I use KeePass (currently version 2.40). The author does claim to use "in-memory protection" of secrets while the program is running, but apparently it is not thorough enough. However I would need to have malware running on my machine (or give physical access) to exfiltrate the in-memory passwords right?
Comments
I use KeePass (currently version 2.40). The author does claim to use "in-memory protection" of secrets while the program is running, but apparently it is not thorough enough. However I would need to have malware running on my machine (or give physical access) to exfiltrate the in-memory passwords right?
Correct. Also if a malware is running it can do better then just steal your manager's password. So I'd say you're OK with only that "bug".