Live data from Hacker News

KeePassXC Debian maintainer has removed all network features

fosstodon.org

161–170 of 367 posts

Re: KeePassXC Debian maintainer has removed all network features

#161

Earlier quoted context omitted.

The justification is absolute rubbish. I The argument is that it reduces attack surface, but compared to what, the alternative to including the yubikey code is not using a yubikey, which reduces security. The alternative to using the browser integration (or the ssh agent) is to use the clipboard, which is likely more code and definitely less vetted code. By the same argument we should remove encryption as well, becau…

>the alternative to including the yubikey code is not using a yubikey, which reduces security. The physics of someone cracking my passphrase and the physics of someone cracking my Yubikey are both in the boil the oceans amount of energy. I'm fine not letting a usb device masquerading as a keyboard have access to my password database. Remember: "When you lose your YubiKey or someone else gets access to it, your databa…

> When you lose your YubiKey or someone else gets access to it, your database is not secure anymore.

You don't store your password on the YubiKey, you use it as a second factor in addition to your password.

Do you know what a YubiKey is when you argue against it?

Re: KeePassXC Debian maintainer has removed all network features

#162

Earlier quoted context omitted.

> My software is a victim of Debian maintainers as well: they chose to remove the default theme from our static site generator, because it was built on top of Bootstrap 3, but Debian only shipped Bootstrap 2 at the time in a global package (they also changed the bootstrap 2 theme to use symlinks to the global version) As a Debian stable devotee, this seems reasonable to me. If I wanted each package to bring along & m…

We ship a copy of bootstrap within our data files. They could just leave it as-is and have it working. Bootstrap is a CSS/JS library, there is no global /usr/lib to be concerned about.

> because it was built on top of Bootstrap 3, but Debian only shipped Bootstrap 2 at the time in a global package

> there is no global /usr/lib to be concerned about

Aside from possibly the path being different, which is of no concern, how can the 2 above sentences reconcile with each other?

Re: KeePassXC Debian maintainer has removed all network features

#163

Meanwhile in Arch land (possibly other distros as well), the fwupd package (which I imagine to be a fairly common package to be installed among the user base) has been silently configured to depend on passim, which spins up an open web server on 0.0.0.0:27500[1] without any(!) explicit user consent whatsover. Passim then uses GnuTLS, which is famous for containing more holes than Swiss cheese [2][3]. Absolutely insan…

Good to know. I think this should probably be it's own post

Re: KeePassXC Debian maintainer has removed all network features

#164

Earlier quoted context omitted.

He removed not only networking but support for yubikey, and autotype. These are all features that are turned off by default.

> and autotype I would go crazy w/o autotype. The way the IT dorks were forced by management to set up 'SSO' via an external provider at work, you have to enter the same information at least 3 times a day. 'SSO' for management means 'sign into each of our tools each single day'. Muh, no work done equals better security!

Usually SSO means that you have to login just once to access all of your accounts. If it requires you to login multiple times a day then something is not configured correctly.

Re: KeePassXC Debian maintainer has removed all network features

#165
post #82

Earlier quoted context omitted.

It's not completely different. They patched stuff out. And I, as an end user, am absolutely fine with that, as a user of vim-nox package etc etc...

But vim-nox is a separate package with a clear name saying that it's got X removed; I don't think this would be nearly as controversial if they'd shipped a keepassxc-nonetwork package.

vim-tiny is installed by default on debian (providing a vim command), and also has X removed.

Re: KeePassXC Debian maintainer has removed all network features

#167

Earlier quoted context omitted.

The justification is absolute rubbish. I The argument is that it reduces attack surface, but compared to what, the alternative to including the yubikey code is not using a yubikey, which reduces security. The alternative to using the browser integration (or the ssh agent) is to use the clipboard, which is likely more code and definitely less vetted code. By the same argument we should remove encryption as well, becau…

>the alternative to including the yubikey code is not using a yubikey, which reduces security. The physics of someone cracking my passphrase and the physics of someone cracking my Yubikey are both in the boil the oceans amount of energy. I'm fine not letting a usb device masquerading as a keyboard have access to my password database. Remember: "When you lose your YubiKey or someone else gets access to it, your databa…

What is the physics of someone sniffing your passphrase with a keylogger?

Re: KeePassXC Debian maintainer has removed all network features

#168

Earlier quoted context omitted.

This. So much this. I don't even understand how browser integrations are not universally thought as a core part of a password manager. With all the phishing that's going along, it's really the last line of defense. Oh and I'm not only talking about elderly relatives and such. Modern phishings are very very well made, and there's one going on to steal Steam accounts that I would have likely fell for (and I consider my…

I'm replying just to +1 this as well. This has saved me multiple times not from phishing attacks but from simple mistakes such as entering a password into a HTTP page when the website supports HTTPS. Often I'm just browsing along and try to get KeepassXC to autofill a password only to be frustrated when it refuses to work. Then the frustration turns to relief when I go into KeepassXC and see that I've entered " https…

It's not like the clipboard is secure either. Any arbitrary app can listen to the clipboard in X11, and while it seems harder in Wayland, I'm not sure if I've ever seen a clipboard permission dialog (my Wayland experience is limited though).

Turning off the browser intergation means that the user may accidentally auto-type into the wrong website. Turning off auto-type means that external applications can see the password.

Re: KeePassXC Debian maintainer has removed all network features

#169
post #165

Earlier quoted context omitted.

But vim-nox is a separate package with a clear name saying that it's got X removed; I don't think this would be nearly as controversial if they'd shipped a keepassxc-nonetwork package.

vim-tiny is installed by default on debian (providing a vim command), and also has X removed.

Okay? Calling it keepassxc-tiny would also be fine. I think it's relevant that `apt install vim` does not give you vim-tiny.

Re: KeePassXC Debian maintainer has removed all network features

#170

Earlier quoted context omitted.

The most secure system is the system with no features! Let's delete everything. #nofeatures #securityonly

Guess this is it. I'm powering everything down for security reasons. To the woods I go to build a cabin.

They made a netflix documentary about the last guy who did that. He wrote a pretty good manifesto.
Post reply on HN