我觉得如果自己的电脑都没保护好的话,谈密码安全会不会有点……拖库泄露了密码,还可以找那些企业背锅,本地的东西,还得先从自身出发找问题啊。或者下次还可以讨论一下因为键盘记录器导致各类密码管理软件在录入数据时就被 get 了密码的问题么?_(:з」∠)_ 啊,抱歉我就是卖个萌,并没有仔细看文章,标题倒是看到了。|・ω・`)
@seki 双通道自动输入混淆: http://keepass.info/help/v2/autotype_obfuscation.html 即使被截取,也不是原密码. 目前是安全的,但是: None of the currently available keyloggers or clipboard spies can eavesdrop an obfuscated auto-type process, but it is theoretically possible to write a dedicated spy application that specializes on logging obfuscated auto-type.
wandero
2015-11-07 09:42:49 +08:00
@LazyZhu "KeePass 支持两步且可以设置成自动填写" 这个是指 TAN 还是类似 Winauth 类的东西? TAN 好像支持的地方少还只一批能用十次,频繁登陆的话会不会比较麻烦?
LazyZhu
2015-11-07 09:49:37 +08:00
@wandero 我是用插件来实现的: https://bitbucket.org/devinmartin/keeotp/wiki/Home Auto Type As of version 1.0.4 there is a custom placeholder that allows a TOTP code to be entered into the system with the KeePass auto type system. To configure this go into the settings of your KeePass entry that contains your TOTP key. Navigate to the Auto-Type tab. Configure your custom sequence with the placeholder {totp}. The {totp} will be replaced with your current totp authentication code.