Post B4h9EEHLvCafKQAuno by pacman@swiss.social
 (DIR) More posts by pacman@swiss.social
 (DIR) Post #B4guHTNKkdF5ho3rJg by keepassxc@fosstodon.org
       0 likes, 12 repeats
       
       🚨 Warning: New FAKE website offering FAKE KeePassXC downloads! Do not fall for it. The correct domain is https://keepassxc.org without hypens!
       
 (DIR) Post #B4guYvJW875xHIb5aS by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       The website is asking for your email address to access the downloads. We never ask for your email address. Do not enter your data there, it's a phishing attempt.
       
 (DIR) Post #B4gvanzGRPS35WaLRY by sn@social.josko.org
       0 likes, 0 repeats
       
       @keepassxc sent email to abuse@dynadot.com and cloudflare abuse (NS records)
       
 (DIR) Post #B4gvhe2no6DOHHV9pA by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @sn Thanks. I've reported it to Microsoft, Google, Netcraft, and other services as well.
       
 (DIR) Post #B4gxb0Q6Pq7nYYMVIu by nestab@infosec.exchange
       0 likes, 0 repeats
       
       @keepassxc 😆 from repository
       
 (DIR) Post #B4gxkG65UvAwmhPcnY by eroc1990@mastodon.parastor.net
       0 likes, 0 repeats
       
       @keepassxcMethinks you should go buy as many typosquat domains as are available before copycats get to them.
       
 (DIR) Post #B4gxubUinWke2irqgi by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @gremlin We already own a lot of variants with different top-level domains and redirect them to keepassxc.org. The only one we couldn't get is .com, because someone snatched it already and has since put it on auction after it was put on block lists. But we cannot also register all possible combinations with hyphens and typos.
       
 (DIR) Post #B4gy0bVHg2EloBzYDA by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @eroc1990 We own several already, but it's a losing game and a pretty expensive one at that.
       
 (DIR) Post #B4gyDPlicPAFB5mt3w by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @gremlin There's an infinite number of possible typos like that. Registering them all is pretty futile and expensive.
       
 (DIR) Post #B4gyNydtoT6CEWAOJM by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @gremlin And then multiply it by 10 different TLDs.
       
 (DIR) Post #B4gyyBtS1YTjkri0jg by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @gremlin As I said, we already own quite a few different domains. We're a small open source project. We get a healthy amount of donations, but we cannot spend $2000 a year on domains, just so someone can register yet another one we haven't registered yet.
       
 (DIR) Post #B4gzPRhrL7NIcJHcIa by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @gremlin Six different variants with hyphens, kee, key -pw etc. times 10 TLDs times $30 is $1800. But if you want to help, keepassxc[.]com is on auction for a mere $50,000.
       
 (DIR) Post #B4h0XlwU5Ri1eFerPk by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @gremlin com is taken, see above. We own net, org, eu, de, us, and some others. Most of these TLDs are $10 the first year and then $15-30 for every following year unless you choose a different registrar for each. app and dev are among the most expensive ones. And then you still have to multiply all those by the number of typosquats you want to catch, which are easily 6-10 for each one.
       
 (DIR) Post #B4h14Z8qhSZZVK4wRE by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @gremlin The reason we started registering all those other TLDs is exactly because someone took .com and then used it to distribute fake downloads. We got the domain blocklisted quickly, so they put it up for sale. It's off the blocklist again now, but we haven't been able to acquire it and I don't think they'll ever let go of it unless we pay their scalper price.
       
 (DIR) Post #B4h1QNWgZCyTqld4IS by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @gremlin Of course they want to auction it off. The 50k is just the "buy now, stupid" price. But we're not a registered legal trademark (yet). Otherwise we'd have done that a long time ago.
       
 (DIR) Post #B4h25SYAnCXzIwuijA by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @gremlin I would expect the domain to be put on the safe browsing list for a while and then they'll either drop it or park it. We don't need someone to gift us those domains (unless of course someone has the contacts or measures to transfer keepassxc[.]com to us). We can always buy a few more ourselves, but there will always be more.
       
 (DIR) Post #B4h3oCXdG8PkdjYjh2 by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @gremlin Maybe I'll try again some time. I guess in the meantime I'll spend another €320 on 36 months of more typoquat domains. Fun fact: I checked whether IONOS had a better offer than Godaddy. They did for the domains themselves. But in addition they wanted a fixed one-time fee of just over €1800 for "premium domains". Ridiculous.
       
 (DIR) Post #B4h4mP1Rz5ksiwDFIm by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @gremlin Namecheap was another option. Maybe I'll transfer some there. But in the long run, it's not much cheaper either.
       
 (DIR) Post #B4h4tmfeSUSC5xXIuW by harvestmalletus@tiggi.es
       0 likes, 0 repeats
       
       @keepassxc Jeeze people. Team KeePassXC is trying the best they can. It's absurd to think that a FREE project can just go out and buy $100,000 worth of typo domains. Do a little research into what you're clicking. I for one applaud the effort KeePassXC is making to try and calm it down, but give them a little slack.
       
 (DIR) Post #B4h52QvSfva9GD3Uy8 by qgustavor@urusai.social
       0 likes, 0 repeats
       
       @keepassxc Don't worry about that: I'm sure most people would agree with you that doing something like that is overkill for any FOSS project. If you were a per-profit company, sure, but it just makes no sense requiring that from you. Their expectations make absolutely zero sense for me. Donation money should be spent on better things than extra domains.
       
 (DIR) Post #B4h7AiFuKLpNEUh7vE by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @smalldog Thanks!
       
 (DIR) Post #B4h7FXJSRJKOk5egT2 by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @dreua @eroc1990 Without a registered trademark, there's little we can do.
       
 (DIR) Post #B4h7WlLrUrq1CozgUS by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @gremlin I'll give it a try.
       
 (DIR) Post #B4h9EEHLvCafKQAuno by pacman@swiss.social
       0 likes, 0 repeats
       
       @keepassxc It's curious that this risk is not mentioned on the KeypassXC.org website.
       
 (DIR) Post #B4hAN2sLmue8WRFRxI by jmax@mastodon.social
       0 likes, 0 repeats
       
       @keepassxc - Well, if this one strips out the AI contributions...
       
 (DIR) Post #B4hGNL48kyzufAHmuu by ohir@vivaldi.net
       0 likes, 0 repeats
       
       @keepassxc You can take over malicious domain quite easy.Then you really should take your product to the typo-safe domain name ASAP.  Possibly leveraging current publicity.UDRP process:https://www.icann.org/en/contracted-parties/consensus-policies/uniform-domain-name-dispute-resolution-policy/uniform-domain-name-dispute-resolution-policy-01-01-2020-en
       
 (DIR) Post #B4hLfTccBScgBMsa6i by TheTearMiser@mastodon.social
       0 likes, 0 repeats
       
       @keepassxcAlways Check Your Sources! 5 mins of reasearch saves a lifetime of chasing down your own accounts!
       
 (DIR) Post #B4hN8tgUSlY7MkHi40 by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @TheTearMiser Care to explain?
       
 (DIR) Post #B4hNEfqooAWoCRs0rg by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @jeroengui Not quite a takedown, but Cloudflare forwarded our request. The actual site is hosted at Hetzner.
       
 (DIR) Post #B4hPE1rdg5Ua5j4ex6 by jeroengui@infosec.exchange
       0 likes, 0 repeats
       
       @keepassxc Of course, there’s no full takedown until the domain is placed on client/server hold. That's correct!That said, in practice, I rarely see any recovery once Cloudflare puts up a warning page. It’s usually easier for the threat actor to register a new domain.The good news is that this domain has already propagated across most major AV vendors, and I’ve shared both the domain indicators and the associated malware samples with several partners and information-sharing networks (Quad9, GCA, GSE, etc.). That should help ensure any residual risk is blocked at multiple layers.I'll set up some monitoring for both this domain and any future attempts to impersonate KeePassXC.
       
 (DIR) Post #B4hgGp1hYxyOMihMjQ by TheTearMiser@mastodon.social
       0 likes, 0 repeats
       
       @keepassxcWe are on the same team. I'm reiterating your point. One "-" and because the user didn't check to be sure the link was right... all the hard work you guys put into these apps goes to immediate waste. I apprciate this post from you helping users do that for your product.
       
 (DIR) Post #B4i42W7DTVFGYkzQ1Y by sn@social.josko.org
       0 likes, 0 repeats
       
       @keepassxc tango down. CloudFlare shows suspected malware.
       
 (DIR) Post #B4i7TRs7exZL51SmOW by ErikvanStraten@todon.nl
       0 likes, 0 repeats
       
       @jeroengui : I very much appreciate your work, but, as a bullet proof proxy service, #CloudflareIsEvil - they're complicit to cybercrime.Cloudflare warns for malware/phishing for a specific *URL*, not the domain.A minor change in the adds (or a forwarding site if that is what these scammers use) would bypass Cloudflare's crap measure.I never saw a malware/phishing warning while opening:    https:⧸⧸keepass-xc.com/index.phpNote: I understand that blocking https:⧸⧸sites.google.com for a single malicious page would be problematic, but that's rather due to the fact that Google Sites sucks.@keepassxc  #BigTechIsEvil #Malware #Phishing #FakeSites
       
 (DIR) Post #B4i7TS9UcNSnwtaeTA by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @ErikvanStraten @jeroengui They forwarded our abuse report to the hoster of the actual page. We’ll see.Also everyone, if you must visit the page, at least do it in a private window or clear your history afterwards, so you don’t accidentally open it again later!
       
 (DIR) Post #B4iARAeqzQHuyVrWgC by insignificant_nagus@mastodon.social
       0 likes, 0 repeats
       
       @keepassxc I installed keepassxc yesterday in a hurry, normally I do pay a lot of attention to the URL, in hindsight not so sure...So if I didn't have to enter an email, I should have chosen the right one? Or at least let's say, not this particular one?Is the download malware that leaks the pw datatbase in plain text? Is the signature known to av programs?
       
 (DIR) Post #B4ke4XfGfflGbr6MuO by Suiseiseki@freesoftwareextremist.com
       0 likes, 0 repeats
       
       @keepassxc You already started to offer fake proprietary versions of keepassxc, as it's slopware now?
       
 (DIR) Post #B4ke4XqxyB7RC8Zi8u by Zergling_man@sacred.harpy.faith
       0 likes, 0 repeats
       
       @Suiseiseki @keepassxc Today, too, motherfuckers need password management.
       
 (DIR) Post #B52xZd2U8OvGEImE1g by RavenLuni@furry.engineer
       0 likes, 0 repeats
       
       @keepassxc Your brain is the only password manager you should ever need.
       
 (DIR) Post #B5CAJ3OBxYtirBzoy8 by odnankenobi@fosstodon.org
       0 likes, 0 repeats
       
       @keepassxc @dreua @eroc1990 how costly is it to have a registered trademark? I imagine there are other benefits that might make it worth it depending on the cost.Might be the only somewhat reliable way of leveraging official mechanisms to take down copycats and scam attempts
       
 (DIR) Post #B5E1MiSLDgPdoyWolM by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @odnankenobi @dreua @eroc1990 trademarks do not automatically protect anything. The owner is required to pursue legal action to protect the mark. That costs... a LOT of money.
       
 (DIR) Post #B6IJGUfMCRjKvF9cDw by mikeTesteLinuxQlub@qlub.social
       0 likes, 0 repeats
       
       @keepassxc Only trust repo from my distro now 😂