TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

KeePass flaw allows retrieval of master password, PoC is public

9 pointsby pil0uabout 2 years ago

2 comments

DemiGuruabout 2 years ago
Also note that KeepassXC is unaffected - <a href="https:&#x2F;&#x2F;github.com&#x2F;keepassxreboot&#x2F;keepassxc&#x2F;discussions&#x2F;9433">https:&#x2F;&#x2F;github.com&#x2F;keepassxreboot&#x2F;keepassxc&#x2F;discussions&#x2F;9433</a>
theamkabout 2 years ago
Note, this is allows one to &quot;retrieve the master password from the software’s memory&quot;, not from disk.<p>Which means the importance is pretty low.. if you have a malicious program running in your account it is game over anyway, as it can sniff the keyboard or inject code into process or do many other things to steal your password.<p>Researcher says the big problem is &quot;someone could obtain access to your computer and conduct forensic analysis&quot;. I agree with that, and I also thing this is not a big concert for many people.