keepassxreboot / keepassxc-browser

KeePassXC Browser Extension
GNU General Public License v3.0
1.78k stars 188 forks source link

Passwort der Datenbank wird angezeigt im Browser-Erweiterung in Klartext immer/ tag Password of the database is displayed in the browser extension in plain text always #2343

Closed Rafaelito2609 closed 2 months ago

Rafaelito2609 commented 2 months ago

Hallo. wenn ich mit einer Datenbank die auf meinem Rechner gespeichert ist verbunden bin und ich auf das Icon der Erweiterung von KeepassXC im Browser drücke, wird angezeigt, dass ich mit meiner Datenbank "xyz" verbunden bin.

ABER darunter ist dann mein Passwort unverdeckt und unverschlüsselt sichtbar. Ist das normal? Ist das gewollt? Kann man das abstellen?

Wäre doch sicherer, das möglichst sicher Passwort (wenn überhaupt nur bei Eingabe) sichtbar zu haben. So könnte doch jeder, der zufällig am Pc vorbeiläuft während ich nicht am Platz bin, direkt ohne suchen zu müssen, mein Passwort sehen.

Hello. If I am connected to a database that is stored on my computer and I click on the KeepassXC extension icon in the browser, it shows that I am connected to my database "xyz".

BUT underneath my password is visible, uncovered and unencrypted. Is that normal? Is that intentional? Can you turn it off?

Wouldn't it be safer to have the most secure password visible (if at all, only when entering it). That way, anyone who happens to walk past the PC while I'm not at my desk could see my password straight away without having to search.

varjolintu commented 2 months ago

I'm not quite sure what you mean here by "y password is visible, uncovered and unencrypted". Could you give some more details or screenshots?

Or are you talking about KeePassXC? It does not show the password by default, and it has nothing to do with the browser extension.

Rafaelito2609 commented 2 months ago

When connecting to the database, I accidentally entered the password under "Identifier" in the window that opened when connecting. I have now deleted the connections, first logged into KeepassXC. Then opened the browser again and this time entered a "fictitious" name/identifier, which is now displayed. I think it was my mistake because I didn't know, I thought it was the "password" entry to connect KeepassXC browser to the key database.

varjolintu commented 2 months ago

The dialog should clearly say that user should give a name for connection. It doesn't ask for a password. Your solution is what you described: make a new connection and delete the previous one from the extension and KeePassXC side (database settngs).