← Home ← Back to /g/

Thread 107064036

77 posts 16 images /g/
Anonymous No.107064036 [Report] >>107064123 >>107064257 >>107064258 >>107064405 >>107064543 >>107064793 >>107065891 >>107069926 >>107070438 >>107070440 >>107071182 >>107071193
Remember when Debian blocked KeepassXC from accessing the internet and the main keepassxc developer went mad? Really makes you think.
Anonymous No.107064123 [Report] >>107064143 >>107064157 >>107064197 >>107064315 >>107064337 >>107064387 >>107065595 >>107065723 >>107065891 >>107066039
>>107064036 (OP)
This is the exact reason linux maintainers cannot be trusted. Instead of packing the application the way the developer intended, they want to mess with shit that's none of their business. Windows and macOS are far more secure and better because you get software from the developer rather than some random person tinkering with the package without you even knowing about it.
Anonymous No.107064143 [Report] >>107065719
>>107064123
This is why I trust red hat more than some troon uploading to the AUR
Anonymous No.107064157 [Report]
>>107064123
looks like someone is still mad about plugging the security hole
Anonymous No.107064197 [Report]
>>107064123
that's exactly why I run my own distro, I don't need some troon to decide how to package stuff.
Anonymous No.107064257 [Report] >>107073809
>>107064036 (OP)
>Free as in free from choice
Anonymous No.107064258 [Report]
>>107064036 (OP)
idc I'm using KeeWeb.
Anonymous No.107064315 [Report] >>107064900
>>107064123
They're compile options.
you're giving up your compile option choice when you choose a maintainer.
unironically install gentoo.
Anonymous No.107064337 [Report]
>>107064123
trvke. package maintainers who think they know better than the developer start fucking their shit and using weird flags and patches. when the software breaks the developer gets the blame even if it's some unreproducible bug on some obscure distro. desktop linux software is broken on a fundamental level.
Anonymous No.107064387 [Report] >>107065457 >>107066296
>>107064123
if these features were hardcoded in and debian lowkey may them rethink that approach then it's good. these are features i use so i would want the full package as well but the arguments about reducing attack surface are good.
it overall seems like a non-issue because of how it's packaged anyway
>The actual impact will be negligible for users of stable versions of Debian, Ubuntu, and other Debian-derived distributions. Klode said that when Debian Trixie is released, upgrades and new installs of the keepassxc package will receive a transitional package that prompts them to decide between "full" and "minimal" packages. Klode says that this will allow users upgrading from bookworm to preserve their current setup. Future releases will have a "virtual" keepassxc package that, again, requires the user to explicitly select one or the other.
Anonymous No.107064405 [Report]
>>107064036 (OP)
testing faggots got cucked
Anonymous No.107064543 [Report] >>107064564 >>107065274 >>107070394
>>107064036 (OP)
Why, may I ask, does it need internet access?
Anonymous No.107064564 [Report] >>107064595
>>107064543
Sync features?
Anonymous No.107064595 [Report] >>107064611
>>107064564
Where? guide me. As far as I know, it only needs wifi to download website favicons, which can be imported offline anyway
Anonymous No.107064611 [Report] >>107064628
>>107064595
>Where?
How would I know I don't use this shit.
Anonymous No.107064628 [Report] >>107070394
>>107064611
Well, I do, and there no such features. That retard is bitching about maintainers breaking his "download icons" button, which is unnecessary and only works half the time
Anonymous No.107064793 [Report] >>107064875
>>107064036 (OP)
trannies will say that linux is totally fine for normal people and do shit like this, lmao.
Anonymous No.107064875 [Report] >>107065361
>>107064793
You sound both retarded and obsessed with trannies. Are you sure you're on the right board, champ?
Anonymous No.107064900 [Report] >>107065147
>>107064315
Not all compile options are exposed by useflags.
Install LFS.
Anonymous No.107065147 [Report] >>107070122
>>107064900
Imagine trusting other people's code. Like sloppy seconds.
Write your own software. Yes, drivers and OS too.
Anonymous No.107065173 [Report] >>107065600
Can anyone tell me what this means in english?
Anonymous No.107065274 [Report] >>107065552 >>107073700
>>107064543
KeepassXC can send your hashed passwords to haveibeenpwned.com to see if you were the victim of data breaches.
Anonymous No.107065361 [Report] >>107065419
>>107064875
You need to go back.
Anonymous No.107065419 [Report] >>107065482
>>107065361
Why are you talking about yourself in second person, MIGApede?
Anonymous No.107065457 [Report]
>>107064387
>Klode
subtlest vibe coder ever, real nice try claude by anthropic...
Anonymous No.107065482 [Report] >>107065501
>>107065419
I’m nta you originally replied to and I don’t support Trump.
You are a troon tourist though and you have to go back.
Anonymous No.107065501 [Report] >>107065513 >>107066258
>>107065482
>you have to go back
I won't.
Anonymous No.107065513 [Report] >>107065527
>>107065501
but you have to
Anonymous No.107065527 [Report]
>>107065513
Tough shit.
Anonymous No.107065552 [Report] >>107065579 >>107065590
>>107065274
Where? Guide me. Which setting? does it do that automatically?
Anonymous No.107065579 [Report]
>>107065552
Open a database and go to: Database > Database Reports (Ctrl+Shift+R) > HIBP
Anonymous No.107065590 [Report] >>107065601 >>107065635 >>107065659 >>107065922 >>107066362
>>107065552
>tools
>database reports
>hibp
not automatic
Anonymous No.107065595 [Report] >>107065610
>>107064123
If you want software exactly as the developer intended, download and install the (official) Flatpak or AppImage release instead. KeePassXC has a Flatpak package, and it's the officially recommended way to install it.
Anonymous No.107065600 [Report]
>>107065173
Debian maintainers chose to make a secure version before they made the full version available

https://github.com/keepassxreboot/keepassxc/wiki/Building-KeePassXC
>KeePassXC comes with a variety of build options that can turn on/off features. Most notably, we allow you to build the application with all TCP/IP networking code disabled.
Anonymous No.107065601 [Report]
>>107065590
not tools actually just database ignore the first thing
Anonymous No.107065610 [Report]
>>107065595
fuck fagpack annoying piece of shite i've ever had the displeasure of having to use for some shit
Anonymous No.107065635 [Report]
>>107065590
okey thanks, that could be useful
Anonymous No.107065659 [Report] >>107065670 >>107065755 >>107065922
>>107065590
Anonymous No.107065670 [Report] >>107065689
>>107065659
Good thing you've got 2fa set up... Right?
Anonymous No.107065689 [Report]
>>107065670
those are all for local network shit like ap control panels and the like so they're not accessible outside thankfully
Anonymous No.107065719 [Report] >>107066925
>>107064143
AUR is actually better than most normal package managers because you can inspect the PKGBUILD and verify it gets the files from the right place and builds it from source.
All binary packages are "trust me bro" tier.
Anonymous No.107065723 [Report]
>>107064123
It's open source. If you don't like the compile options the maintainers choose for the software, compile it yourself and/or install gentoo.
Anonymous No.107065755 [Report] >>107065771
>>107065659
damn, I only got 10k and 100k :(
Anonymous No.107065771 [Report] >>107065791
>>107065755
millions of time is unsurprisingly
>admin
Anonymous No.107065791 [Report]
>>107065771
bruh
I got 100k on my google account "A1234567s"
I use that account for youtube, and nothing more. My subscriptions and likes have been leaked, oh the horror...
Anonymous No.107065891 [Report] >>107065922
>>107064036 (OP)
Windowschad here
I block KeePass and any other program I want from the internet using Windows Defender Firewall with Advanced Security
Lintroons will never have this

>>107064123
why would you want your password vault to access the internet? sounds like the debian guy was doing a good thing and the keepassxc dev glows.
Anonymous No.107065922 [Report] >>107065940
>>107065891
>why would you want your password vault to access the internet?
for features like >>107065590
>>107065659
and to download favicons of site I guess
Anonymous No.107065940 [Report] >>107065950
>>107065922
>deliberately sending your passwords to someone on the internet
LMAO WTF
Anonymous No.107065950 [Report]
>>107065940
>sending your passwords
i see you can't read, sad
Anonymous No.107066039 [Report] >>107068101
>>107064123
This is the exact reason upstream maintainers cannot be trusted. Instead of packing the application in a way that respects the user, they want to mess with shit that's none of their business. Debian and Fedora are far more secure and better because you get software from a trusted packager rather than some random person tinkering with your system without you even knowing about it.
Anonymous No.107066074 [Report]
Debian maintainers are pretty obsessed with security and licenses. I mean they forked firefox to iceweasel because of the licensing on the logo/icon. Now with this audacity thing I'm still running the old version.

If they say its best practice to block these features of keepassxc, it's their right. I mean it is open source isn't it? It's supposed to be changeable.

I like this about debian, it's one of the reasons I run it.
Anonymous No.107066258 [Report] >>107066988
>>107065501
That’s fine, you’ll join the 41% eventually.
Anonymous No.107066296 [Report] >>107066362
>>107064387
But why do end users have to look this up? Why do they have to know what "minimal" and "full" feature? Why not just fix the security issue in-kernel and just install full?
Anonymous No.107066362 [Report]
>>107066296
because it's not a real security issue so much as a feature that gives the ick to the maintainer there's nothing to fix users have to explicit click "connect to internet" buttons for these to do anything see for example >>107065590
Anonymous No.107066925 [Report] >>107073391
>>107065719
sure, just compile everything from source dude
why not use gentoo at that point honestly
you realize the main point of compiled package package managers is so you don't have to spend hours compiling even slight version bumps on your software?
Anonymous No.107066988 [Report] >>107069915
>>107066258
>being the meme
Anonymous No.107068101 [Report] >>107068108 >>107073464 >>107073734
>>107066039
If you don’t trust the developer then why use their software? What you’re saying doesn’t make any sense. Debian backdooring your packages isn’t secure despite what you think.
Anonymous No.107068108 [Report]
>>107068101
he just edited an anti-linux comment, ironically in a way that goes against his very comment but oh well
Anonymous No.107069915 [Report] >>107073527
>>107066988
>tds
>left can't meme
wew
Anonymous No.107069926 [Report]
>>107064036 (OP)
>blocked KeepassXC from accessing the internet
Imagine being so cucked you actually let your passwords into the internet.

No excuse for this level of retardation.
Anonymous No.107070025 [Report]
lesspass, stateless password manager is what you want to use
Anonymous No.107070122 [Report]
>>107065147
Imagine trusting other people's hardware. Source your own materials, mine it, refine it, manufacture and assemble chips and pcb's. It's the only way you can be certain.

I don't even connect to anything outside of my own internet infrastructure. The power generation is also wholly mine from the ground up.
Anonymous No.107070394 [Report] >>107070684
>>107064543
Browser integration I’d imagine. And also>>107064628
Anonymous No.107070438 [Report]
>>107064036 (OP)
this is EXACTLY the kind of people I'd like to trust my passwords with, kek
Anonymous No.107070440 [Report]
>>107064036 (OP)
Works just fine on LinuxMint.
Anonymous No.107070684 [Report]
>>107070394
That is done via extension, you don't even need to have the packages to be able to use it, just the database.
Anonymous No.107071182 [Report]
>>107064036 (OP)
thats why i lov debian, it has stric public policies that developers and package mainteners follow along.
Anonymous No.107071193 [Report]
>>107064036 (OP)
What the fuck, that's based. I'm actually considering installing debian now.
Anonymous No.107072294 [Report] >>107073402 >>107073527
this got me spooked. is keepassxc really not okay to use?
Anonymous No.107073391 [Report]
>>107066925
>why not use gentoo at that point honestly
or just use NIX/Guix where you can guarantee a package fits its functional description whether it's compiled locally or not. Gentoo is just yesteryear's Guix.
Anonymous No.107073402 [Report]
>>107072294
it's fine
Anonymous No.107073464 [Report]
>>107068101
The developer could sell out or could suddenly make a user hostile choice.
See for example Simple Mobile Tools: dev sold the apps to some greedy company that added ads and spyware to the play store versions. F-droid (the distro) caught the change and switched to the fork Fossify keeping their users safe.
I trust distros because they have policies and processes to ensure users are respected. Debian has a great track record of this.
Anonymous No.107073527 [Report]
>>107069915
Stay mad, MIGApede.

>>107072294
It's free software and has been audited. If it did anything shady, it'd be found way faster than the xz exploit.
Anonymous No.107073700 [Report] >>107073754
>>107065274
>KeepassXC can send your hashed passwords
>hashed
like I'd ever trust a (((password manager))) to do that instead of pushing all my shit to mossad.
lol. lmao even.
Anonymous No.107073734 [Report]
>>107068101
>removing the backdoor is backdooring
post your nose, moshe
Anonymous No.107073754 [Report]
>>107073700
Exactly, these damn DEMONrats are taking backdoored mossad jewish (((passwords))) and sending them to the NSA CIA because the vaxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx dementia joe biden doesn't even know Keep ASS ex dee is all just a tranny indian psyop. Fucking libs
Anonymous No.107073809 [Report]
>>107064257
/thread
When people start screeching about muh freedom you can safely assume they are an authoritarian at best and the only reason they aren't full out fascist is that they are too impotent to make the step up from authoritarian to fascist.
>b-b--but it's only for your own good!
Yeah that's what every authoritarian and fascist says.