google-authenticator-exporter VS KeeFarce

Compare google-authenticator-exporter vs KeeFarce and see what are their differences.

google-authenticator-exporter

Get the TOTP secrets exported by Google Authenticator (by krissrex)

KeeFarce

Extracts passwords from a KeePass 2.x database, directly from memory. (by denandz)
SurveyJS - Open-Source JSON Form Builder to Create Dynamic Forms Right in Your App
With SurveyJS form UI libraries, you can build and style forms in a fully-integrated drag & drop form builder, render them in your JS app, and store form submission data in any backend, inc. PHP, ASP.NET Core, and Node.js.
surveyjs.io
featured
InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
google-authenticator-exporter KeeFarce
5 7
364 989
- -
2.2 10.0
5 months ago over 8 years ago
JavaScript C++
MIT License BSD 3-clause "New" or "Revised" License
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

google-authenticator-exporter

Posts with mentions or reviews of google-authenticator-exporter. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-06-03.

KeeFarce

Posts with mentions or reviews of KeeFarce. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-10-25.
  • KeePass Sicherheitslücke ist ein großes Problem!
    1 project | /r/de_EDV | 3 Feb 2023
  • Diskussion um Schwachstelle in KeePass
    1 project | /r/de_EDV | 2 Feb 2023
  • Open source security camera/CCTV apps?
    1 project | /r/androidapps | 2 Nov 2022
    inb4 KeeFarce. It's 7 years old and only works in specific situations.
  • How the Clipboard Works
    3 projects | news.ycombinator.com | 25 Oct 2022
    > isn't securing this one major IMO attack vector an improvement over not doing anything about it

    Unfortunately securing this attack vector is costly - in the sense of annoying the user with prompts and access grants.

    This is why even on mobile as you noticed, only browsers require user confirmation before allowing webpages access to the clipboard.

    You could maybe do something in between, like not allowing clipboard access to processes which don't have a foreground window visible to the user.

    But in practice, this attack vector is not exploited. If you are targeted, it's much more likely that a specific attack against the password manager is used, since it will extract ALL passwords, and not need to wait for one to show up:

    > KeeFarce allows for the extraction of KeePass 2.x password database information from memory. The cleartext information, including usernames, passwords, notes and url's are dumped into a CSV file in %AppData%

    https://github.com/denandz/KeeFarce

  • Google Authenticator's first update in years tweaks how you access security codes
    6 projects | /r/Android | 3 Jun 2022
    I'm not sure how that defeats the purpose of 2FA. If anything, critical things like 2FA codes being stored locally on your device are more dangerous. Just because it's online doesn't mean it is suddenly insecure. By your logic, password managers being online and cross-platform are also somehow insecure, yet everybody expects those as the most basic features. I don't want to get into a long-winded, pointless "everything on the internet is insecure!" discussion, but I just don't see your point.
  • Why I don't hear about malware targetting password managers?
    7 projects | /r/hacking | 29 May 2022

What are some alternatives?

When comparing google-authenticator-exporter and KeeFarce you can also consider the following projects:

extract_otp_secrets - Extract one time password (OTP) secrets from QR codes exported by two-factor authentication (2FA) apps such as "Google Authenticator". The exported QR codes from authentication apps can be captured by camera, read from images, or read from text files. The secrets can be exported to JSON or CSV, or printed as QR codes to console.

KeeThief - Methods for attacking KeePass 2.X databases, including extracting of encryption key material from memory.

AuthenticatorPro - 📱 Two-Factor Authentication (2FA) client for Android + Wear OS

LaZagne - Credentials recovery project

pyotp - Python One-Time Password Library

KeePassHax - A tool to extract a KeePass master password from memory

speakeasy - **NOT MAINTAINED** Two-factor authentication for Node.js. One-time passcode generator (HOTP/TOTP) with support for Google Authenticator.

1PasswordSuite - Utilities to extract secrets from 1Password

andOTP - [Unmaintained] Open source two-factor authentication for Android

SharpClipboard - C# Clipboard Monitor

authelia - The Single Sign-On Multi-Factor portal for web apps

Aegis - A free, secure and open source app for Android to manage your 2-step verification tokens.