krserv
BANNED | Редактировать | Профиль | Сообщение | Цитировать | Сообщить модератору продолжаю обсуждение: source:Technical FAQ - KeePass Is the Auto-Type feature resistant to keyloggers? KeePass 1.x Only No. The Auto-Type feature has been designed in a way that it's impossible for target applications to distinguish real keys from auto-typed ones. This on the one hand has the advantage that the feature is really compatible with all applications out there. On the other hand, the auto-typed keys can of course be logged by keyloggers. If you worry about keyloggers, you have to use one of the other methods (drag&drop, copying to clipboard, KeeForm, ...). KeePass 2.x Only By default: no. The Auto-Type method in KeePass 2.x works the same as the one in 1.x and consequently is not keylogger-safe. However, KeePass features an alternative method called Two-Channel Auto-Type Obfuscation (TCATO), which renders keyloggers completely useless. This is an opt-in feature (because it doesn't work with all windows) and must be enabled for entries manually. See the TCATO documentation for details. Can Auto-Type locate child controls? No. Auto-Type only checks whether the title of the currently active top level window matches. Browsers like Mozilla Firefox completely draw the window (all controls) themselves, without using standard Windows controls. Consequently it is technically impossible for KeePass to check whether an URL matches (methods like creating a screenshot and using optical character recognition are not reliable and secure). Also, it's impossible to check which child control currently has the focus. These problems can only be avoided by using browser integration plugins, i.e. not using auto-type at all. The user must make sure that the focus is placed in the correct control before starting auto-type Давайте вместе вникать в суть написанного и как можно сделать более безопасным копирование пароля в приложение. У меня Банк-клиент, который не поддерживает двухфакторную аутентификацию с eToken и приходится пароль только копировать в него из keepass. Увы другого выхода в этом случае нет, т.к я привязан к этому Банк-клиенту самим банком. |