Live data from Hacker News

KeePassXC Debian maintainer has removed all network features

fosstodon.org

241–250 of 367 posts

Re: KeePassXC Debian maintainer has removed all network features

#241

Earlier quoted context omitted.

This isn’t the project maintainer we’re talking about, it’s the Debian package maintainer. Their job is building a working .deb with working software, not randomly messing with it. Users have the right to demand their packages to be trustworthy.

Randomly messing with the code they package is the primary job of a debian packager. Which is how we get such great contributions from debian maintainers like the weak keys fiasco.

It can also work the other way around. When I install Apache on other distros I end up having to disable so many modules -- whereas the default Apache config in Debian is pretty watertight I never really have to mess around with modules. Likewise installing PHP only installs the core PHP module, you have to specifically install the extras. Other distros install everything including the kitchen sink. Needless to say, I'll take the Debian approach, warts and all.

Re: KeePassXC Debian maintainer has removed all network features

#242

Earlier quoted context omitted.

If both upstream and a significant portion of users strongly disagree with a maintainer's judgement, then how is their role as maintainer justified? It's KeePassXC's job to secure the software and produce features that fulfill users' needs as they see fit. Julian's role as maintainer may intersect with that to a limited extent , in deciding on what kind of defaults best fit the rest of the OS. But, in this case, the…

> KeePassXC's job Is KeepassXC even a company ? looking at their site and wikipedia, they're just a bunch of people dedicated enough to maintain the project. Looking at the donation page [0] they don't even list anything going to themselves in the use of the money. So they're effectively paying with their time to keep the thing alive. If anything the community seem to own a ton to these guys. [0] https://keepassxc.or…

This reminds me of "The gift of it's your problem now" (2021):

   The best part of free software is it sometimes produces stuff you never would have been willing to pay to develop (Linux), and sometimes at quality levels too high to be rational for the market to provide (sqlite).

   The worst part of free software is you get what you get, and the developers don't have to listen to you. (And as a developer, the gift recipients aren't always so grateful either.)
https://apenwarr.ca/log/20211229

https://news.ycombinator.com/item?id=29736369

Re: KeePassXC Debian maintainer has removed all network features

#243

Earlier quoted context omitted.

not sure why you're commenting without even reading the linked 200 character post? the maintainer has enabled all plugins (including network stuff) in the keepassxc-full package, the keepassxc package will be just the basics with a much better security posture. that's obviously completely fine and completely within the remit of a maintainer, the entire complaint is about this being a change .

The default package should be named keepassxc-debian-limited or similar and the proper package should be keepassxc

It's the tyranny inherent to dependency-hell monolithic package management. nix avoids this problem by permitting multiple versions and flexible configurations of the same package.

Re: KeePassXC Debian maintainer has removed all network features

#244

Earlier quoted context omitted.

Sorry, why do maintainers owe us anything? They’re typically unpaid or poorly paid and are doing everyone a favour. The code is open source and anyone who doesn’t like their work can easily fork the project. They don’t need to justify anything to us

Package maintainer != Project maintainer. In this instance the maintainer of the Debian package for KeePassXC has unilaterally made a choice.

Which is pretty much what all other Debian package maintainers do. For Debian users it's expected they ensure the software they are packaging fits in with the Debian way of doing things. This is what Debian users want -- if they wanted all packages 'nude' with no changes applied there are other distros e.g. Arch that are much better suited. I personally tried other distros which tries to package as close to upstream as possible, and I was pretty surprised by the poor upstream defaults of many packages and lack of useful utilities. E.g. Apache is so much better packaged by Debian -- it wasn't until I installed Apache in Arch that I realised many of the useful stuff I used in Debian was actually Debian-specific. Most packages in Debian come with very good defaults that my "setup" script (i.e. install/configure packages) for my Debian machine is literally <50 lines whereas for Arch it was something like 200 lines including due to having to reconfigure a lot of not-very-well-thought-out upstream defaults that Arch kept in place.

Re: KeePassXC Debian maintainer has removed all network features

#245

Earlier quoted context omitted.

Sorry, why do maintainers owe us anything? They’re typically unpaid or poorly paid and are doing everyone a favour. The code is open source and anyone who doesn’t like their work can easily fork the project. They don’t need to justify anything to us

If you claim to distribute application FooBar, you owe it to the authors of said application to actually distribute FooBar and not something else that was modified against their wishes. If you want to distribute a modified version, you should call it something other than FooBar. You also owe it to your users to not mislead them by claiming that your modified version is actually the real FooBar.

I note elsewhere in this thread that all they did was disable an option from the upstream build script -- suggesting this is an acceptable option provided by upstream themselves? I think suggesting a rename is a bridge too far given even upstream provides a way to build the software without the extra functionality behind what sounds like a simple build option flag.

Re: KeePassXC Debian maintainer has removed all network features

#246

Earlier quoted context omitted.

Sorry, why do maintainers owe us anything? They’re typically unpaid or poorly paid and are doing everyone a favour. The code is open source and anyone who doesn’t like their work can easily fork the project. They don’t need to justify anything to us

This line is always ludicrous because it doesn’t play in literally any other volunteering scenario. In a previous life I coordinated volunteers. You better believe that I still held them to a standard and told them their time was better spent elsewhere if they didn’t want to play by the rules. “But they’re volunteering!” Is a uniquely open source contributor mindset that only seeks to perpetuate some nerd’s weird fie…

At the end of the day the volunteer is a volunteer for the Debian project (not KeepassXC or others) and doing what is deemed right for the Debian project. I agree volunteers should be held to a high standard, although I suspect in this case the volunteer is maintaining Debian's high standards. As a Debian user the volunteer's decision seems in line with Debian's ethos.

Re: KeePassXC Debian maintainer has removed all network features

#247

Earlier quoted context omitted.

He removed not only networking but support for yubikey, and autotype. These are all features that are turned off by default.

> and autotype I would go crazy w/o autotype. The way the IT dorks were forced by management to set up 'SSO' via an external provider at work, you have to enter the same information at least 3 times a day. 'SSO' for management means 'sign into each of our tools each single day'. Muh, no work done equals better security!

I'm in info sec and I agree with you. cyberArk weekly password rotation, no ability to save passwords in Edge, no ability to install a password manager.

Guess who keeps their password saved in notepad, all but three characters?

Re: KeePassXC Debian maintainer has removed all network features

#248

I abandoned KeePassX (pre XC fork) when they made wonky changes ~10 years ago. Use Bitwarden (optionally run your own sync server) or Keeper (for less technical people).

I recently switched from BW to XC in the wake of their acquisition, and I have to admit, the mobile experience is just a little more annoying. But I sleep better at night knowing that I don't keep anything critical on servers I don't own.

Re: KeePassXC Debian maintainer has removed all network features

#249
post #15

Looks like pretty reasonable decision to me - network features and browser integrations are huge potential holes / exploit entry points. And without network-related features and only running the trusted databases, the tool should be impossible to exploit even if exploits are found, which is a very desirable trait for something as important as password manager. Even original maintainer agrees [1]. Remember, the full n…

He removed not only networking but support for yubikey, and autotype. These are all features that are turned off by default.

If it's turned off by default, then please explain the drama. This simple statement makes this drama look like a storm in the proverbial teacup.

Re: KeePassXC Debian maintainer has removed all network features

#250
post #30

Earlier quoted context omitted.

Using the term crappy made me immediately lose respect for julian-klode.

Particularly of features that users depend on. It really leaves the impression that he thinks very little of debian users.

Features that according to your GP was disabled by default. And according to others in this discussion thread, disabled by default in the upstream also.
Post reply on HN