keepassxc,
@keepassxc@fosstodon.org avatar

Following the recent discussion around the Debian decision to ship KeePassXC without any of its optional modules, we've seen some extreme misconceptions floating around the internet regarding what the WITH_XC_NETWORKING=OFF compile flag actually does.

Let us be clear: KeePassXC does NOT "randomly" connect to the internet in the background, regardless of whether you build with the flag on or off. Claims to the contrary of KeePassXC "surfing in the background" or "calling home" are false.

1/4

keepassxc,
@keepassxc@fosstodon.org avatar

KeePassXC connects with the internet in only three situations:

  1. to check for updates (we ask you first if you agree to that and this feature is disabled in downstream packages such as Debian's anyway)

  2. when you manually click the button to download a website's favicon on the Edit Entry form

  3. when you decide to check your credentials against the online Hibp service (again, by explicitly clicking a button).

2/4

keepassxc,
@keepassxc@fosstodon.org avatar

That's it. That's all that is removed from your build when you disable the flag. There is no web server running or anything, it's only client code requiring a manual action that is removed (as well as a link dependency to OpenSSL, which may be more significant).

3/4

keepassxc,
@keepassxc@fosstodon.org avatar

What this flag DOES NOT do is sandbox KeePassXC in any way. It will also not remove Qt's internal networking modules, since these are still required for certain offline functionality such as URL parsing and local sockets (blame Qt for not separating this functionality). It will also not prevent a local attacker from loading other DLLs/SOs/DYLIBs containing network code at runtime.

4/4

neo,

@keepassxc People that were going to fearmonger about this are not going to be stopped because of your wall of text. They will still say "THING BAD" without understanding what they're saying.

keepassxc,
@keepassxc@fosstodon.org avatar

@neo This is not for those spreading misinformation, it’s for those receiving it without knowing the context.

larsmb,
@larsmb@mastodon.online avatar

@keepassxc It does also break the browser plugin functionality though, right?

Also: keep up the great work, I love keepassxc.

keepassxc,
@keepassxc@fosstodon.org avatar

@larsmb Yes. Although that is a separate flag that was also turned off.

urig,
@urig@mastodon.online avatar

@keepassxc this might be a good opportunity to say a

BIG THANK YOU

to all of you, dear team members, for your hard effort put into one of the most useful FOSS tools available today to enhance personal data security.

Many thanks!

melroy,
@melroy@mastodon.melroy.org avatar

@keepassxc I also don't agree with Debian maintainers. They just needed to leave the package as is. Create a minimal version if really wanted.

Arcaik,
@Arcaik@hachyderm.io avatar

@melroy @keepassxc That's what they did.

vintprox,
@vintprox@techhub.social avatar

@Arcaik @melroy @keepassxc Sure, after stirring the pot that packager could avoid by, maybe, not shoving defaults major userbase didn't ask for.

Arcaik,
@Arcaik@hachyderm.io avatar

@vintprox @melroy @keepassxc Just install keepassxc-full and be done with it.

melroy,
@melroy@mastodon.melroy.org avatar

@Arcaik @vintprox @keepassxc understood. But normal users are confused and from user perspective this is a bug, suddenly features are not working anymore.

melroy,
@melroy@mastodon.melroy.org avatar

@Arcaik @keepassxc no. The debian maintainers created a minimal version using the existing package name.

r1w1s1,
@r1w1s1@fosstodon.org avatar

@keepassxc many thanks guys!!! keep your great work!!!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • modclub
  • DreamBathrooms
  • osvaldo12
  • GTA5RPClips
  • ngwrru68w68
  • magazineikmin
  • everett
  • Youngstown
  • slotface
  • rosin
  • mdbf
  • kavyap
  • tacticalgear
  • InstantRegret
  • JUstTest
  • Durango
  • cubers
  • khanakhh
  • ethstaker
  • thenastyranch
  • normalnudes
  • provamag3
  • tester
  • cisconetworking
  • Leos
  • megavids
  • anitta
  • lostlight
  • All magazines