[Безопасность] KeePass 1.14

Тема в разделе "Софт", создана пользователем de_n, 19 окт 2008.

Статус темы:
  1. de_n

    de_n Создатель

    8 май 2007
    KeePass Password Safe - менеджер паролей. Данная программа позволяет в удобном виде хранить важные данные (логины и пароли) в закодированной базе. Разработчики сообщают, что кодирование происходит с помощью надежных и безопасных алгоритмов AES и Twofish. Используя эту утилиту, пользователь может создать для себя категории, в которых будут храниться пароли. Например, данные, касающиеся интернета, можно занести в одну категорию, а данные, касающиеся операционной системы - в другую. Предусмотрен быстрый поиск по всей хранимой в программе информации. KeePass Password Safe включает в себя генератор, с помощью которого можно создать безопасный и уникальный пароль.

    Today you need to remember many passwords. You need a password for the Windows network logon, your e-mail account, your homepage's FTP password, online passwords (like website member account), etc. etc. etc. The list is endless. Also, you should use different passwords for each account. Because if you use only one password everywhere and someone gets this password you have a problem... A serious problem. The thief would have access to your e-mail account, homepage, etc. Unimaginable.

    KeePass is a free/open-source password manager or safe which helps you to manage your passwords in a secure way. You can put all your passwords in one database, which is locked with one master key or a key file. So you only have to remember one single master password or select the key file to unlock the whole database. The databases are encrypted using the best and most secure encryption algorithms currently known (AES and Twofish).


    Strong Security
    • KeePass supports the Advanced Encryption Standard (AES, Rijndael) and the Twofish algorithms to encrypt its password databases.
    • Both of these ciphers are regarded as very secure by the cryptography community. Banks are using these algorithms for example, too.
    • Even if you would use all computers in the world to attack one database, decrypting it would take longer than the age of the universe.
    • Even quantum computers won't help that much. The algorithms are symmetric so its complexity would be reduced a bit, anyway, the sun will go nova before you have decrypted the database.
    • The complete database is encrypted, not only the password fields. So your usernames, notes, etc. are protected, too.
    • SHA-256 is used as password hash. SHA-256 is a 256-bit cryptographically secure one-way hash function. Your master password is hashed using this algorithm and its output is used as key for the encryption algorithms.
    • In contrast to many other hashing algorithms, no attacks are known yet against SHA-256.
    • Protection against dictionary and guessing attacks: by transforming the final master key very often, dictionary and guessing attacks can be made harder.
    • In-Memory Passwords Protection: Your passwords are encrypted while KeePass is running, so even if Windows caches the KeePass process to disk, this wouldn't reveal your passwords anyway.
    • [2.x] Protected In-Memory Streams: When loading the inner XML format, passwords are encrypted using a session key.
    • Security-Enhanced Password Edit Controls: KeePass is the first password manager that features security-enhanced password edit controls. None of the available password edit control spies work against these controls. The passwords entered in those controls aren't even visible in the process memory of KeePass.

    Multiple User Keys
    • One master password decrypts the complete database.
    • Alternatively you can use key files. Key files provide better security than master passwords in most cases. You only have to carry the key file with you, for example on a floppy disk, USB stick, or you can burn it onto a CD. Of course, you shouldn't lose this disk then.
    • For even more security you can combine the above two methods: the database then requires the key file and the password in order to be unlocked. Even if you lose your key file, the database would remain secure.
    • [2.x] Additionally, you can lock the database to the current Windows user account. The database can then only be opened by the same person who created it.

    Portable and No Installation Required
    • KeePass is portable: it can be carried on an USB stick and runs on Windows systems without being installed.
    • Installer packages are available, too, for the ones who like to have shortcuts in their Windows start menu and on the desktop.
    • KeePass doesn't store anything on your system. The program doesn't create any new registry keys and it doesn't create any initialization files (INI) in your Windows directory. Deleting the KeePass directory (in case you downloaded the binary ZIP package) or using the uninstaller (in case you downloaded the installer package) leaves no trace of KeePass on your system.
    • [1.x] KeePass runs, without downloading any additional libraries, on Windows 98, 98SE, ME, NT, 2000, XP (Home & Pro, 32-bit & 64-bit), 2003 and Vista. No .NET framework is required.
    • [2.x] KeePass requires the Microsoft .NET Framework (which can be downloaded for free at Microsofts website). Windows Vista already includes this framework; for Windows 98 / ME / 2000 / XP you need to install it, if it's not installed already.
    • Ports for other systems like Linux, MacOSX, PocketPC, Smartphone, etc. are available!
    • [2.x] Accessibility: KeePass 2.x features an advanced option that explicitly optimizes the user interface for screen readers.

    Export To TXT, HTML, XML and CSV Files
    • The password list can be exported to various formats like TXT, HTML, XML and CSV.
    • The XML output can be easily used in other applications.
    • The HTML output uses cascading style sheets (CSS) to format the table, so you can easily change the layout.
    • The CSV output is fully compatible with most other password safes like the commercial closed-source Password Keeper and the closed-source Password Agent, also the CSVs can be imported by spreadsheet applications like Microsofts Excel or OpenOffice's Calc.
    • Many other file formats are supported through KeePass plugins.

    Import From Many File Formats
    • KeePass uses the common CSV export format of various passwords safes like Password Keeper and Password Agent. Exports from these programs can be easily imported to your KeePass databases.
    • KeePass can parse and import TXT outputs of CodeWalletPro, a commercial closed-source password safe.
    • KeePass can import TXT files created by Bruce Schneier's Password Safe v2.
    • [2.x] Out of the box, KeePass supports importing more than 20 formats.
    • Many other file formats are supported through KeePass plugins.

    Easy Database Transfer
    • A password database consists of only one file that can be transferred from one computer to another easily.

    Support of Password Groups
    • You can create, modify and delete groups, in which passwords can be sorted into.
    • The groups can be arranged as a tree, so a group can have subgroups, those subgroups can have subgroups themselves, etc.

    Time Fields and Entry Attachments
    • KeePass supports time fields: creation time, last modification time, last access time and expiration time.
    • You can attach files to password entries (useful to store PGP signature files in KeePass for example).

    Auto-Type, Global Auto-Type Hot Key and Drag&Drop
    • KeePass can minimize itself and type the information of the currently selected entry into dialogs, webforms, etc. Of course, the typing-sequence is 100% user-customizable, read the documentation file for more.
    • KeePass features a global auto-type hot key. When KeePass is running in the background (with opened database) and you press the hot key, it looks up the correct entry and executes its auto-type sequence.
    • All fields, title, username, password, URL and notes can be drag&dropped into other windows.

    Intuitive and Secure Windows Clipboard Handling
    • Just double-click on any field of the password list to copy its value to the Windows clipboard.
    • Timed clipboard clearing: KeePass can clear the clipboard automatically some time after you've copied one of your passwords into it.
    • [1.x] Protection against clipboard monitors (other applications won't get notifications that the clipboard content has been changed).
    • [1.x] Paste-once functionality: allow only one paste operation, after pasting the clipboard is cleared automatically by KeePass.

    Searching and Sorting
    • You can search for specific entries in the databases.
    • To sort a password group, just click on one of the column headers in the password list, you can sort by any column.

    Multi-Language Support
    • KeePass can be translated into other languages very easily.
    • Over 30 different languages are available!

    Strong Random Password Generator
    • KeePass can generate strong random passwords for you.
    • You can define the possible output characters of the generator (number of characters and type).
    • Random seeding through user input: mouse movement and random keyboard input.

    Plugin Architecture
    • Other people can write plugins for KeePass.
    • Plugins can extend the functionality of KeePass, like providing additional import/export methods for other file formats.

    Changes from 1.13 to 1.14:

    New Features:
    KeePass is now also available as MSI package.
    Entry field references are now dereferenced in drag&drop operations.
    Added support for writing databases to hidden files.
    Added '-lock' command line option.

    Improved compatibility of browser placeholders with cmd:// URLs.
    Improved compatibility of the database auto-saving option (at exit and locking) with other options.
    Consecutive auto-type delays now add up.
    Improved encoding detection in file import routines.
    Several 64-bit code improvements.
    Various code optimizations.
    Minor other improvements.

    Fixed crash that happened when clicking 'No' in the plugin incompatibility message box while passing a plugin command line argument.
    Special XML characters in group names are now encoded correctly in XML exports (group tree attribute).

    ОС: Windows 98, 98SE, ME, NT, 2000, XP (Home & Pro, 32-bit & 64-bit), 2003 and Vista
    Интерфейс: Русский / Multilanguage
    Homepage: http://keepass.info/

    KeePass 1.14 (Windows Installer EXE)

    Portable KeePass 1.13 (ZIP Package)

    Страница загрузки (все версии)
  2. kamikadzun

    kamikadzun Создатель

    1 авг 2007
    Очень хорошая программа. Только это не варез, программа бесплатно скачивается с официальной страницы (которую автор указал). Кстати есть аналог данной программы под любые платформы - linux, symbian,WM,java,mac. Под линукс и мак называется KeePassX.

    П.С. Кто-нибудь знает степень реальной защиты данной программой?
    pachango нравится это.
Статус темы: