KeePassXC is a modern, secure, and open-source password manager that stores and manages your most sensitive information. You can run KeePassXC on Windows, macOS, and Linux systems. KeePassXC saves many different types of information, such as usernames, passwords, URLs, attachments, and notes in an offline, encrypted file that can be stored in any location, including private and public cloud solutions. Team email PGP key: 2FB8 CA9C 105D 8D57 BB97 46BD
Public Key
npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Profile Code
nprofile1qqs2672jfkc97v2rxsn2cjzdjfsuxxv79eqglgwz32ntwvyqs6vac7spz3mhxue69uhhyetvv9ujuerpd46hxtnfduqs6amnwvaz7tmwdaejumr0dslkyp2k
Show more details
Published at
2026-06-10T08:43:19Z Event JSON
{
"id": "5e9cc89e038a9bb7dd26eca2b51acd34d44270a1babe3889bac02f5e4ad651cc" ,
"pubkey": "ad79524db05f31433426ac484d9261c3199e2e408fa1c28aa6b730808699dc7a" ,
"created_at": 1781080999 ,
"kind": 0 ,
"tags": [
[
"proxy",
"https://fosstodon.org/users/keepassxc",
"activitypub"
],
[
"client",
"Mostr",
"31990:6be38f8c63df7dbf84db7ec4a6e6fbbd8d19dca3b980efad18585c46f04b26f9:mostr",
"wss://relay.ditto.pub"
]
],
"content": "{\"name\":\"Team KeePassXC\",\"about\":\"KeePassXC is a modern, secure, and open-source password manager that stores and manages your most sensitive information.\\n\\nYou can run KeePassXC on Windows, macOS, and Linux systems. KeePassXC saves many different types of information, such as usernames, passwords, URLs, attachments, and notes in an offline, encrypted file that can be stored in any location, including private and public cloud solutions.\\n\\nTeam email PGP key: 2FB8 CA9C 105D 8D57 BB97 46BD\",\"picture\":\"https://cdn.fosstodon.org/accounts/avatars/109/328/392/729/834/441/original/499bf9ac75dae150.png\",\"banner\":\"https://cdn.fosstodon.org/accounts/headers/109/328/392/729/834/441/original/555dc526fe5aeac1.png\",\"nip05\":\"[email protected] \",\"fields\":[[\"Website\",\"https://keepassxc.org\"],[\"GitHub\",\"https://github.com/keepassxreboot/keepassxc\"],[\"Snapshot Builds\",\"https://snapshot.keepassxc.org\"],[\"Bluesky\",\"https://bsky.app/profile/keepassxc.org\"]]}" ,
"sig": "2b56181a99bf5aa21127c5bb50f88b8867b4721bb75d5cd1d9a56afdb8aafe35a9c7d73713e07c6f035b5e1afdbf5402b4125d9104f662514d02a8e7b2df2a15"
}
Last Notes npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…9rrf Not quite a takedown, but Cloudflare forwarded our request. The actual site is hosted at Hetzner. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…l4j9 @nprofile…dntq Without a registered trademark, there's little we can do. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…dntq We own several already, but it's a losing game and a pretty expensive one at that. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…vu5u Thanks. I've reported it to Microsoft, Google, Netcraft, and other services as well. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC The website is asking for your email address to access the downloads. We never ask for your email address. Do not enter your data there, it's a phishing attempt. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC 🚨 Warning: New FAKE website offering FAKE KeePassXC downloads! Do not fall for it. The correct domain is https://keepassxc.org without hypens! https://cdn.fosstodon.org/media_attachments/files/116/302/549/635/481/199/original/2f7d1b091809fa3c.png npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…fh5j Can you point to the issue report you're referring to? npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC New bugfix release: #KeePassXC 2.7.12. More information and full changelog at https://keepassxc.org/blog/2026-03-10-2.7.12-released/ npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…ufyn It’s loosely based on entropy or Kolmogorov complexity, but it’s not the same. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…ufyn We use zxcvbn. It’s a password strength measure that takes into account frequent patterns. Entropy per se is not a useful measure for password strength. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…ufyn Use the password strength meter in the password generator. Entropy per se is not a useful measure for passwords. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…76dd We have no reason to change our recommendation at the moment. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…vchw @nprofile…fqkf @nprofile…ptur @nprofile…nanz @nprofile…ulx7 @nprofile…463r Then you still have the problem that even if your authentication cannot be replayed, all the work you do is still being recorded. The attacker might not be able to lock you out of your account, but basically everything else I can be done. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…vchw @nprofile…fqkf @nprofile…ptur @nprofile…nanz @nprofile…ulx7 @nprofile…463r For authentication, yes. For encryption, no. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…fqkf @nprofile…ptur @nprofile…nanz @nprofile…ulx7 @nprofile…463r A key logger is always “doom”. If it records USB devices, a YubiKey won’t help you either. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC To everyone experience issues with KeePassXC-Browser on Edge at the moment: We are aware of that. It's caused by a browser engine bug that has already been rolled back in other Chromium-based browsers, but not Edge. Please be patient, downgrade, or use this workaround: https://github.com/keepassxreboot/keepassxc-browser/issues/2838#issuecomment-3788210495 npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…nfl7 I don't see your IBAN, though. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…nfl7 Your name (with last name as asterisks if you haven't checked the full name reveal option). npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…za8k The QR code would do the same. The only way I could imagine it to make a difference is if you scan it from within the app. But then why would it even bother opening when you scan it externally? This looks like a bug to me. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…za8k The QR code contains exactly that link. This seems to be an issue with the Sparkasse app specifically. You can also donate to wero at keepassxc.org. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…d2dq It's a separate account to manage and people could do funny things with direct debit. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…9fx4 Wasn’t too easy to find a suitable bank for that. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC It's a test run. We'll evaluate how popular this actually is and whether it's worth the hassle. :-) npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC Due to repeated request, we now support SEPA transfer and Wero as new donation methods. Want to support us? Go to https://keepassxc.org/donate/ 💰 npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…yex7 Funny. We also got exactly the opposite feedback. ^^ npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…y2q9 @nprofile…9dx0 As I understood, the selection was random, which could definitely be questioned. Though adding some lesser known choices can make sense. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC Based on early feedback provided from the BSI (and similar request in the past), KeePassXC version 2.7.11 (released two weeks ago) changed the default auto-lock setting after inactivity to "on" with a timeout of 15 minutes. Go to settings -> Security in case you want to restore the previous behaviour. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC Earlier this year, the German BSI together with the Consumer Advice Centre NRW performed a review of 10 popular password managers. What can we say? We're happy to be one of only few to receive a very positive review without major security concerns. 🥳 We're also mentioned explicitly for being particularly privacy-friendly. The full report (in German) can be found at https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/DVS-Berichte/passwortmanager_sicherheit_datenschutz.html and https://www.verbraucherzentrale.nrw/wissen/digitale-welt/apps-und-software/10-passwortmanager-im-vergleich-113439 npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…s9ww Thanks for the concern, but as written in the blog post, we are not being overwhelmed by code contributions, neither AI nor otherwise. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC https://fosstodon.org/@keepassxc/115601882012937086 The full report of the CSPN audit performed by Synacktiv on behalf of ANSSI is now available on our website. If you ever wanted to know how KeePassXC works under the hood, it should make for an interesting read with many annotated code examples. Link: https://keepassxc.org/audits/#cspn-2025-11-17 npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC The full report of the CSPN audit performed by Synacktiv on behalf of ANSSI is now available on our website. If you ever wanted to know how KeePassXC works under the hood, it should make for an interesting read with many annotated code examples. https://keepassxc.org/audits/#cspn-2025-11-17 https://fosstodon.org/@keepassxc/115601882012937086 npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…x9sq You can download it from our website. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…j69e 🤷 npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…j69e Why do you ask us? Feel free to start one. So far, the most "fuzzy" thing in the "mix" has been us and other human contributors. Which is why we have code review and a test suite. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…4kcy We don't really do patch releases. Treat the last digit as our minor release and the second digit as our major release. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC New macOS DMG and AppImage builds have been posted as 2.7.11-1, which fix code signing and packaging issues. https://elk.zone/fosstodon.org/@keepassxc/115604317140706945 npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC New macOS DMG and AppImage builds have been posted as 2.7.11-1. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC Update: There's an issue with the code signature on macOS, which prevents users from using the browser extension and the CLI tool. We're looking into that and will post a fix later today. https://github.com/keepassxreboot/keepassxc/issues/12713#issuecomment-3570094213 npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…7cvy This seems to be a known issue with the code signature. We’re looking into it. https://github.com/keepassxreboot/keepassxc/issues/12713 npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC 🎉 We're very happy to announce our new release KeePassXC 2.7.11 and... *drumroll* that the KeePassXC version 2.7.9 has been awarded a CSPN Security Visa by the French National Cybersecurity Agency (ANSSI). 🎉❤️🔒 See our blog post for more information: https://keepassxc.org/blog/2025-11-23-2.7.11-released/ #VisaSecu #KeePassXC https://cdn.fosstodon.org/media_attachments/files/115/601/873/371/327/882/original/91b0814e19527224.png https://cdn.fosstodon.org/media_attachments/files/115/601/873/728/000/631/original/16051e5ab654859d.png npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC On 17 November 2025, KeePassXC (Version 2.7.9 for Windows 10) has been awarded a security Visa by the French National Cybersecurity Agency (ANSSI) for a First-level Security Certification (CSPN) with report No. ANSSI-CSPN-2025/16. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC The most notable new features are: support for more file types in the inline attachment viewer, the ability to edit text file attachments, a new database merge confirmation dialog, support for groups in KeeShare, and an option for automatically generating passwords in new entries. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…83qc Not the kind of crypto that keeps your passwords safe from peeping eyes. 😉 npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…yk63 The Airdrop page is an imitation of an existing page, but you only get there after a bunch of redirects. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC 🚨Careful! There seems to be a series of Medium posts advertising a new $KEEPASSXC crypto coin with links to fake airdrop websites. THIS IS NOT REAL! Stay away! We don’t offer crypto coins and we have not the slightest desire to do so. https://cdn.fosstodon.org/media_attachments/files/115/527/898/390/930/142/original/2ba294b733a0b626.jpeg https://cdn.fosstodon.org/media_attachments/files/115/527/898/392/026/991/original/31f617818e828c53.jpeg https://cdn.fosstodon.org/media_attachments/files/115/527/898/391/580/974/original/6a5188aa7c611b1d.jpeg npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…sn9v @nprofile…p7lw Much less actually. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…uqgz KeePass is a fantastic product with an impeccable track record. But you should adjust your own trust model. For all you know, KeePass’s entire code base could be vibe coded and you’d never find out (I’m sure it’s not, neither is ours). There’s also no public record of any kind of code review, human or AI. The point is, it’s weird to trust one over the other here based on the little data you have. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…p7lw to eaches own npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…mpfd @nprofile…yuel @nprofile…np83 They don’t even have a public code repository, but you do you. Thank goodness there are choices for everyone. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…yuel @nprofile…np83 There is a small percentage of checked and tested code that was generated by an LLM. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…np83 There are no AI features in KeePassXC, so there’s so encryption backdoor. But we wrote that in the article. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…0gc9 @nprofile…9zs8 Which is speculation and it is addressed by the second-to-last paragraph. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…a7m5 @nprofile…9zs8 We are not doing anything behind the scenes. It's as transparent as it can be. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…s9ww As we detailed in the blog post, we don't vibe code. Besides, you do not provide evidence for code that passes our QA is bad or what the harms of "vibe coding" would be in our case. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…9zs8 We had a longer section in the first draft, but decided to shorten it, since there is too much speculation in this argument in the first place and it's a bit beside the point. Text LLMs are designed to appeal to humans (which they do terribly sometimes), but it's not something that a trained individual would fall for. Code LLMs, on the other hand, have different alignment processes to ensure the generation matches a specification. Code isn't optimised to look good, it has to be correct. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC We wrote up a blog post detailing our development and quality assurance workflow. We describe how new contributions are merged into the code base, and we address the change to our policy regarding AI-assisted code submissions and the concerns raised about it. https://keepassxc.org/blog/2025-11-09-about-keepassxcs-code-quality-control/ npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…6ufz Please check our existing issues on GitHub and open a new one if yours is not among them. Constant new database prompting shouldn't happen. We don't display info about the client requesting that at the moment, which is an open issue. https://github.com/keepassxreboot/keepassxc/issues/8174 npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…uh47 @nprofile…p7lw We are completely open and transparent with our development process. You can find everything on GitHub. This whole discussion only exists because of that transparency. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…fpyu Thank you for the discussion points! npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…nydn No worries! npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…p7lw We’re working on a blog post with some more information. Many here seem to be largely unaware of our general development process and fill the gaps with their own interpretation. I don’t think adding more to the README is needed or useful, since it’s a moving target. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…p7lw Thank you. We will consider more explicit language in the README. We are also working on a blog post to describe all of this a little clearer (social media is not the best at conveying complex topics). npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…p7lw That wasn't the counter, it is just reality. I said we already disclose at the PR level. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…eydk @nprofile…nydn You are welcome to contribute, we have over 600 issues you can pull from. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…346h @nprofile…nydn Uhhh, we are definitely part of that community. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…p7lw I find it is a reasonable assumption that an project that allows for AI contributions may contain AI code. Everything that has been merged has been checked and amended, so it has passed the barrier. The problematic code is in front of the barrier, not beyond. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…twyd @nprofile…p7lw It means what it means, there is no requirement. We already disclose use at the individual PR level which is far more informative than a blanket statement. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…p7lw It is incredibly important to understand the technology and its limitations. That is exactly what we did and will continue to do. There is never any implicit trust of any code. Even maintainer hand-developed code is reviewed by a co-maintainer prior to merging. No other FOSS password manager has that level of intense scrutiny. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…p7lw Frankly because we don't use generative ai that often. This project is easily 99% hand coded. Even generative ai submissions are co-developed with human input and fixes. Also, there is absolutely no requirement to disclose use of AI, as discussed we already make it clear which submissions are AI assisted. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…p7lw We use the labels to disclose our own use. What other disclosure do you need? We don’t commit to the main branch directly. Pull requests are not only for external contributors. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…p7lw direct link to AI Assisted PR's (this is all, even draft unmerged ones): https://github.com/keepassxreboot/keepassxc/pulls?q=sort%3Aupdated-desc+is%3Apr+label%3A%22pr%3A+ai-assisted%22+ npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…nydn sure, happy to discuss. We use generative ai to help us code simple things and improve our pull request reviews. No code is ever merged to the develop branch (ie, in production) without a human reviewing and often times cleaning/quality improving the code. This applies to third party submissions and AI submissions equally. Generative AI has already been helpful to help us find and prevent bugs and security issues during several pull request reviews. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…p7lw Every pull request that has AI in it is marked with a label. You can look them up, it’s all fully transparent. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…p7lw link to README: https://github.com/keepassxreboot/keepassxc/#generative-ai npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…0phu @nprofile…lpr0 We posted to our README and CONTRIBUTING the 'policy' on LLM use. You must declare its use on submission. We have had people already follow that policy and their contributions were reviewed with the same level of rigor and testing as other submissions. Its more of an awareness thing than anything else. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…lpr0 @nprofile…hl8k @nprofile…n3e6 @nprofile…9dx0 The thought is what makes a pull request dangerous. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…lpr0 @nprofile…hl8k @nprofile…n3e6 @nprofile…9dx0 Oh, for sure! In five years time we’ll be seeing a lot of technical debt due to LLM code. But it’s not because an LLM wrote the code, it’s because people used LLMs to generate a lot more code than they could realistically check for correctness or lacked the skills to do so. That LLMs somehow add invisible ink to their PRs is a weird argument. I don’t trust LLMs but I also don’t trust (or understand) people. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…lpr0 @nprofile…hl8k @nprofile…n3e6 @nprofile…9dx0 You are making a lot of assumptions about us and our development workflow there. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…57v2 @nprofile…2pm5 Considering our software is free to use, I'm not sure how this impacts us in any way. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…hl8k @nprofile…n3e6 @nprofile…9dx0 have you ever received and reviewed code submissions from the general public? I certainly have, hundreds of them, they ALL CONTAIN TRIVIAL ERRORS AND SECURITY PROBLEMS. Stop fooling yourself, open software development is full of land mines. We treat LLM code exactly how we treat drive by contributors and our own maintainers. Nothing is trusted implicitly. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…2pm5 ALL code is publicly reviewed and accessible through our Github. A maintainer individually reviews and tests every single PR regardless of source or creation method. LLM's add no changes to that game. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…uflw you will need to use a script to export the passwords to a CSV file. There are a few available by searching github. We do not endorse any particular method. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…04la @nprofile…nfmd Well, I suppose you haven’t really worked with code agents before or you didn’t spend too much time looking into how we use them. Otherwise you wouldn’t come to the conclusion that we want to encourage bad code. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…04la @nprofile…nfmd Why would we lose your passwords any more likely than if someone sent a bad or even malicious human pull request? Everything gets reviewed and tested, no matter who or what created the code. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…rlx8 you are welcome to file a bug report with Firefox, it is their wording. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…yjmd @nprofile…eaf5 Wait for version 1.9.9. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…gqh9 Yes, but the new version for Firefox hasn’t been approved yet in the store. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…f07u Already are. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC Please accept the permission change to re-enable the extension. More information can be found in the pull request that added the change: https://github.com/keepassxreboot/keepassxc-browser/pull/2570 npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC PSA: The new version of our browser extension now requires additional permissions to "change your privacy-related settings". The new permissions are required so we can set KeePassXC-Browser as your default password manager backend. Unfortunately, there isn't a better name for this permission set. https://cdn.fosstodon.org/media_attachments/files/114/738/913/228/459/958/original/a7b9834078d422a7.png https://cdn.fosstodon.org/media_attachments/files/114/738/913/229/574/990/original/0a7cb2469035b1dd.png npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…uflw For setting the default password manager to be precise. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…vz6q KeePassXC Plus subscription with ten new monthly passwords. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…dm7z Military Grade Encryption is just a dumb marketing term that indicates the encryption algorithm could be FIPS 140 certified (ie, approved for use in military applications). npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…kzvl AES-256 is plenty post-quantum-secure. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…jdc6 Our old website said "industry-standard" and that is already cringe af, so we removed it with the redesign. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…0zd7 Yes, they took it down just now. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC @nprofile…n7w5 Since there isn't any sort of payment involved, I would assume it's just some sort of malicious fork. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC GitHub took down the repository just now. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC FYI: The "Download" link goes through I series of redirects with several obfuscated JavaScript pages in between. I didn't open it in a browser and therefore didn't spend the time to resolve the full chain to the final download, but the fact alone that these obfuscations are there speaks for itself. npub144u4yndstuc5xdpx43yymynpcvveutjq37su9z4xkucgpp5em3aqrn57rx Team KeePassXC 🚨 *Attention!* We were made aware of a fake “KeePassXC Password Manager Pro” repository on GitHub that links to unverified external binary downloads. - There is NO Pro version of KeePassXC! - You get all the “Pro” features with the regular version. Please download KeePassXC only from trusted distribution channels linked on https://keepassxc.org/ ! https://cdn.fosstodon.org/media_attachments/files/114/544/477/107/390/643/original/1397f6046b1c8260.jpeg https://cdn.fosstodon.org/media_attachments/files/114/544/477/335/314/061/original/cf3e38dbda22d621.jpeg