Live data from Hacker News

KeePassXC Debian maintainer has removed all network features

fosstodon.org

271–280 of 367 posts

Re: KeePassXC Debian maintainer has removed all network features

#271

It's crazy the amount of power maintainers hold over someone else's software. This reminds me of the time when Fedora maintainers disabled GLES1 support in Mesa because "nobody should be using it anymore (there are newer OpenGL versions)", disregarding the fact that GLES1 was well and fully maintained upstream, and was and is still the only option on many devices.

Not even comparable. Debian users can choose between the stripped and full version of Keepassxc, unlike the MESA example above.

Re: KeePassXC Debian maintainer has removed all network features

#272
post #57

Earlier quoted context omitted.

Because maintainers have an opinion and explicitly wanted to change the default.

Perhaps, and that's not unreasonable in and of itself. But to do so in such a user-hostile manner? That's a bit over the top. A new minimal package, advertising it, and only then eventually making it the default would have been far, far more effective. If an engineer of mine pulled this on our user-base I'd have them reverting it in a heartbeat regardless of the technical merit. They already failed just in how they e…

Yeah, I agree with you. I'm joking that KeePassXC developers should make parsing .kdbx an optional feature (that's an attack surface by itself for sure!) and see whether Debian package maintainer enable it or not.

Re: KeePassXC Debian maintainer has removed all network features

#274
post #211
post #4

Earlier quoted context omitted.

Debian maintainer, Julian Klode, has a "pointed" opinion: > I'm afraid that's not going to happen. It was a mistake to ship with all plugins built by default. This will be painful for a year as users annoyingly do not read the NEWS files they should be reading but there's little that can be done about that. > It is our responsibility to our users to provide them the most secure option possible as the default. All of…

My favorite part is that this guy works at Canonical.

Yes, had he been a Fedora maintainer working at Red Hat everyone would be applauding him for his bold decision.

Re: KeePassXC Debian maintainer has removed all network features

#275
post #57

Earlier quoted context omitted.

Because maintainers have an opinion and explicitly wanted to change the default.

Perhaps, and that's not unreasonable in and of itself. But to do so in such a user-hostile manner? That's a bit over the top. A new minimal package, advertising it, and only then eventually making it the default would have been far, far more effective. If an engineer of mine pulled this on our user-base I'd have them reverting it in a heartbeat regardless of the technical merit. They already failed just in how they e…

> user-hostile manner

This isn't user hostile.

You know what'd be user hostile? Removing the functionality and not providing the -full package alongside.

Re: KeePassXC Debian maintainer has removed all network features

#276
post #15

Looks like pretty reasonable decision to me - network features and browser integrations are huge potential holes / exploit entry points. And without network-related features and only running the trusted databases, the tool should be impossible to exploit even if exploits are found, which is a very desirable trait for something as important as password manager. Even original maintainer agrees [1]. Remember, the full n…

Indeed. I use Gentoo and one of the best things is being able to easily switch off features in individual packages like this (or across the whole system, like systemd or X11, for example). But what can a Debian user do? If they're going to build one binary and make it the default it should be the most secure version, not the most featureful.

The keepassxc account is being ridiculously sensationalist. Removing ALL features? Lol

Re: KeePassXC Debian maintainer has removed all network features

#277
post #257

It's crazy the amount of power maintainers hold over someone else's software. This reminds me of the time when Fedora maintainers disabled GLES1 support in Mesa because "nobody should be using it anymore (there are newer OpenGL versions)", disregarding the fact that GLES1 was well and fully maintained upstream, and was and is still the only option on many devices.

>power maintainers hold over someone else's software There's some subtle assumptions about ownership in this comment that aren't accurate, insofar as free and open source software is concerned. FOSS software is not "someone else's" software. They may own the trade mark, but by releasing the software under a FOSS licence, they lose the right to control the direction the software may take. I'm free to copy it, edit it,…

That's besides the point. You can do whatever with the software, but it gets muddy when you then release it under the same name as the original. That name may not be trademarked, but it is still not yours to use.

Re: KeePassXC Debian maintainer has removed all network features

#278
post #266
post #261

Earlier quoted context omitted.

So the Debian maintainer complains about the upstream project (which they decided to maintain the package for) bringing "crap" and having "utterly misguided" development? And somehow people say that this is the reasonable person here, basing a major change of a software's featureset on such an opinion? Independent from whether the original change is good or bad, so much of what's wrong with Open Source is people tryi…

what leads you to suspect he's wrong? from the quotes in your comment i suspect it's his choice to use plain language and openly disagree with others. in my experience that's how trustworthy, competent people talk people working together successfully in free software doesn't depend on them having the same values or getting along or wanting the software to do the same thing. it just depends on being clear and open abo…

I guess you missed the bits on Mastodon where the package maintainer simply didn’t bother reaching out to the upstream whatsoever because he was ‘too busy’ and would only do so over a particular IRC setup. That’s not competent or good faith maintenance.

Re: KeePassXC Debian maintainer has removed all network features

#279

Earlier quoted context omitted.

Sorry, why do maintainers owe us anything? They’re typically unpaid or poorly paid and are doing everyone a favour. The code is open source and anyone who doesn’t like their work can easily fork the project. They don’t need to justify anything to us

This isn’t the project maintainer we’re talking about, it’s the Debian package maintainer. Their job is building a working .deb with working software, not randomly messing with it. Users have the right to demand their packages to be trustworthy.

demand? Perhaps if you are unhappy you should ask for a refund. I just can't get my head around this sort of entitlement.

Re: KeePassXC Debian maintainer has removed all network features

#280

Earlier quoted context omitted.

Perhaps, and that's not unreasonable in and of itself. But to do so in such a user-hostile manner? That's a bit over the top. A new minimal package, advertising it, and only then eventually making it the default would have been far, far more effective. If an engineer of mine pulled this on our user-base I'd have them reverting it in a heartbeat regardless of the technical merit. They already failed just in how they e…

> user-hostile manner This isn't user hostile. You know what'd be user hostile? Removing the functionality and not providing the -full package alongside.

It is.

The software has been broken - the UI wasn’t designed with those toggles in mind so now users suddenly have non functioning features presented to the in the UI.

The argument the all users should be keeping up to speed on NEWS - especially in the stable channels this will end up in - to explain why their UX is suddenly broken is not exactly ‘user friendly’.

Post reply on HN