Live data from Hacker News

KeePassXC Debian maintainer has removed all network features

fosstodon.org

21–30 of 367 posts

Re: KeePassXC Debian maintainer has removed all network features

#21
post #4

Earlier quoted context omitted.

Debian maintainer, Julian Klode, has a "pointed" opinion: > I'm afraid that's not going to happen. It was a mistake to ship with all plugins built by default. This will be painful for a year as users annoyingly do not read the NEWS files they should be reading but there's little that can be done about that. > It is our responsibility to our users to provide them the most secure option possible as the default. All of…

[flagged]

Or maybe just fork the project instead and let users who want these features use the package the way the authors intended.

There are multiple KeePass implementations. The people using this one are doing so because they want its features.

Re: KeePassXC Debian maintainer has removed all network features

#22
post #13

Earlier quoted context omitted.

not sure why you're commenting without even reading the linked 200 character post? the maintainer has enabled all plugins (including network stuff) in the keepassxc-full package, the keepassxc package will be just the basics with a much better security posture. that's obviously completely fine and completely within the remit of a maintainer, the entire complaint is about this being a change .

But that's not what they disagree with. They are saying you shouldn't have a package called "keepassxc" if it is missing a ton of features from upstream KeepassXC. You should name it something different instead. So you shouldn't have "keepassxc" and "keepassxc-full". Instead you should have "keepassxc" and "keepassxc-minimal".

But it’s a valid build configuration option provided by upstream. Not sure I follow this line of reasoning.

Re: KeePassXC Debian maintainer has removed all network features

#23
post #8

IMHO is a downstream maintainer is going to change a package in a way that doesn't have the intent of the upstream project, it should be published under a different name and that maintainer deal with all bug reports caused by their modified version.

The WITH_XC_NETWORKING build option is off by default so the developers have obviously intended this to be a valid build configuration.

Sure, but that doesn't change the fact that a point release suddenly broke everyone's workflows and is causing maintenance headaches. I don't think the technical minutia of how exactly things were broken is the issue.

If Debian shipped a Linux kernel point release that disabled networking I think people would be similarly upset, even though it's also just a build option and intended to be a valid build configuration (and would even more secure!)

Re: KeePassXC Debian maintainer has removed all network features

#25
post #6

[flagged]

The most secure system is the system with no features! Let's delete everything. #nofeatures #securityonly

Guess this is it. I'm powering everything down for security reasons. To the woods I go to build a cabin.

Re: KeePassXC Debian maintainer has removed all network features

#26
post #19

Earlier quoted context omitted.

[flagged]

They removed other non-networking features too. E.g. even autotype was removed. At that point why not just store your passwords in an encrypted notes app?

Just use https://www.passwordstore.org

Re: KeePassXC Debian maintainer has removed all network features

#27
Gutting the functionality that upstream has built into a piece of software and then publishing it under the same name is dubious at best. If they want to go this direction they should publish as a fork under a different name so upstream doesn't get constantly barraged by complaints of users having issues.

This reminds me of the time years ago when the Debian maintainer of Chromium decided to unilaterally disable the ability to install extensions. Thankfully, more pragmatic minded people prevailed and the patch was reverted.

This also reminds me of a time many many many years ago when Debian removed the kernel interface that provided the ability to load binary firmware into network cards and broke networking for me.

Re: KeePassXC Debian maintainer has removed all network features

#28
post #6

[flagged]

The most secure system is the system with no features! Let's delete everything. #nofeatures #securityonly

Nothing is deleted. Just the default options are now used, as intended and announced upstream.

How should a debian openssh be called, with custom patches to integrate systemd logging, enabling all old and insecure cyphers? Or a debian openssl with all legacy cyphers enabled?

Re: KeePassXC Debian maintainer has removed all network features

#29
post #15

Looks like pretty reasonable decision to me - network features and browser integrations are huge potential holes / exploit entry points. And without network-related features and only running the trusted databases, the tool should be impossible to exploit even if exploits are found, which is a very desirable trait for something as important as password manager. Even original maintainer agrees [1]. Remember, the full n…

There's one way in which browser integration improves security vs not using it, which is that the browser extension checks the page URL before filling in the credentials, while the approach of manually copy-pasting credentials is vulnerable to typo- and homoglyph-phishing.

Re: KeePassXC Debian maintainer has removed all network features

#30
post #15

Looks like pretty reasonable decision to me - network features and browser integrations are huge potential holes / exploit entry points. And without network-related features and only running the trusted databases, the tool should be impossible to exploit even if exploits are found, which is a very desirable trait for something as important as password manager. Even original maintainer agrees [1]. Remember, the full n…

Using the term crappy made me immediately lose respect for julian-klode.
Post reply on HN