TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

KeeWeb: Unofficial KeePass web and desktop client

265 点作者 floriangosse超过 9 年前

17 条评论

dchest超过 9 年前
Do not generate passwords with it, it uses insecure Math.random:<p><a href="https:&#x2F;&#x2F;github.com&#x2F;antelle&#x2F;kdbxweb&#x2F;blob&#x2F;906e927d3e3384db4dd393f6a9cbba00b1c85720&#x2F;lib&#x2F;crypto&#x2F;random.js#L19" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;antelle&#x2F;kdbxweb&#x2F;blob&#x2F;906e927d3e3384db4dd3...</a><p><a href="https:&#x2F;&#x2F;github.com&#x2F;antelle&#x2F;keeweb&#x2F;blob&#x2F;master&#x2F;app&#x2F;scripts&#x2F;util&#x2F;password-generator.js#L29" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;antelle&#x2F;keeweb&#x2F;blob&#x2F;master&#x2F;app&#x2F;scripts&#x2F;ut...</a><p>(in meme form: <a href="https:&#x2F;&#x2F;imgur.com&#x2F;FcZNflQ" rel="nofollow">https:&#x2F;&#x2F;imgur.com&#x2F;FcZNflQ</a>)<p>Filed issue: <a href="https:&#x2F;&#x2F;github.com&#x2F;antelle&#x2F;kdbxweb&#x2F;issues&#x2F;5" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;antelle&#x2F;kdbxweb&#x2F;issues&#x2F;5</a><p>(embarrassing&#x2F;funny: it was me who wrote Salsa20 &quot;user-space&quot; generator used here (<a href="https:&#x2F;&#x2F;github.com&#x2F;antelle&#x2F;kdbxweb&#x2F;blob&#x2F;906e927d3e3384db4dd393f6a9cbba00b1c85720&#x2F;lib&#x2F;crypto&#x2F;salsa20.js#L3" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;antelle&#x2F;kdbxweb&#x2F;blob&#x2F;906e927d3e3384db4dd3...</a>), but it should be properly seeded from secure random number source to be secure. Added this note to the gist where the author found it: <a href="https:&#x2F;&#x2F;gist.github.com&#x2F;dchest&#x2F;4582374#file-salsa20-js-L1-L16" rel="nofollow">https:&#x2F;&#x2F;gist.github.com&#x2F;dchest&#x2F;4582374#file-salsa20-js-L1-L1...</a>)
评论 #11174704 未加载
评论 #11174680 未加载
wwarren超过 9 年前
This is awesome. People are obviously going to give you a hard time about security and your implementation of the important parts of the software, but that&#x27;s the advantage of open source!<p>Edit: I am a daily user of KeePassX and get really tired of the UI after a while so I will definitely be trying this out ASAP!
评论 #11174469 未加载
评论 #11178795 未加载
Sir_Cmpwn超过 9 年前
Check out pass for those wanting a solution in line with the Unix way:<p><a href="https:&#x2F;&#x2F;www.passwordstore.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.passwordstore.org&#x2F;</a>
评论 #11174824 未加载
评论 #11174652 未加载
评论 #11175601 未加载
评论 #11176766 未加载
Sephr超过 9 年前
The reference implementation&#x27;s domain is vulnerable to MITM attacks between KeeWeb and CloudFlare until they set their CloudFlare crypto settings to &quot;strict&quot; and get some real certificates of their own (e.g. Let&#x27;s Encrypt).<p>I submitted an issue here: <a href="https:&#x2F;&#x2F;github.com&#x2F;antelle&#x2F;keeweb&#x2F;issues&#x2F;111" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;antelle&#x2F;keeweb&#x2F;issues&#x2F;111</a><p>Of course exploiting this would be very difficult, but it is <i>possible</i> to MITM the connection between the CloudFlare proxy and GitHub pages as long as keeweb.info continues to not use DNSSEC.
评论 #11180356 未加载
talles超过 9 年前
I always get confused with KeePass, KeePass2 and KeePassX...<p>I use KeePassX on OS X. Will I be able to use this one with my database file?
评论 #11174480 未加载
评论 #11174319 未加载
评论 #11174921 未加载
评论 #11174316 未加载
mjs7231超过 9 年前
This looks awesome. My only gripes with KeePass is the confusion between KeePass,2,X etc; get it together guys. Also there is a serious lack of good browser extensions. There only seems to be one offering and its the clunkiest thing I have ever used. -- That said, as soon as the second problem is addressed, I&#x27;ll be switching as soon as possible. I&#x27;d love to move off my proprietary solution to an open one.
zaphoyd超过 9 年前
How does it handle multiple users&#x2F;computers trying to write to a database on dropbox?
评论 #11174430 未加载
评论 #11174385 未加载
评论 #11174403 未加载
phjesusthatguy3超过 9 年前
That&#x27;s pretty nice. I&#x27;m going to look into packaging it for myself for FirefoxOS. My only issue with it right now is aesthetic: the top item (search box on the main page, &quot;&lt; back to list&quot; in entries, etc) scrolls off the top of the screen, leaving that much blank white space at the bottom of the screen. I&#x27;m on a ZTE Open C running the nightly version of FxOS from <a href="http:&#x2F;&#x2F;builds.firefoxos.mozfr.org&#x2F;doc&#x2F;en&#x2F;devices&#x2F;zte-open-c-eu" rel="nofollow">http:&#x2F;&#x2F;builds.firefoxos.mozfr.org&#x2F;doc&#x2F;en&#x2F;devices&#x2F;zte-open-c-...</a>
评论 #11174610 未加载
openaccount超过 9 年前
The notes field should be a multiline text field. This is mandatory since some data needs more explanation than just a password.
relaxitup超过 9 年前
Does there exist an enterprise grade server&#x2F;webui solution based on a keepass db? We are looking for an enterprise password manager solution that does not need all the ldap&#x2F;ad integration bells&#x2F;whistles (although we may explore ldap integration with the tool in the future). So I was thinking why not just use keepass. And by enterprise grade I guess I really mean it needs to be a multi user solution, but everyone would be working from the same pw db..
评论 #11176735 未加载
greggarious超过 9 年前
This is great. My weekend project this weekend was to move to KeePassX, but it&#x27;s not very usable. This UI is great!
评论 #11174908 未加载
slavik81超过 9 年前
The title should probably be &quot;KeyWeb - a KeePass Web and desktop client&quot; to be clear that this is not the official KeePass client. I was briefly concerned because I generated many passwords with KeePass, but this post is about a different piece of software.
评论 #11176078 未加载
jareds超过 9 年前
Just built this, looks good so far. Being a totally blind back-end developer I&#x27;ve wanted to look at web accessibility, while the app is accessible I think it could be made better so hopefully I can use this as a way to learn.
qertoip超过 9 年前
Excellent work! Clean, beautiful and works out of the box.<p>Is there any way to have a system-wide shortcut to auto-enter passwords? In KeePassX it&#x27;s called &quot;Global Auto Type Shortcut&quot;. I just can&#x27;t live without this ;)
theomega超过 9 年前
Would it be possible to connect this to WebDav (i.e. Own cloud)?
评论 #11174180 未加载
评论 #11174188 未加载
magicmu超过 9 年前
Looks awesome! I&#x27;ve been using 1password, are there any big advantages that KeePass has over it?
评论 #11174329 未加载
评论 #11174650 未加载
评论 #11174304 未加载
评论 #11174327 未加载
pickle27超过 9 年前
I&#x27;ve been waiting &#x2F; hoping someone would build this! thanks!