Benjamin-Loison / KeePassDX

Lightweight vault and password manager for Android, KeePassDX allows editing encrypted data in a single file in KeePass format and fill in the forms in a secure way.
https://www.keepassdx.com/
GNU General Public License v3.0
0 stars 0 forks source link

Web-browser and other apps integrations #5

Open Benjamin-Loison opened 8 months ago

Benjamin-Loison commented 8 months ago

Fennec web-browser for instance.

Like KeePassXC web-browser add-on.

What is the purpose of the registered On-screen keyboard?

image

+69

Is your feature request related to a problem? Please describe. A clear and concise description of what the problem is. Ex. I'm always frustrated when [...]

Describe the solution you'd like A clear and concise description of what you want to happen.

Describe alternatives you've considered A clear and concise description of any alternative solutions or features you've considered.

Additional context Add any other context or screenshots about the feature request here.

Benjamin-Loison commented 6 months ago

KeePassDX/wiki/Home/2fc6dbad3baccc168fffe19208ffb2e24c17a423:

The Magikeyboard is an Android keyboard specially designed to fill in forms securely with the elements of a database entry.

Should investigate more especially why it does not look user-friendly to me.

Should investigate the app settings concening this possibility.

Magikeyboard · Kunzisoft_KeePassDX Wiki.pdf.txt

Magikeyboard · Kunzisoft_KeePassDX Wiki.xopp.xml.zip

Using the clipboard on your device to copy data from an entry may be convenient, but it is also dangerous.

The clipboard is shared by all apps, It is therefore recommended to use this functionality for non-sensitive data. KeePassDX will try to delete the clipboard elements at the end of the time limit but some devices do not allow to delete any data stored in the clipboard.

Trust

When the application is started for the first time, sensitive data such as passwords and hidden fields are not accessible in the clipboard. These fields have a gray copy icon which asks the user if he trusts his clipboard or not. (It is not recommended to trust your clipboard because most are not secure but easy to use.) You can change this behavior at any time in Settings -> Form filling -> Clipboard trust

...

Compatibility

WARNING: Some devices do not correctly delete the data from the clipboard, this issue is caused by the device's operating system, which can not be corrected from the KeePassDX app. In this case, the timeout defined in Settings -> Form filling -> Clipboard timeout cannot delete any element from the clipboard.

Unfortunately, if your operating system has a clipboard containing a history, it may not be possible to delete items from this clipboard.

It is not recommended to use this method to copy passwords, use the Magikeyboard or Autofill instead.

Related to Benjamin-Loison/android/issues/{32,3}.

Browser Tested Version Store Autofill Description
Fennec 82.1.1 F-Droid Native -

Source: KeePassDX/wiki/AutoFill/22c05969054da098a0d568a9825c53a3355f19b1#compatibility-mode

Form security

Please note that the use of the Autofill service in third party forms cannot be secured by KeepassDX, make sure you trust the applications and the websites using it.

Why have to trust the websites and even apps?

It is recommended that you use native autofill compatible web browsers to optimize form filling, for security and to use registration.

Benjamin-Loison commented 5 months ago

Related to Benjamin-Loison/android/issues/55.

Benjamin-Loison commented 5 months ago

image

image

image

image

Benjamin-Loison commented 4 months ago

Note that on LineageOS 21 there is a toast notification when an app read the clipboard content, so if as long as there is a secret in the clipboard I pay attention to toast notifications, then I can know what app(s) accessed the secret. Should test with Termux if background app can access the clipboard content.

Benjamin-Loison commented 3 months ago

Related to Benjamin-Loison/keepassxc-browser/issues/57.

Benjamin-Loison commented 3 months ago

image

Benjamin-Loison commented 3 months ago

Related to Benjamin_Loison/L_Identite_Numerique_La_Poste/issues/1.

Benjamin-Loison commented 1 week ago

Related to Benjamin-Loison/keepassxc/issues/6.