Skip to content

HIBP excluded entries are still included when scanning #59

@koitsu

Description

@koitsu

Scenario

  • A KeePass group has 10 entries in it
  • Of those 10 entries, 4 are marked "Excluded" (for HIBP checks)
  • Select all 10 entries in KeePass
  • Right-click and select "Have I Been Pwned? -> Check"
  • All 10 entries are checked (rather than just 6)
    • I ASSUME all 10 are checked; the progress bar size etc. seems to imply all 10 are checked, given the interval delay between all 10

Conclusion

It seems the Excluded feature is only considered when checking the entire password database (via Tools -> HIBP Offline Check... -> Check All Passwords), and not through the right-click context menu.

I can see the use for doing HIBP checks for entries which are marked Excluded, but not as a default; a user expects an excluded entry to truly be excluded.

Recommended change

In the right-click context menu, make a new option called "Check (forced)", which will check selected entries regardless of their Excluded status. However, "Check" should exclude entries as described above.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions