An engadget story has the following to say about KeePass2 and developer Dominik Reichl:
Think it's bad when companies take their time fixing security vulnerabilities? Imagine what happens when they avoid fixing those holes in the name of a little cash. KeePass 2 developer Dominik Reichl has declined to patch a flaw in the password manager's update check as the "indirect costs" of the upgrade (which would encrypt web traffic) are too high -- namely, it'd lose ad revenue. Yes, the implication is that profit is more important than protecting users.
(Score: 2) by Techwolf on Tuesday June 07 2016, @02:11AM
There are several different flavors of keepass. For desktop, there is keepass (mono code), keepassX (Linux code), and for what I use for Android, keepass2android. https://play.google.com/store/apps/details?id=keepass2android.keepass2android&hl=en [google.com] is open source , ad free, is more secure and has no commercial interests. http://keepass2android.codeplex.com/ [codeplex.com]