Videos

Published on August 26th, 2013 📆 | 7053 Views ⚑

0

KeePass & TrueCrypt (TCATO)


iSpeech



Most password managers rely on auto-typing (auto-filling) data into login fields. So does Keepass. But auto-typed data can be key-logged. Keepass provides a way around this vulnerability through enabling a use of Two-Channel Auto-Type Obfuscation (TCATO) for data entry at logins. I do not know of any other mainstream password managers who provide their users with this type of protection.

The Auto-Type feature of KeePass is very powerful: it sends simulated keypresses to other applications. This works with all Windows applications and for the target applications it's not possible to distinguish between real keypresses and the ones simulated by Auto-Type. This at the same time is the main disadvantage of Auto-Type, because keyloggers can eavesdrop the simulated keys. That's where Two-Channel Auto-Type Obfuscation (TCATO) comes into play.

TCATO makes standard keyloggers useless. It uses the Windows clipboard to transfer parts of the auto-typed text into the target application. Keyloggers can see the Ctrl-V presses, but do not log the actual contents pasted from the clipboard.





http://keepass.info/help/v2/autotype_obfuscation.html

source

Tagged with:



Comments are closed.