In 2022

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2022 · Magazine Pro Theme on Genesis Framework · WordPress · Log in