Home > Enterprise Desktop Tips > > Freeware tool for password tracking and storage
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Freeware tool for password tracking and storage


Serdar Yegulalp, Contributor
07.12.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Keeping track of one password is easy enough, but, overall, password management can be a problematic task. It's hard to remember many of them, and writing them down would defeat the purpose of keeping passwords secret in the first place.

KeePass Password Safe is a new open-source/freeware project that runs on all 32-bit versions of Windows. It's designed to help you manage and protect all kinds of passwords. The source code is freely available, so it can be inspected by security-conscious programmers (who can, in turn, suggest improvements).

You can store any number of passwords in the program, which can either be typed in by hand or imported from a variety of sources, including CSV (comma-separated value) files. The passwords are then stored in a database encrypted using the very strong Advanced Encryption Standard (AES) or Twofish algorithms to keep them from being compromised. Even when the program is running, the passwords are encrypted in memory, so caching the program's memory to disk will not compromise security.

KeePass typically works by using a master password or passphrase to unlock the database. It's also possible to use a physical key disk, such as a removable USB "pen" drive or a floppy disk, as the database key. The two approaches can also be combined for even greater security. The passwords themselves can be organized and presented according to many different sort/search criteria, grouped together or arranged hierarchically. Password lists can be exported (only if you must!), transferred between instances of the program or generated on demand. If you've ever needed to machine generate a whole list of passwords on demand for new installations in an organization, this is one quick way to do it.

One of KeePass' best features is that it can be used to automatically fill in a password field (i.e. in a Web page form) without any retyping. The password itself doesn't even have to be exposed. The program also has a plug-in architecture that makes it possible to expand on the program's basic functionality, and a few such plug-ins have already been written (i.e., XML importer). The entire project is open source, which keeps it from being compromised in turn.

The most recent version of the program is 1.0, with new revisions coming regularly (about once a month). The authors have also created multiple language resource files for the program (including Japanese, Polish, Russian and Hebrew).

About the author: Serdar Yegulalp is the editor of the Windows 2000 Power Users Newsletter. Check it out for the latest advice and musings on the world of Windows network administrators -- and please share your thoughts as well!


More information from SearchWindowsSecurity.com

  • Tip: Avoid these Windows password management myths
  • Tip: Get 25 password hardening tips in 25 minutes
  • Tip: Find out how easily passwords can be cracked


  • Rate this Tip
    To rate tips, you must be a member of SearchEnterpriseDesktop.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Securing Windows legacy operating systems
    Run legacy applications with Windows Vista security
    How to Bypass BIOS Passwords
    Security concerns of unattended, automatic installations
    How 'limited' malcode pulled off the year's biggest attack
    Taking over the domain
    How to get an attacker out of your network
    Checklists: Harden access control settings
    Manual vs. automated patch tracking
    Protect desktop files and folders from inside snoops
    Keeping remote PCs patched

    Windows passwords and permissions management
    Build secure computer password policies
    Remote user security checklist
    Reduce resistance to creating strong computer passwords
    Unauthenticated vs. authenticated security testing
    Step 1: Know your hardware
    Step 2: Configure the drives
    Step 4: Start the BitLocker encryption process
    Password security FAQs
    Step 3: Edit the local policy
    Top client security tips of 2006

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    drive-by download  (SearchEnterpriseDesktop.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
    HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts