8 ms·
KeePassXC 2.2.0 released with YubiKey and TOTP support
- FT_intern 9y agoHas anyone thought of a good redundancy scheme for yubikey? Physical object authentication is great except physical objects are less durable than brain memory (or at least, if my brain memory is gone then I probably would have no use for the password anyway).
- tedd4u 9y agoKeep 1 key on your keychain, one in a fire vault in the house, and one in the safety-deposit box at the local branch bank office. Most U2F-enabled sites let you register multiple keys. Add new sites with keychain during the day, in the evening add the fire-vault key at home. Once a quarter add the third key from the safety-deposit box.
- watersb 9y agoI am playing with YubiKey storing certificates, then using the certificates like any other GPG setup, so I can have redundancy and revocation. But I have yet to make it dead simple enough to use for real-world application. Or maybe I am just procrastinating.
- otachack 9y agoNice! Excited for future development of this. I'll have to get a Neo soon to try out these new features.
- interfixus 9y agoThis is by far the best of the KeePassX* lot, incorporating loads of enhancements which, disappointingly after years of development, never made it into KeePassX 2.x proper, and some 1.x features which simply disappeared in the upgrade. [Edit: missing word]
- droidmonkey 9y agoWow thank you for the kind words! Appreciate the support.
- interfixus 9y agoYou're welcome, it's a very decent effort. And now I'm sort of shamed into actually contributing. Reporting back as soon as time allows.
- secfirstmd 9y agoYep we are now switching to advising its use for the human rights defenders and journalists that we work with.
- m-p-3 9y agoI find it almost better than the original KeePass 2.x program. I say almost because I'm used to the original interface, but I'm sure after getting used to it, it will supersede it on my systems.
- shmerl 9y agoI'm still waiting for it to arrive in Debian: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=855173 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=855173
- sillysaurus3 9y agoSo there's KeePass, KeePassX, and now KeePassXC? (And two different variants of KeePass that have nothing to do with each other.) Not that there's anything wrong with that. I'm just curious if KeePassXC is yet another fork, or if it's from the same people who did KeePassX. KeePassX has an excellent security reputation, so it'd suck if an unrelated fork ruined that.
- abrowne 9y agoPrevious discussion of this: https://news.ycombinator.com/item?id=13468486 https://news.ycombinator.com/item?id=13468486
- grawlinson 9y agoThere doesn't seem to be active development on KeePass/KeePassX, hence the KeePassXC fork. The C in the fork title apparently stands for 'community'. It has a lot of support behind it.
- wernercd 9y agoNo active development? I'm using KeePass on Windows (and have been for years) and I've just had a new update pushed (2.36)... Am I missing something?
- xfer 9y agoKeePass is actively maintained, keepassx is the non-mono port for unix and is not being developed actively. Keepasssxc is fork of keepassx.
- mook 9y agoKeePass (the original C# version) appears to actively developed. KeePassX (the C++ rewrite) appears to have slowed down. KeePassXC (the fork of the C++ rewrite) is the one under discussion here.
- sillysaurus3 9y ago
- desdiv 9y agoYou guys rock! Thank you for your hard work. BTW the Windows portable version link on your download page is 404ing: Incorrect URL: https://github.com/keepassxreboot/keepassxc/releases/download/2.2.0/KeePassXC-2.2.0-Win64.zip https://github.com/keepassxreboot/keepassxc/releases/downloa... Correct URL: https://github.com/keepassxreboot/keepassxc/releases/download/2.2.0/KeePassXC-2.2.0-Win64-Portable.zip https://github.com/keepassxreboot/keepassxc/releases/downloa...
- droidmonkey 9y agocorrected thank you! I also added links to the 32-bit variants.
- cyphar 9y agoIt also now has CSV importing so you can now import your passwords from LastPass (though you'll have to manually recreate the folder structure).
- gregwebs 9y agoThis release looks great. Unfortunately I had to switch to LastPass to get sharing, real sync support rather than blob syncing in, and also easy usage on mobile.
- woodsier 9y agoDecent mobile support is the only thing holding me back from switching. The current 3rd party options are underwhelming.
- underlines 9y agoI just wait for Android O Autofill Framework to arrive. Then mobile password managers will finally be useful.
- scott_karana 9y agoReally?... The syncing and conflict resolution (or lack thereof) is the true problem for me.
- Semaphor 9y agoKeepass2Android works great for me syncing over OwnCloud (they have several cloud sync options)
- ViViDboarder 9y agoCould be a problem with a shared database though as the entire thing is one blob, changes can't be merged.
- Androider 9y agoInteresting, how will it be better? The Lastpass for Android autofill in both native apps and web is already pretty perfect in my experience, it detects the fields and fills in the login. In the very rare case it doesn't, the notification list will have a one-click entry to force-fill the info.
- atomlib 9y agoI see it supports Linux, Windows, and macOS, but are there any Android and iOS apps to open and modifty KeePassXC databases?
- mynegation 9y agoIf you feel like keeping your kdbx file in Dropbox you may use ikeepass[1] on iOS to load and modify it. For Android there is keepassdroid [2] [1] https://itunes.apple.com/us/app/ikeepass/id299697688?mt=8 https://itunes.apple.com/us/app/ikeepass/id299697688?mt=8 [2] http://www.keepassdroid.com/ http://www.keepassdroid.com/
- snowwrestler 9y agoI use MiniKeePass on iOS and have been very happy with it.
- simcop2387 9y agoFor standard keepass I use keepass2android and nextcloud for syncing. That said I don't believe it supports any of the fun new stuff from KeepassXC. It does work with NFC and HOTP though. I'd love to use TOTP instead.
- distances 9y agoThumbs up for Keepass2Android. Extra two thumbs up since it provides also a version without network capabilities for additional peace of mind, I found that a great touch.
- Slurpee99 9y agoHow well does it work for teams? Is there issues for syncing the database if two or more people are using it at the same time?
- rkv 9y agoWorks OK for small teams. If a user forgets to close the database then other team members are only able to open it as read-only. My biggest gripe is that you don't know who is holding the write lock. We work around this by using a setting in our keepass client to close the db after a certain amount of time.
- TokenDiversity 9y agoAs someone using Keepass2 (mono on Linux), can someone knowledgeable briefly tell me (and probably others) why should and why should not I switch to KeePassX? I'm getting the feeling that this uses the older protocol? I got a good answer to the above question from desdiv so I'm adding an edit: Is there a reason to use this (and not use this) in place of KeePass2 on Windows?
- TokenDiversity 9y agoI'll answer part of my own question- this does look like it's compatible with the Keepass protocol 2. So that shouldn't be the reason to stop. Of course there could be other reasons.
- phoerious 9y agoKeePassXC does support the KeePass2 format (i.e., KDBX3). It does not (yet) support the very latest format (KDBX4), but by default KeePass also still uses KDBX3, so both are compatible.
- desdiv 9y ago1. Unlocking the database takes much longer than it should. Linux Keepass2 is much slower at unlocking than Windows Keepass2 on the same machine. 2. On Linux, after entering the password the windows disappears, giving no UI feedback during the lengthy unlocking process. When you type the password wrong, it takes even longer for some reason, and there's no tray icon when you type the password wrong, so you'd have to minimize all your windows to find the dialog box all the way in the back. 3. Lacking Unicode support in 2017 is simply unacceptable: https://i.imgur.com/X0T46bY.png https://i.imgur.com/X0T46bY.png None of this is the fault of the Keepass developers, since all three problems are absent in the Windows build. As far as I can tell the problem lies with Mono.
- TokenDiversity 9y agoYeah I just downloaded. This seems like a good native drop-in replacement. Even the menus et all seem to be in the same place. And Unicode works, yeah! I have a really old computer and keepass2 opens stuff instantly so I'm guessing I'm probably not using good enough security.
- angelsl 9y agoNo KDBX 4 support unfortunately.
- TokenDiversity 9y agoFeatures I like: 1) Download website favicon (no clue how though, tried entering website but didn't see an option to download favicon) 2) Command line interface, no clue again how to use.
- balajics 9y agoFor 1) Download favicon option is there inside "icon" menu of a keepass entry. https://keepassxc.org/images/screenshots/macos/screen_003.png https://keepassxc.org/images/screenshots/macos/screen_003.pn... I wish there was a way to download and associate favicon of all entries in one-click.
- pacomerh 9y agoIndeed, wish there was more documentation on how to use the CLI
- barbs 9y agoSame here. I was hoping to run this completely headlessly but any attempt to run even `keepassxc --help` or `keepassxc --version` results in: QXcbConnection: Could not connect to display Aborted
- th3zero 9y agoCan you open an issue on Github? Thanks
- barbs 9y agoEDIT: I originally created an issue for the wrong repository, and it looks like someone has already made an issue for me: https://github.com/keepassxreboot/keepassxc/issues/668 https://github.com/keepassxreboot/keepassxc/issues/668 Thanks for your attention
- TokenDiversity 9y agoOkay, issue 254 has documentation on the CLI. Looks like you can't query password if that's what you're after
- sowbug 9y agoThis is really cool. Here are more feature requests (and for all I know they're already there): * Optionally display a secret as a QR code * Generate and validate BIP39-compatible seeds (like Diceware but with a checksum. Many Bitcoin wallets these days accept them) * Get this into Tails
- phoerious 9y agoWould you be so kind to file a feature request on GitHub? Here it gets lost. Thanks!
- sowbug 9y agoDone! https://github.com/keepassxreboot/keepassxc/issues/675 https://github.com/keepassxreboot/keepassxc/issues/675 https://github.com/keepassxreboot/keepassxc/issues/676 https://github.com/keepassxreboot/keepassxc/issues/676 https://github.com/keepassxreboot/keepassxc/issues/677 https://github.com/keepassxreboot/keepassxc/issues/677
- wst_ 9y agoI'd love to be able to decide which characters to use when generating a password.
- ktta 9y agoNotable features: 1. Unlock using Yubikey 2. TOTP 2FA 3. Diceware password generator 4. ASLR for in-memory security (didn't expect this!) 5. Portable and Single instance mode (I'll have to check this one in detail) Thanks for your work team!
- problems 9y agoFor anyone wondering - the TOTP 2FA is not on the password wallet itself, but that the wallet is able to store the TOTP key, authenticating TOTP involves knowing the key, by which point there's really no value in using it to authenticate the wallet, it'd be a UI-only protection. However I think storing TOTP keys in your wallet is a bad idea for security - now if someone hacks your machine they get both your password and your TOTP key at the same time. The main advantage of TOTP is that it puts your second form of auth on a separate device, preventing a single point of compromise. not much malware will exploit this as not many people will use it, but a targeted attack might greatly benefit from something like this.
- pfg 9y agoJust to make sure no one gets the wrong impression: You still have a single point of compromise, as having sufficient access to your machine would allow an attacker to do anything from intercepting your TOTP code to stealing your session or just sending requests from your device. U2F doesn't help with this aspect either, it just adds phishing resistance. The difference lies in the amount of effort an attacker would have to go through. A compromised password manager database including TOTP secrets effectively gives them access to everything at once, whereas any other kind of compromise would require a lot more effort to get everything, and would probably increase the odds of detection. It's also a good way to hedge against types of compromise where only your password manager is affected, from vulnerable browser extensions (see LastPass, among others) to the possibility of weak crypto (which would be especially devastating for password managers that use centralized online storage) or even backdoors.
- th3zero 9y agoJust to make sure no one gets the wrong impression: You should store your TOTP keys in a different KDBX file, locked with a different master password, and maybe even used on a different device/PC. We all know that you shouldn't store your password along with TOTP secrets, or should I make a blog post explaining this?
- problems 9y agoStill no KDBX 4 support though? Please consider making it a priority - it looks like someone tried to pull request it but that failed? The older format uses a custom AES-based KDF - and while I don't personally see any major issues with it, I'm much more comfortable with the modern, heavily reviewed Argon2 design used in the KDBX4. https://github.com/keepassxreboot/keepassxc/issues/148 https://github.com/keepassxreboot/keepassxc/issues/148
- angelsl 9y agoThat would be me. I wrote the patch against the original KeePassX which seems to be no longer maintained (?). One of the KeePassXC guys asked me to rebase it over so I did. Then we (they) spent a week or two debating on how to support libargon2 and the newer libgcrypt required for ChaCha20, coming to no resolution, and I just lost any motivation to push for them to merge my patch. They also disagreed with the way I implemented KDBX 4 (by adding conditionals to the KDBX reader/writer instead of just creating a whole new class — I did this because KeePass did it this way). I agree that it should be separated, but at that point I already gave up on getting them to accept my patch. The PR is [here](https://github.com/keepassxreboot/keepassxc/pull/399 https://github.com/keepassxreboot/keepassxc/pull/399), you can read it, I know I sound rather impatient here. The other PR on updating their Docker to get newer libraries (libargon2 and libgcrypt) is [here](https://github.com/keepassxreboot/keepassxc/pull/419 https://github.com/keepassxreboot/keepassxc/pull/419). I honestly thought someone else would take it up after I gave up to get it in by 2.2 (it's not even a very big patch), but.. I guess not. Someone with more experience/patience/persistence, please, you can take the patch and rebase it and clean it up to what they want. You'll also need to wait for them to figure out how they want to use the libraries required with their packaging system.
- kronos29296 9y agoHope somebody cleans it up and adds the PR to Keepassxc. I would but I am not a C++ guy.(only Python guy sadly)
- phoerious 9y agoKDBX4 is a priority indeed, but we only have limited resources. We hoped to get it into 2.2.0, but it just wasn't possible. We really appreciate your patch and will make sure it lands in 2.3.0. It's not forgotten.
- finchisko 9y agoReally good timing for me to self promote. :-) I'm working on improved keepassxc browser extension. Communication between browser and KeePassXC is via NativeClient. You need varjolintu fork of KeePassXC, but eventually it will also support KeePassHTTP protocol too. My goals currently are: internalization, nicer UI, clean and extensible code base. I already did options page with material-ui and react. Currently working on replacing jquery popup implentation for hyperapp, which appeared here on HN yesterday. If interested I can send instruction how you can build extentions. I would like to see this as official part of KeePassXC and willing to donate for free. What you guys think? You can try options UI on https://mauron85.github.io/keepassxc-browser/preview/ https://mauron85.github.io/keepassxc-browser/preview/
- wh-uws 9y agoawesome will definitely signup to be a beta test when you get it where you want that. actively using lastpass now and would like to move to an open source solution I feel like I can trust
- finchisko 9y agoYou can go fully OSS already. Try https://github.com/pfn/passifox https://github.com/pfn/passifox. It is using KeePassXC http protocol. I'am working on it's replacement.
- mosselman 9y agoAny chance of creating an Opera version as well? I just force installed the chrome version on Opera, but it doesn't seem to work.
- finchisko 9y agoI'll take look. If Opera supports webextensions, then it should be viable.
- varjolintu 9y agoThe official and latest version is always available here: https://github.com/varjolintu/keepassxc-browser https://github.com/varjolintu/keepassxc-browser Firefox Nightly (version 56) is also supported. The extension will work officially when Mozilla releases build 57.
- dfabulich 9y agoIs there a KeePass fork with support for the new MacBook touch bar?
- cmcginty 9y agoDoesn't work for my DB ... "Unable to open the database. Duplicate custom attribute found". Gonna stick with MacPass I guess.
- th3zero 9y agoCan you open an issue on Github?
- sayright 9y agoStoring password and TOTP seed in a single storage goes against the concept of 2FA.
- unsignedint 9y agoWell instead general password without password manager assumes the fact someone remembers that password. (and perhaps reusing that password.) Using password manager (with different password for each service) plus TOTP would serve its purpose. You still have to enter the code, so it still require you to "have" that code somehow which makes it no different than provisioning multiple devices which many 2FA systems won't prevent, perhaps other than hardware TOTP devices.
- th3zero 9y agoYou should store your TOTP keys in a different KDBX file, locked with a different master password, and maybe even used on a different device/PC. We all know that you shouldn't store your password along with TOTP secrets, or should I make a blog post explaining this?
- niksakl 9y agoAn official ppa repository for Ubuntu would be great! There is a link to an unofficial one in your page, but since this is a security app, installing it from some random repo just feels wrong... Thank you for the great work!
- melicerte 9y agoHave you tried the snap install ?
- niksakl 9y agoYes I did that, but the gui looked horrible, as it was not using my themes, colors etc. I then found out that this was a known issue of snap at that time.
- finchisko 9y agokeepassxc from snap is starting much longer. at least 5sec diff
- nirvdrum 9y agoSorry to hijack the thread a bit, but since you're discussing the snap install I thought I'd ask. This is the first snap app I've ever used. I find the file browser for opening the DB won't show anything outside of my $HOME. I assume this is some sort of sandbox feature of snap apps. But I'd like to store my DB on a network mount, so that gets in the way unless I set up symlinks. Is there any way to get this to behave a bit more like a normal desktop program?
- deleted 9y ago[deleted]
- can3p 9y agoGreat release! Is kdbx format supported by any iPhone app? I'm stuck with KeepassX for that reason.
- 2citizen 9y agoTry MiniKeePass. It works well but has some actions flow to sync your kdbx backups with updated data from the phone and vise versa. https://itunes.apple.com/us/app/minikeepass-secure-password-manager/id451661808 https://itunes.apple.com/us/app/minikeepass-secure-password-...
- TokenDiversity 9y agoAnyone knows how should I change the font? I know this seems a minor thing but I'd like this thing to be readable :-). The font-size is too small. And I'd prefer a font of my own choice.
- crb 9y agoDocs are.. sparse. The website says go to the GitHub wiki, and that only really talks about how to build and develop the app, not how to use it. Can anyone tell me how to enable Yubikey?
- phoerious 9y agoJust plug it in. ;-)
- svdb_ 9y agoOne thing I like about the KeePassX interface is the ability to search with a hotkey (CTRL+F). Also, this could be done without having the menu bar visible, hitting the hotkey just pulls up the input field.
- lifty 9y agoI use MacPass, which is a good native Mac alternative for KeePass. It supports KeePassHTTP and judging by their github wiki they have recently implemented support for the KDBX4 format.
- binaryanomaly 9y agoWell done! It's great to see some progress with open source in this particular area. At the moment I'm still stuck with [insert_name_of_commercial_proprietary_solution] but would love to switch to a true open source solution with good user experience and reliable mobile support. I will make a small donation as soon as I get through the flattr waitlist as a small token of appreciation.
- tomlong 9y agoI really like KeePassXC, it's the only password manager I use (excluding mobile) but my one major bugbear still exists in this release. The 'lock database' and 'copy password to clipboard' icons are nearly identical (both essentially a padlock) and still adjacent but one in the UI. I accidentally lock the database far more often than I would like. I know I'm a bit clumsy and a slow to catch on but this one simple change would really make application a lot more useable for us divs. https://image.ibb.co/k1amA5/kxpc.png https://image.ibb.co/k1amA5/kxpc.png
- sillysaurus3 9y agoI use Command-L to lock, for what it's worth.
- Chaebixi 9y agoCan someone explain how the YubiKey and TOTP support is supposed to work? I can't think of a way those could work with a local password manager like KeePass.
- danjoc 9y agoReading it, it sounds like they use HMAC challenge response for the password to the vault. For that to work, you'd insert yubikey, enter a password, and the password is passed through the yubikey and hashed. The hash is then used as the password to open/lock the vault. That gives you a reasonably strong password for the vault. It does not prevent phishing. Therefore, anyone with the hash and access to the vault can still access all passwords without your knowledge. The TOTP thing sounds like a google authenticator sort of feature. I'm sticking with zx2c4 pass. It is an assembly of gnupg, git, and pwgen. Trusted open source components. Works with a Yubikey (opensc and gpg-agent) to prevent private key theft via software. QTPass is a nice cross platform gui client. PassFF extension provides excellent browser integration. Android Password Store and OpenKeychain allow pass and yubikey to work on my mobile. Strong 2 factor password storage everywhere I need it. My biggest problem these days is dealing with sites that don't allow 30+ char passwords with full range of special characters. Almost exclusively, banks.
- ConfucianNardin 9y agopass no longer uses pwgen as of version 1.7, by the way (changed in 639c46a342466209e9b0600c2b3574bb44a0ff31).
- GordonS 9y agoI think Yubikey can be used to unlock the database
- jsfitzsimmons 9y agoI'm trying the snap package, but I don't think the cli is available this way. I can find the binary in /snap/keepassxc/current/bin, but it has library loading problems.
- Cardiologist 9y agoHow is KeePassXC comparing in verification/testing vs the original KeePass2? I was not able to find information on that process on eithers project homepage