Keepass2Android

Get it on Google Play

 

Join the Beta tester community to get the latest preview releases directly from Google Play:

https://plus.google.com/communities/107293657110547776032

Don't forget to opt-in in the beta test then:

https://play.google.com/apps/testing/keepass2android.keepass2android


 

 Keepass2Android is an open source password manager application for Android. It reads and writes .kdbx-files, the database format used by the popular KeePass 2.x Password Safe for Windows and other desktop operating systems.

The user interface is based on Keepassdroid (by Brian Pellin), ported from Java to Mono for Android. The backend uses the original KeePass libraries to handle file access to ensure file format compatibility.

Main features of the App are

  • read/write support for .kdbx (KeePass 2.x) files
  • integrates with nearly every Android browser (see below)
  • QuickUnlock: Unlock your database once with your full password, re-open it by typing just a few characters (see below)
  • Integrated Soft-Keyboard: Switch to this keyboard for entering user credentials. This shields you from clipboard based password sniffers (see below)
  • support for editing entries including additional string fields, file attachments, tags etc.
  • read/write files on the web directly (supports FTP and WebDAV). You can use "Keepass2Android Offline" if you don't need this feature.
  • search dialog with all search options from KeePass 2.x.

HELP! Please contribute by translating Keepass2Android on http://crowdin.net/project/keepass2android! 

DO YOU LIKE Keepass2Android? If you consider making a donation, please visit http://philipp.crocoll.net/donate.php

Browser integration

If you need to lookup a password for a webpage, go to Menu/Share... and select Keepass2Android. This will

  •  
    • bring up a screen to load/unlock a database if no database is loaded and unlocked
    • go to the Search Results screen displaying all entries for the currently visited URL
    • - or -
    • directly offer the Copy Username/Password notifications if exactly one entry matches the currently visited URL

QuickUnlock

You should protect your password database with a strong (i.e. random and LONG) password including upper and lower case as well as numbers and special characters. Typing such a password on a mobile phone every time you unlock your database is time-consuming and error-prone. The KP2A solution is QuickUnlock:

  •  
    • Use a strong password for your database
    • Load your database and type the strong password once. Enable QuickUnlock.
    • The application is locked after the time specified in the settings
    • If you want to re-open your database, you can type just a few characters (by default, the last 3 characters of your password) to unlock quickly and easily!
    • If the wrong QuickUnlock key is entered, the database is locked and the full password is required to re-open.

Is this safe? First: it allows you to use a really strong password, this increases safety in case someone gets your database file. Second: If you loose your phone and someone tries to open the password database, the attacker has exactly one chance to make use of QuickUnlock. When using 3 characters and assuming 70 characters in the set of possible characters, the attacker has a 0.0003% chance of opening the file. If this sounds still too much for you, choose 4 or more characters in the settings.

QuickUnlock requires an icon in the notification area. This is because Android would kill Keepass2Android too often without this icon. The icon is shown by the QuickUnlockForgroundService. Note that this service does not do ANY computations or keep the screen on, which means that the battery lifetime is not affected by this feature.

Keepass2Android Keyboard

 A German research team has demonstrated that most clipboard-based access of credentials as used by most Android password managers is not safe[1]: Every app on your phone can register for changes of the clipboard and thus be notified when you copy your passwords from the password manager to your clipboard. In order to protect against this kind of attack, you should use the Keepass2Android keyboard: When you select an entry, a notification will appear in the notification bar. This notification lets you easily switch to the KP2A keyboard. This is a simple keyboard with an important key: click the Keepass2Android symbol to "type" your credentials. Click the keyboard key to switch back to your favorite keyboard.

[1]: https://www2.dcsec.uni-hannover.de/files/p170.pdf

Last edited Jan 2 at 4:01 AM by PhilippC, version 21