PhilippC / keepass2android

Password manager app for Android
https://play.google.com/store/apps/details?id=keepass2android.keepass2android
GNU General Public License v3.0
4.81k stars 390 forks source link

[QUESTION] iOS Keepass Mini has been compromised, what can keepass2android learn from that? #2346

Open therealmarv opened 1 year ago

therealmarv commented 1 year ago

It seems that an open source implementation of iOS Keepass Mini has been compromised:

https://old.reddit.com/r/techsupport/comments/13nqarb/suspicious_ios_keepass_client/

I just wonder and open for discussion if there can be any counter measurements which can be implemented for Keepass2Android in regards to this topic to harden Keepass2Android. Having in mind:

The whole topic just made me aware that I have to trust the authors of KeepassXC (desktop) and Keepass2Android (phone) to be always security focused and having the best interest of their users in mind. Was not aware about this weaknesses of my password management system (trust of several entities for extracting/saving my passwords).

AriehSchneier commented 1 year ago

@PhilippC It would be great if you looked into SLSA for the generated app (fully generated in github CI and doesn't require any code to be built on a local users machine):