Live data from Hacker News

KeePassXC Debian maintainer has removed all network features

fosstodon.org

101–110 of 367 posts

Re: KeePassXC Debian maintainer has removed all network features

#101
post #72

Earlier quoted context omitted.

I think you'd have to actually ask the users about that. Not make assumptions based on some loud people on a Mastodon thread. What the user is given here is a choice.

Users should be asked if they actually wanted the features in the existing package after all? Why shouldn't users have been asked before changing the existing package? I'm one of those users. If I'm loud, does that mean my opinion doesn't count anymore?

It never counted. You can suggest or advise, but you never had the power to tell Debian what to do. Being loud will not change that, no. You'll have to resort to persuasion.

Re: KeePassXC Debian maintainer has removed all network features

#102
post #93

I think it's correct for the default package to be the safest-possible one. It's a password manager not an mp3 player. Yes it's annoying that an existing behavior will change, but that problem is not more impportant than the problem of what should be the default behavior of a security app. keepassxc should have always been like that by default and all the added conveniences that also add bug-surface and attack-surfac…

A password manager with a built-in MP3 player? That's my next project.

The songs could tell you where to find the post-it note within your record library. Let the hackers gain access to your google drive AND decrypt the db. :)

Re: KeePassXC Debian maintainer has removed all network features

#104

Gutting the functionality that upstream has built into a piece of software and then publishing it under the same name is dubious at best. If they want to go this direction they should publish as a fork under a different name so upstream doesn't get constantly barraged by complaints of users having issues. This reminds me of the time years ago when the Debian maintainer of Chromium decided to unilaterally disable the…

IF apple said "hey we edited your app because we think its more secure"...

People would have torches and pitchforks out.

But a deb maintainer does it and there is debate?

If there was a security issue then the insecure version should NOT be available. But again this is not the case.

In an App Store world, the role of mainainter has to change. The job is to make the software work with the distro, not keep the name and make some pseudo fork because you want it to be another way.

Re: KeePassXC Debian maintainer has removed all network features

#105

Earlier quoted context omitted.

If both upstream and a significant portion of users strongly disagree with a maintainer's judgement, then how is their role as maintainer justified? It's KeePassXC's job to secure the software and produce features that fulfill users' needs as they see fit. Julian's role as maintainer may intersect with that to a limited extent , in deciding on what kind of defaults best fit the rest of the OS. But, in this case, the…

Sorry, why do maintainers owe us anything? They’re typically unpaid or poorly paid and are doing everyone a favour. The code is open source and anyone who doesn’t like their work can easily fork the project. They don’t need to justify anything to us

>Sorry, why do maintainers owe us anything?

"they're doing it for free, no one owes you anything" is always the argument people make when someone does something reasonably dumb and they need to defend the maintainers/devs. They don't owe anyone anything, but people DO HAVE _REASONABLE_ expectations of them.

Re: KeePassXC Debian maintainer has removed all network features

#106

Earlier quoted context omitted.

Absolute security means you can't do anything . Too much security friction can easily lead to *much more insecure* workarounds.

Somehow, I have been using the same app without any of those features. So, the idea that the app is not functional or useful without them is bullshit. As for friction leading indirectly to less security through user behavior... how many clicks and how many seconds is it to install the full version? So, yet more bullshit.

> Convenience and necessity are two different things. You want conveninece, and you're not wrong to want it, but you don't need it, and your want...

> Somehow, I have been using the same app without any of those features. So, the idea that the app is not functional or useful without them is bullshit.

Different people might have different needs and wants and other criteria to consider it functional? I think this is not up for you to decide.

Re: KeePassXC Debian maintainer has removed all network features

#107
post #100
post #81

Earlier quoted context omitted.

But they already had a choice, since the removed options were disabled by default. This really just breaks core functionality that exists and is expected by real users, under the guise of unnamed security risks...theres plenty of disabled options in Linux that are "potential" risks, so its a silly choice.

Hyperbole! $ apt install keepassx $ apt install keepassx-full Choice made.

Choice was already made when they installed it with xyz features available.

If it was so important they never should have packaged it in the first place. -Minimal option is the obvious reasonable choice, unless trying to be an arse to make a point, since you're changing a users choice after the fact.

Are we going to stop compiling sshd with plaintext pw options and root login, and suddenly?

If a user has an option enabled you don't like anymore, notify them, don't blindly remove functionality and say "your fault for not reading the changelogs".

Frankly the security claims ring more of hyperbole than anything

Re: KeePassXC Debian maintainer has removed all network features

#108
post #82
post #79

Earlier quoted context omitted.

Well no, what the user is actually being given is a completely different application than the original one they downloaded, which is now increasing the maintenance burden upstream because THEY are they one getting all the bug reports because Debian decided to swap the packages out from underneath their users: https://github.com/keepassxreboot/keepassxc/issues/10725#iss... > This is now our fourth bug report because o…

It's not completely different. They patched stuff out. And I, as an end user, am absolutely fine with that, as a user of vim-nox package etc etc...

vim-nox is pretty much full-featured vim without x11 stuff.

Do you have a non-trivial .vimrc/.vim directory?

Would you be accepting of the maintainer disabling a bunch of features and pushing those changes out under the main vim-nox package such that it breaks your existing install? Would it be reasonable to expect you as the end user to figure out what has happened and that you need to uninstall vim-nox and and install vim-nox-full?

Re: KeePassXC Debian maintainer has removed all network features

#109

I think it's correct for the default package to be the safest-possible one. It's a password manager not an mp3 player. Yes it's annoying that an existing behavior will change, but that problem is not more impportant than the problem of what should be the default behavior of a security app. keepassxc should have always been like that by default and all the added conveniences that also add bug-surface and attack-surfac…

Safest by what metric? Calling the browser integration a "convenience" feature only is just fundamentally wrong.

Realistically the most common attack most users face is a phishing attack, removing the browser integration which checks the URL programmatically before filling the password opens the user up to being phished more easily (users check URLs less consistently and less reliably), so arguably this makes the package less secure in the real world.

Re: KeePassXC Debian maintainer has removed all network features

#110

Earlier quoted context omitted.

If both upstream and a significant portion of users strongly disagree with a maintainer's judgement, then how is their role as maintainer justified? It's KeePassXC's job to secure the software and produce features that fulfill users' needs as they see fit. Julian's role as maintainer may intersect with that to a limited extent , in deciding on what kind of defaults best fit the rest of the OS. But, in this case, the…

Sorry, why do maintainers owe us anything? They’re typically unpaid or poorly paid and are doing everyone a favour. The code is open source and anyone who doesn’t like their work can easily fork the project. They don’t need to justify anything to us

Package maintainer != Project maintainer.

In this instance the maintainer of the Debian package for KeePassXC has unilaterally made a choice.

Post reply on HN