need to get some advices on KEEPASS-file: where to store

Einfach Dinge, die nichts mit XAMPP, Apache Friends, Apache, MySQL, PHP und alle dem zu tun haben. Allerlei halt. ;)

need to get some advices on KEEPASS-file: where to store

Postby unleash_it » 24. December 2019 13:30

Hi there

need to get some advices on KEEPASS-file: where to store

I'd just like to check if there's anything I may have overlooked in the issue of where to store the KeePass database and a keyfile for it.
I just realised that I'd always visualised using a 'fixed' location for a KeePass database on one or more synchronised PCs, and a 'movable' location for a keyfile

well i thoght of using a USB stick that I plug in to each PC as I use it.

what do you think about this idea. Is there any practical difference between having the same keyfile permanently stored on every PC I use and carrying my database around from here to there on the USB stick?

pros and cons:
The only advantage I can see is that I would have only one database file and it can never be out of sync.

well what are the possible scenarios.

I also understand the concept that keyfile and database have to be maintained very well in order to work together.

but lets imagine if we say that components A+B have to be simultaneously available to access my passwords, then does it really matter whether A is the database or A is the keyfile? The main difference I think is that the database contents are likely to be not the same.

well if it comes to the disadvantages? I can't see any, but I'd be interested to hear views. To permit usage on any PC, including one I'd never visited before, I could even store a copy of the keyfile in Dropbox or wherever. The keyfile in itself doesn't hold any valuable data so protecting it is not really an issue. Or is it?

but wait: it is like if i am carrying my door with me everywhere I go and leaving lots of copies of my key lying around in public. But if I'm the only one with the door, so what do you advice here.

what can i do to make it better to make it safe?
Interessen: Bikes & steel frames: Linux & SBC https://www.allaboutcircuits.com :: die neuen Knowledge-Base: AFFiNE: There can be more than Notion and Miro. auf affine.pro :: WordPress Entwicklung - sic: make.wordpress.org/core/
User avatar
unleash_it
 
Posts: 779
Joined: 10. December 2011 18:32
Operating System: linux opensuse 12.1

Re: need to get some advices on KEEPASS-file: where to store

Postby nemesis » 24. December 2019 14:50

To be nearly 99% safe, you need keepass on a device without any wireless connection (like an old smartphone in airplane mode) and maybe 2 factor auth. to open your database on that device (yubikey and so on).
You always have to type in your password per hand on an trusted device and operating system/browser.
For surfing you can use one of those live distributions that start from an dvd.
https://tails.boum.org/index.en.html

There are some ways available to steal credentials from your browser or even your keepass database. So it's not an good idea to spread them over a few devices.
Ubuntu 18.04 | SMP P3 1.4 GHz | 6 GByte RegECC | 74 GByte Seagate 15k5 system | 3Ware 9550SXU-4LP with 4x 500 GByte Seagate ES2 Raid 10 data | StoreCase DE400 | PX-230A | Intel Pro/1000MT Dual PCI-X
User avatar
nemesis
AF Moderator
 
Posts: 1044
Joined: 29. December 2002 13:14
Location: Ingolstadt
XAMPP version: depends
Operating System: Linux, BSD, Win, iOS, Android


Return to Allerlei

Who is online

Users browsing this forum: No registered users and 28 guests