Posts by keepassxc@fosstodon.org
(DIR) Post #B4gyyBtS1YTjkri0jg by keepassxc@fosstodon.org
0 likes, 0 repeats
@gremlin As I said, we already own quite a few different domains. We're a small open source project. We get a healthy amount of donations, but we cannot spend $2000 a year on domains, just so someone can register yet another one we haven't registered yet.
(DIR) Post #B4gzPRhrL7NIcJHcIa by keepassxc@fosstodon.org
0 likes, 0 repeats
@gremlin Six different variants with hyphens, kee, key -pw etc. times 10 TLDs times $30 is $1800. But if you want to help, keepassxc[.]com is on auction for a mere $50,000.
(DIR) Post #B4h0XlwU5Ri1eFerPk by keepassxc@fosstodon.org
0 likes, 0 repeats
@gremlin com is taken, see above. We own net, org, eu, de, us, and some others. Most of these TLDs are $10 the first year and then $15-30 for every following year unless you choose a different registrar for each. app and dev are among the most expensive ones. And then you still have to multiply all those by the number of typosquats you want to catch, which are easily 6-10 for each one.
(DIR) Post #B4h14Z8qhSZZVK4wRE by keepassxc@fosstodon.org
0 likes, 0 repeats
@gremlin The reason we started registering all those other TLDs is exactly because someone took .com and then used it to distribute fake downloads. We got the domain blocklisted quickly, so they put it up for sale. It's off the blocklist again now, but we haven't been able to acquire it and I don't think they'll ever let go of it unless we pay their scalper price.
(DIR) Post #B4h1JTNKQDBBxnxYI4 by keepassxc@fosstodon.org
0 likes, 0 repeats
@aaron No. Write it down and store it in a safe place somewhere.
(DIR) Post #B4h1QNWgZCyTqld4IS by keepassxc@fosstodon.org
0 likes, 0 repeats
@gremlin Of course they want to auction it off. The 50k is just the "buy now, stupid" price. But we're not a registered legal trademark (yet). Otherwise we'd have done that a long time ago.
(DIR) Post #B4h25SYAnCXzIwuijA by keepassxc@fosstodon.org
0 likes, 0 repeats
@gremlin I would expect the domain to be put on the safe browsing list for a while and then they'll either drop it or park it. We don't need someone to gift us those domains (unless of course someone has the contacts or measures to transfer keepassxc[.]com to us). We can always buy a few more ourselves, but there will always be more.
(DIR) Post #B4h3oCXdG8PkdjYjh2 by keepassxc@fosstodon.org
0 likes, 0 repeats
@gremlin Maybe I'll try again some time. I guess in the meantime I'll spend another €320 on 36 months of more typoquat domains. Fun fact: I checked whether IONOS had a better offer than Godaddy. They did for the domains themselves. But in addition they wanted a fixed one-time fee of just over €1800 for "premium domains". Ridiculous.
(DIR) Post #B4h4mP1Rz5ksiwDFIm by keepassxc@fosstodon.org
0 likes, 0 repeats
@gremlin Namecheap was another option. Maybe I'll transfer some there. But in the long run, it's not much cheaper either.
(DIR) Post #B4h7WlLrUrq1CozgUS by keepassxc@fosstodon.org
0 likes, 0 repeats
@gremlin I'll give it a try.
(DIR) Post #B4hNEfqooAWoCRs0rg by keepassxc@fosstodon.org
0 likes, 0 repeats
@jeroengui Not quite a takedown, but Cloudflare forwarded our request. The actual site is hosted at Hetzner.
(DIR) Post #B4i7TS9UcNSnwtaeTA by keepassxc@fosstodon.org
0 likes, 0 repeats
@ErikvanStraten @jeroengui They forwarded our abuse report to the hoster of the actual page. We’ll see.Also everyone, if you must visit the page, at least do it in a private window or clear your history afterwards, so you don’t accidentally open it again later!
(DIR) Post #B6BLDvMLL0pcdwRYps by keepassxc@fosstodon.org
0 likes, 0 repeats
RE: https://mastodon.social/@bagder/116554421875449945"All modern AI models are good at this now. Anyone with time and some experimental spirits can find security problems now. The high quality chaos is real."Second that. The number of confidential security reports for KeePassXC has also gone up (though nothing major yet). Those AI reports used to be slop, but they are now mostly legitimate . We don't know which models are being used by the reporters, but occasionally, we get the same things reported multiple times within the span of just days.RT: https://mastodon.social/users/bagder/statuses/116554421875449945
(DIR) Post #B6BMBAHjUKZm1HXF5c by keepassxc@fosstodon.org
0 likes, 0 repeats
@dzwiedziu The reports we get these days are mostly legitimate now (not all, but most). Legitimate doesn't necessarily mean "high impact".
(DIR) Post #B6BTr1h0WXxZDFGW1o by keepassxc@fosstodon.org
0 likes, 0 repeats
@Chronocide We didn’t receive that many before, so unclear. They are helpful in the sense that some issue was found that people previously missed. Most are low-hanging fruit like hypothetical integer overflows and mismatches between code and documentation etc.
(DIR) Post #B6BU0KVFxMP49tCmJs by keepassxc@fosstodon.org
0 likes, 0 repeats
@Chronocide KeePassXC is in the convenient position of having a rather low attack surface to begin with.
(DIR) Post #B6izNBCWh9F07yFRFA by keepassxc@fosstodon.org
0 likes, 1 repeats
Here's your regular reminder to always check where you're downloading things from. #KeePassXC 's website is https://keepassxc.org.Do not blindly trust search results or AI answers at the top!https://blog.eclecticiq.com/seo-poisoning-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer
(DIR) Post #B6slw0VoyJGBKoaLE8 by keepassxc@fosstodon.org
0 likes, 0 repeats
@mikeTesteLinuxQlub Yes
(DIR) Post #B8u9ro4mNDPI5Inwo4 by keepassxc@fosstodon.org
0 likes, 0 repeats
@Numerfolt We don’t have that feature at the moment. But there’s also no way to verify the authenticity of an app.
(DIR) Post #BA1mO6gVAhLJSr6WZc by keepassxc@fosstodon.org
0 likes, 0 repeats
@kerravonsen @Em0nM4stodon Probably due to the Qt5 dependency. You can try out 2.8 snapshots.