Hacker News new | ask | show | jobs
by pfg 4792 days ago
I found the following info on the KeePass homepage[0]:

>For both algorithms [AES/Twofish], a 128-bit initialization vector (IV) is generated randomly each time you save the database.

>This allows multiple databases to be encrypted using the same key without observable patterns being revealed.

I'm no crypto expert, but I think this also covers multiple versions of your kdb file.

[0]: http://keepass.info/help/base/security.html#secencrypt