The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Is Uploading Keepass to Dropbox Safe?

    Discussion in 'Windows OS and Software' started by Drew1, Jun 8, 2017.

  1. Drew1

    Drew1 Notebook Virtuoso

    Reputations:
    25
    Messages:
    2,076
    Likes Received:
    56
    Trophy Points:
    66
    As many of you know, keepass is a program where it configures and stores passwords for you. I have it on my laptop and also a copy of it on an external hard drive. So my backup is the external hard drive.


    However, I do not have a backup copy of it online. Is uploading keepass to dropbox a good idea? The thing is you should always have an online backup right for keepass? And if so, well shouldn't it always be on an online storage site like dropbox, google drive or icloud?


    Thus the only thing you would really need to remember are your keepass password and dropbox? My thoughts are well if you do this, well if anything happens to your laptop, external hard drive or anything else, well you can open your keepass file from dropbox. Thoughts on this? I mean isn't having an online backup of keepass pretty much mandatory? Thanks all.
     
  2. Drew1

    Drew1 Notebook Virtuoso

    Reputations:
    25
    Messages:
    2,076
    Likes Received:
    56
    Trophy Points:
    66
    anyone who uses keepass can tell me about this?
     
  3. StormJumper

    StormJumper Notebook Virtuoso

    Reputations:
    579
    Messages:
    3,537
    Likes Received:
    488
    Trophy Points:
    151
    As long as your keepass is Password protected it should be safe uploading to dropbox. If you don't do that then well that is your choice to do that.
     
  4. TreeTops Ranch

    TreeTops Ranch Notebook Deity

    Reputations:
    330
    Messages:
    904
    Likes Received:
    124
    Trophy Points:
    56
    Yes, like StormJumper says, it should be OK to do what you want. The Keepass database of passwords is encrypted. Make sure you have a strong password.
     
  5. Drew1

    Drew1 Notebook Virtuoso

    Reputations:
    25
    Messages:
    2,076
    Likes Received:
    56
    Trophy Points:
    66
    Someone told me in a forum that i should use axcrypt to encrypt it before i put it on dropbox. Do you think that is unnecessary assuming my master password for keepass is pretty strong?

    Thanks.
     
  6. TreeTops Ranch

    TreeTops Ranch Notebook Deity

    Reputations:
    330
    Messages:
    904
    Likes Received:
    124
    Trophy Points:
    56
  7. HTWingNut

    HTWingNut Potato

    Reputations:
    21,580
    Messages:
    35,370
    Likes Received:
    9,877
    Trophy Points:
    931
    I use dropbox with keepass with a (very) strong password for years.
     
  8. StormJumper

    StormJumper Notebook Virtuoso

    Reputations:
    579
    Messages:
    3,537
    Likes Received:
    488
    Trophy Points:
    151
    In this day and age your Login/Password is a goldmine if you fail to use a good password for your keepass database before you upload to DropBox this failure is the user fault not Keepass problem. I use a Master password for Keepass and that provides security even if someone gets that file they will take a lifetime to decrypt it. Make sure the Master Password is something you can remember and not forget otherwise the person lockout would be you the User.
     
  9. yutzybrian

    yutzybrian Notebook Consultant

    Reputations:
    50
    Messages:
    118
    Likes Received:
    100
    Trophy Points:
    56
    I wouldn't choose to use Dropbox myself, but that's because of the negative stigma around them from multiple security breaches.
     
  10. StormJumper

    StormJumper Notebook Virtuoso

    Reputations:
    579
    Messages:
    3,537
    Likes Received:
    488
    Trophy Points:
    151
    If you don't encrypt your keepass database before uploading it - that is nothing anyone else can do to help with that choice one makes. And you think the problem is only just DropBox from what your describing befuddles the mind.
     
  11. yutzybrian

    yutzybrian Notebook Consultant

    Reputations:
    50
    Messages:
    118
    Likes Received:
    100
    Trophy Points:
    56
    The Keepass database is encrypted anytime it is on disk, not sure how you think you could upload it anywhere unencrypted. My point was that I wouldn't put it on the most highly targeted file storage site.
     
  12. StormJumper

    StormJumper Notebook Virtuoso

    Reputations:
    579
    Messages:
    3,537
    Likes Received:
    488
    Trophy Points:
    151
    All sites a targeted already one site isn't more then the other-that's the point I made. It's a over simplification of the problem of storage sites being hacked. And since those hacked sites aren't going to say oh by the way we got hacked sorry your data was stolen since we didn't encrypt our system. That isn't going to happen-it's not in their best interest to say that publicly to users of their system. Only time they admit is when the hackers or insider tells the Press or Online content then they will admit it happened.
     
  13. Drew1

    Drew1 Notebook Virtuoso

    Reputations:
    25
    Messages:
    2,076
    Likes Received:
    56
    Trophy Points:
    66
    Hey there bit confused with this. So if you don't encrypt keepass before uploading it to dropbox, they still need to know your master keepass in order to open it right? So im confused with this.
     
  14. yutzybrian

    yutzybrian Notebook Consultant

    Reputations:
    50
    Messages:
    118
    Likes Received:
    100
    Trophy Points:
    56
    Your KeePass database is always encrypted on disk, and therefore anywhere you upload it as well. The only place it will ever be decrypted is within the memory of the computer you have opened it and entered the master password for.

    So yes, they would still need your master password to open it from dropbox.
     
  15. StormJumper

    StormJumper Notebook Virtuoso

    Reputations:
    579
    Messages:
    3,537
    Likes Received:
    488
    Trophy Points:
    151
    It probably is but unless you password protected it will not be protected. Encryption only works if you password protect the keepass data otherwise it is wide open should anyone want to read and edit your passwords. AFAIK it doesn't password protect it be default you must password encrypt it-this is what I remember when I first started using it.
     
  16. yutzybrian

    yutzybrian Notebook Consultant

    Reputations:
    50
    Messages:
    118
    Likes Received:
    100
    Trophy Points:
    56
    Just attempted to create a new database with a blank password and saw it actually does let you, didn't think it would. Kind of stupid in my opinion, may as well use Excel.
     
  17. HTWingNut

    HTWingNut Potato

    Reputations:
    21,580
    Messages:
    35,370
    Likes Received:
    9,877
    Trophy Points:
    931
    You need a password if you want to encrypt something. You can't encrypt something unless you have a key to unlock it. Not sure why it's included, but it is an option if users want it.
     
  18. yutzybrian

    yutzybrian Notebook Consultant

    Reputations:
    50
    Messages:
    118
    Likes Received:
    100
    Trophy Points:
    56
    Yea I was previously under the assumption that KeePass wouldn't let you create a database without providing one of the three options (pass, key file, or windows login) as an encryption method. I guess as usual, stupid users get what stupid user want.