Live data from Hacker News

KeePassXC Debian maintainer has removed all network features

fosstodon.org

1–10 of 367 posts

Re: KeePassXC Debian maintainer has removed all network features

#2
IMHO is a downstream maintainer is going to change a package in a way that doesn't have the intent of the upstream project, it should be published under a different name and that maintainer deal with all bug reports caused by their modified version.

Re: KeePassXC Debian maintainer has removed all network features

#4

For folks interested this issue on GitHub seems to have the latest comments. https://github.com/keepassxreboot/keepassxc/issues/10725

Debian maintainer, Julian Klode, has a "pointed" opinion:

> I'm afraid that's not going to happen. It was a mistake to ship with all plugins built by default. This will be painful for a year as users annoyingly do not read the NEWS files they should be reading but there's little that can be done about that.

> It is our responsibility to our users to provide them the most secure option possible as the default. All of these features are superfluous and do not really belong in a local password database manager, these developments are all utterly misguided.

> Users who need this crap can install the crappy version but obviously this increases the risk of drive-by contributor attacks.

Re: KeePassXC Debian maintainer has removed all network features

#5

IMHO is a downstream maintainer is going to change a package in a way that doesn't have the intent of the upstream project, it should be published under a different name and that maintainer deal with all bug reports caused by their modified version.

not sure why you're commenting without even reading the linked 200 character post?

the maintainer has enabled all plugins (including network stuff) in the keepassxc-full package, the keepassxc package will be just the basics with a much better security posture.

that's obviously completely fine and completely within the remit of a maintainer, the entire complaint is about this being a change.

Re: KeePassXC Debian maintainer has removed all network features

#8

IMHO is a downstream maintainer is going to change a package in a way that doesn't have the intent of the upstream project, it should be published under a different name and that maintainer deal with all bug reports caused by their modified version.

The WITH_XC_NETWORKING build option is off by default so the developers have obviously intended this to be a valid build configuration.

Re: KeePassXC Debian maintainer has removed all network features

#9

IMHO is a downstream maintainer is going to change a package in a way that doesn't have the intent of the upstream project, it should be published under a different name and that maintainer deal with all bug reports caused by their modified version.

not sure why you're commenting without even reading the linked 200 character post? the maintainer has enabled all plugins (including network stuff) in the keepassxc-full package, the keepassxc package will be just the basics with a much better security posture. that's obviously completely fine and completely within the remit of a maintainer, the entire complaint is about this being a change .

As stated in the GitHub thread [1]:

  You fundamentally misunderstand our program when you use the word plugin. These are
  built in features, not plugins. The features can be enabled as desired by the user and
  they come disabled by default. This change to not compile and ship these features in the
  base keepassxc package does nothing besides create angry (or confused) users.
[1] https://github.com/keepassxreboot/keepassxc/issues/10725#iss...

Re: KeePassXC Debian maintainer has removed all network features

#10

IMHO is a downstream maintainer is going to change a package in a way that doesn't have the intent of the upstream project, it should be published under a different name and that maintainer deal with all bug reports caused by their modified version.

Either that or it should indicate to the end user that it's an unsupported package. Maybe showing up as KeePassXC-Debian or KeePassXC-Unsupported and have the developer's contact details (website etc) removed from About and replaced with the Debian details for support.

A downstream maintainer making small changes to fit within the OS that doesn't meaningfully affect the app is fine. A downstream maintainer modifying an app and removing core functionality so the upstream dev gets a ton of grief is not.

Post reply on HN