Home > Windows Security Tips > > Freeware tool for password tracking and storage
Windows Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Freeware tool for password tracking and storage


Serdar Yegulalp, Contributor
07.12.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Keeping track of one password is easy enough, but, overall, password management can be a problematic task. It's hard to remember many of them, and writing them down would defeat the purpose of keeping passwords secret in the first place.

KeePass Password Safe is a new open-source/freeware project that runs on all 32-bit versions of Windows. It's designed to help you manage and protect all kinds of passwords. The source code is freely available, so it can be inspected by security-conscious programmers (who can, in turn, suggest improvements).

You can store any number of passwords in the program, which can either be typed in by hand or imported from a variety of sources, including CSV (comma-separated value) files. The passwords are then stored in a database encrypted using the very strong Advanced Encryption Standard (AES) or Twofish algorithms to keep them from being compromised. Even when the program is running, the passwords are encrypted in memory, so caching the program's memory to disk will not compromise security.

KeePass typically works by using a master password or passphrase to unlock the database. It's also possible to use a physical key disk, such as a removable USB "pen" drive or a floppy disk, as the database key. The two approaches can also be combined for even greater security. The passwords themselves can be organized and presented according to many different sort/search criteria, grouped together or arranged hierarchically. Password lists can be exported (only if you must!), transferred between instances of the program or generated on demand. If you've ever needed to machine generate a whole list of passwords on demand for new installations in an organization, this is one quick way to do it.

One of KeePass' best features is that it can be used to automatically fill in a password field (i.e. in a Web page form) without any retyping. The password itself doesn't even have to be exposed. The program also has a plug-in architecture that makes it possible to expand on the program's basic functionality, and a few such plug-ins have already been written (i.e., XML importer). The entire project is open source, which keeps it from being compromised in turn.

The most recent version of the program is 1.0, with new revisions coming regularly (about once a month). The authors have also created multiple language resource files for the program (including Japanese, Polish, Russian and Hebrew).

About the author: Serdar Yegulalp is the editor of the Windows 2000 Power Users Newsletter. Check it out for the latest advice and musings on the world of Windows network administrators -- and please share your thoughts as well!


More information from SearchWindowsSecurity.com

  • Tip: Avoid these Windows password management myths
  • Tip: Get 25 password hardening tips in 25 minutes
  • Tip: Find out how easily passwords can be cracked


  • Rate this Tip
    To rate tips, you must be a member of SearchWindowsSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Authentication
    Locked out of Windows 2000 computer
    Reduce resistance to creating strong computer passwords
    Looking ahead to life without passwords
    Accessing a Windows 2000 Pro without the password
    Accessing forgotten passwords
    HijackThis
    Default passwords for Windows 2000 and Windows XP
    How to Bypass BIOS Passwords
    Laptop security solutions for Windows users
    Taking over the domain
    Authentication Research

    Authentication
    Reduce resistance to creating strong computer passwords
    Looking ahead to life without passwords
    Setting 'log-on-to machines' in Active Directory
    Hacking other machines
    Taking over the domain
    Managing passwords and passphrases
    Offline NT Password and Registry Editor
    Ultimate Boot CD
    Login Recovery
    John the Ripper
    Authentication Research

    Authentication
    Correct improperly assigned user rights in Windows XP
    How do I track file access in Windows folders?
    Password security in Windows XP Professional
    Cool things about security, nothing about Britney Spears
    Sharing files and folders in Windows XP
    Reduce resistance to creating strong computer passwords
    Crack the admin password in Windows XP
    Looking ahead to life without passwords
    Learning center: Remote access authentication
    Troubleshooting your Windows-based VPN
    Authentication Research

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT DownloadsBlogs
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts