Live data from Hacker News

KeePassXC Debian maintainer has removed all network features

fosstodon.org

91–100 of 367 posts

Re: KeePassXC Debian maintainer has removed all network features

#91
post #56

Earlier quoted context omitted.

He removed not only networking but support for yubikey, and autotype. These are all features that are turned off by default.

They are not "features that are turned off by default" but plugins that are now actually plugins and not built-in features that are turned off. Why on earth would they include plugins that aren't plugged in as a default? How anyone could see a smaller attack surface as a bad thing on HN baffles the mind. Could he have made a -minimal version? Sure, but the default version should be the clean, secure, without plugins…

Compile-time flags are by definition not plugins. All optional features were removed indiscriminately.

Re: KeePassXC Debian maintainer has removed all network features

#92
post #52

Earlier quoted context omitted.

The role of a maintainer is more than copying and pasting upstream. They are allowed to exercise their judgement in what they believe is appropriate for end users of a distribution. In this case, there does seem to be reasonable security justifications for it, and an alternative is provided.

If both upstream and a significant portion of users strongly disagree with a maintainer's judgement, then how is their role as maintainer justified? It's KeePassXC's job to secure the software and produce features that fulfill users' needs as they see fit. Julian's role as maintainer may intersect with that to a limited extent , in deciding on what kind of defaults best fit the rest of the OS. But, in this case, the…

Sorry, why do maintainers owe us anything? They’re typically unpaid or poorly paid and are doing everyone a favour. The code is open source and anyone who doesn’t like their work can easily fork the project. They don’t need to justify anything to us

Re: KeePassXC Debian maintainer has removed all network features

#93

I think it's correct for the default package to be the safest-possible one. It's a password manager not an mp3 player. Yes it's annoying that an existing behavior will change, but that problem is not more impportant than the problem of what should be the default behavior of a security app. keepassxc should have always been like that by default and all the added conveniences that also add bug-surface and attack-surfac…

A password manager with a built-in MP3 player? That's my next project.

Re: KeePassXC Debian maintainer has removed all network features

#94

Earlier quoted context omitted.

Thinking browser or other local integration is not as dangerous as network features is nonsensical. All of the disabled features are expendable. I never used any even while they were in there. Yet I do use keepassxc all day every day for the one job it actually does exist to do. Convenience and necessity are two different things. You want conveninece, and you're not wrong to want it, but you don't need it, and your w…

Absolute security means you can't do anything . Too much security friction can easily lead to *much more insecure* workarounds.

Somehow, I have been using the same app without any of those features. So, the idea that the app is not functional or useful without them is bullshit.

As for friction leading indirectly to less security through user behavior... how many clicks and how many seconds is it to install the full version? So, yet more bullshit.

Re: KeePassXC Debian maintainer has removed all network features

#95
post #24

Earlier quoted context omitted.

They disabled all plugins, not just those that may access networks. This is not good, it's nonsensical.

Thinking browser or other local integration is not as dangerous as network features is nonsensical. All of the disabled features are expendable. I never used any even while they were in there. Yet I do use keepassxc all day every day for the one job it actually does exist to do. Convenience and necessity are two different things. You want conveninece, and you're not wrong to want it, but you don't need it, and your w…

[flagged]

Re: KeePassXC Debian maintainer has removed all network features

#96

Earlier quoted context omitted.

If both upstream and a significant portion of users strongly disagree with a maintainer's judgement, then how is their role as maintainer justified? It's KeePassXC's job to secure the software and produce features that fulfill users' needs as they see fit. Julian's role as maintainer may intersect with that to a limited extent , in deciding on what kind of defaults best fit the rest of the OS. But, in this case, the…

Sorry, why do maintainers owe us anything? They’re typically unpaid or poorly paid and are doing everyone a favour. The code is open source and anyone who doesn’t like their work can easily fork the project. They don’t need to justify anything to us

This isn’t the project maintainer we’re talking about, it’s the Debian package maintainer. Their job is building a working .deb with working software, not randomly messing with it. Users have the right to demand their packages to be trustworthy.

Re: KeePassXC Debian maintainer has removed all network features

#97
post #52

Earlier quoted context omitted.

The role of a maintainer is more than copying and pasting upstream. They are allowed to exercise their judgement in what they believe is appropriate for end users of a distribution. In this case, there does seem to be reasonable security justifications for it, and an alternative is provided.

If both upstream and a significant portion of users strongly disagree with a maintainer's judgement, then how is their role as maintainer justified? It's KeePassXC's job to secure the software and produce features that fulfill users' needs as they see fit. Julian's role as maintainer may intersect with that to a limited extent , in deciding on what kind of defaults best fit the rest of the OS. But, in this case, the…

> If both upstream and a significant portion of users strongly disagree with a maintainer's judgement, then how is their role as maintainer justified?

By their making the decision they think is best and that agrees with the philosophy of the distribution they're maintaining the package for? I'm glad they don't have to justify their existences to upstream and every "significant portion[...] of users."

> It's KeePassXC's job to secure the software and produce features that fulfill users' needs as they see fit.

You don't control free software after you've licensed and distributed it that way. The entire point of the concept is to make calls like this about anti-features. KeePassXC can feel free to comment on it, like anyone else. They can demand that Debian make available the modified sources. They can revoke any license to the use of trademarks. That's it.

If users only want to deal with KeePassXC, they can compile it themselves or use a portable version. If KeePassXC wants to deal with Debian users directly, they can host a package repository for their canonical version.

Re: KeePassXC Debian maintainer has removed all network features

#99
I have already been using bubblewrap[1] to isolate KeePassXC from the network and more (the only access it has is to its own private directory and a hardened Wayland socket[2]). I wouldn't recommend relying on devs or maintainers to do application isolation work for you.

[1] https://github.com/containers/bubblewrap>

[2] https://git.sr.ht/~whynothugo/way-secure>

Re: KeePassXC Debian maintainer has removed all network features

#100
post #81
post #72

Earlier quoted context omitted.

I think you'd have to actually ask the users about that. Not make assumptions based on some loud people on a Mastodon thread. What the user is given here is a choice.

But they already had a choice, since the removed options were disabled by default. This really just breaks core functionality that exists and is expected by real users, under the guise of unnamed security risks...theres plenty of disabled options in Linux that are "potential" risks, so its a silly choice.

Hyperbole!

$ apt install keepassx

$ apt install keepassx-full

Choice made.

Post reply on HN