<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=6602&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / KeepassXC]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=6602</link>
		<description><![CDATA[The most recent posts in KeepassXC.]]></description>
		<lastBuildDate>Tue, 02 Jul 2024 14:28:04 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: KeepassXC]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=50881#p50881</link>
			<description><![CDATA[<p>Does anyone have a list of the features that were omitted re: this bug ticket? One of the commenters mentions it&#039;s the &quot;fourth&quot; bug ticket related to feature-removal.</p><p>Edit: Unrelated to the question but I found this... <a href="https://news.ycombinator.com/item?id=40320166" rel="nofollow">https://news.ycombinator.com/item?id=40320166</a></p><div class="quotebox"><blockquote><div><p>All they did was change the XC_ALL build parameter to OFF [0] which happens to be the default in upstream&#039;s CMakeLists.txt</p></div></blockquote></div><p>And</p><div class="quotebox"><blockquote><div><p>INSTALL.md [0] recommends passing -DWITH_XC_ALL in the Build Steps section.</p></div></blockquote></div><p>From Soren&#039;s GH issue, it sounds like the maintainers may remove such functionality in the future. <a href="https://github.com/keepassxreboot/keepassxc/issues/10725#issuecomment-2104750715" rel="nofollow">https://github.com/keepassxreboot/keepa … 2104750715</a></p><div class="quotebox"><blockquote><div><p>As @droidmonkey said, none of these features are plugins. All of them are built-in functionality that belong to the main product. If anything, we will reduce the number of such compile-time flags in the future, so these things cannot be disabled anymore.</p></div></blockquote></div><p>I&#039;m not gonna take a position on this since all of this boils down to &quot;free labor&quot; from all parties. The &quot;drive-by contributor attack&quot; is certainly a valid concern these days, notably with respect to the XZ/LZMA fiasco. This could be an interesting case to investigate...</p><p>Edit: The Debian packages site isn&#039;t loading for me, but my search engine is fetching results for <span class="bbc">keypasscx-full</span> and <span class="bbc">keypassxc-minimal</span>. So...</p>]]></description>
			<author><![CDATA[dummy@example.com (siva)]]></author>
			<pubDate>Tue, 02 Jul 2024 14:28:04 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=50881#p50881</guid>
		</item>
		<item>
			<title><![CDATA[Re: KeepassXC]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=50876#p50876</link>
			<description><![CDATA[<p>I can understand both sides. I don&#039;t use the unstable branch so I doubt I will get affected by this but if I were the App Image and Flatpack options are there. Each camp has options at their disposal to gett he result they want.</p>]]></description>
			<author><![CDATA[dummy@example.com (Publiclewdness)]]></author>
			<pubDate>Tue, 02 Jul 2024 04:52:16 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=50876#p50876</guid>
		</item>
		<item>
			<title><![CDATA[Re: KeepassXC]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=49922#p49922</link>
			<description><![CDATA[<div class="quotebox"><cite>soren wrote:</cite><blockquote><div><p> It kind of reminds me of something microsoft would do.</p></div></blockquote></div><p>Microso~1 uploads and stores your passwords in its cloud - without asking of course. Just try the new outlook, it&#039;s great!</p><p>Edit:<br />I don&#039;t see a problem at all. The full feature version is still existing; beside a more secure, minimal version.</p>]]></description>
			<author><![CDATA[dummy@example.com (delgado)]]></author>
			<pubDate>Mon, 13 May 2024 17:47:16 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=49922#p49922</guid>
		</item>
		<item>
			<title><![CDATA[Re: KeepassXC]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=49915#p49915</link>
			<description><![CDATA[<div class="quotebox"><blockquote><div><p><strong>Altoid wrote:</strong><br />As I understand it, julian-klode&#039;s point of view is clearly aligned with the Unix/Linux philosophy.<br />ie: doing one thing and doing it well.</p></div></blockquote></div><p>So how far does this mindset go to preempt a perceived security risk, not an actual risk? Lets start ripping build features out of xorg that might seem superfluous shall we?</p><p>I dont understand the reasoning as the password manager has features that directly relate to safe password storage and usage, nothing more nothing less. And on another note, from what i can gather is there could be two packages in the pipeline, one full one minimal. So why bother when the program itself has these build options/features that have been accused of having security risks as opt in not opt out and are turned off by default. On the one hand the full keepassxc is le bad but they will still ship it but have a minimal debian built version?? It kind of reminds me of something microsoft would do.</p>]]></description>
			<author><![CDATA[dummy@example.com (soren)]]></author>
			<pubDate>Mon, 13 May 2024 02:00:04 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=49915#p49915</guid>
		</item>
		<item>
			<title><![CDATA[Re: KeepassXC]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=49911#p49911</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>ab wrote:</cite><blockquote><div><p>... wouldn&#039;t be able to use the current Debian package.</p></div></blockquote></div><p>From what I make out of the OP, the reduced functionality has only been applied to <span class="bbc">sid</span>, the unstable developement Debian, meaning <span class="bbc">Excalibur</span> in Devuan.</p><p>I&#039;d opine that there is still a <em>long</em> way to go till the package with the reduced functionality actually gets into the Debian stable repositories. </p><p>In the meantime, I&#039;m sure a way to get what different users need without going against the basic <span class="bbu">do one thing and do it well</span> philosophy will be found.</p><p>eg: base package for most users plus a set of separately packaged plugins (or similar) for those who need the different additional functionalities.(?)</p><p>Just my $0.02.</p><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Sun, 12 May 2024 23:03:40 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=49911#p49911</guid>
		</item>
		<item>
			<title><![CDATA[Re: KeepassXC]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=49910#p49910</link>
			<description><![CDATA[<p>If one needs more functionality than is included in the neutered Debian KeepassXC package, this is probably a good time to consider the KeepassXC AppImage or Flatpak.&#160; There might be an extra step with each in getting browser integration working.</p><p>I wouldn&#039;t be able to use the current Debian package.&#160; That&#039;s a no go.</p>]]></description>
			<author><![CDATA[dummy@example.com (ab)]]></author>
			<pubDate>Sun, 12 May 2024 21:58:31 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=49910#p49910</guid>
		</item>
		<item>
			<title><![CDATA[Re: KeepassXC]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=49907#p49907</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>julian-klode wrote:</cite><blockquote><div><p>... these features are superfluous and do not really belong in a local password database manager ...</p></div></blockquote></div><p>Makes a lot of sense to me.</p><p>Much more so with what we have seen happening lately. </p><p>As I understand it, julian-klode&#039;s point of view is <span class="bbu">clearly aligned</span> with the Unix/Linux philosophy.<br />ie: doing one thing and doing it well.</p><p>Something to be lauded, not criticised.<br />As always, YMMV.</p><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Sun, 12 May 2024 18:48:00 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=49907#p49907</guid>
		</item>
		<item>
			<title><![CDATA[KeepassXC]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=49899#p49899</link>
			<description><![CDATA[<p>The debian maintainer for keepassxc has decided to reduce the functionality of keepassxc in debian sid due to what he percieves as&#160; unwanted/needed security attack surface, not sure if this affects devuan ceres. In my opinion this is not warranted, the software is built to have all this functionality around it. </p><p><a href="https://github.com/keepassxreboot/keepassxc/issues/10725/" rel="nofollow">https://github.com/keepassxreboot/keepa … ues/10725/</a></p><p>tldr:</p><p><strong>droidmonkey</strong></p><div class="quotebox"><blockquote><div><p>@julian-klode this needs to be reverted asap. This is now our fourth bug report because of the decision to neuter the base KeePassXC package in Debian. Put the base package back where it was and create a keepassxc-minimal.</p></div></blockquote></div><p><strong>julian-klode</strong></p><div class="quotebox"><blockquote><div><p>I&#039;m afraid that&#039;s not going to happen. It was a mistake to ship with all plugins built by default. This will be painful for a year as users annoyingly do not read the NEWS files they should be reading but there&#039;s little that can be done about that.</p><p>It is our responsibility to our users to provide them the most secure option possible as the default. All of these features are superfluous and do not really belong in a local password database manager, these developments are all utterly misguided.</p><p>Users who need this crap can install the crappy version but obviously this increases the risk of drive-by contributor attacks.</p></div></blockquote></div>]]></description>
			<author><![CDATA[dummy@example.com (soren)]]></author>
			<pubDate>Sun, 12 May 2024 08:50:39 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=49899#p49899</guid>
		</item>
	</channel>
</rss>
