GNU bug report logs -
#27909
Replace keepassx with keepassxc
Previous Next
To add a comment to this bug, you must first unarchive it, by sending
a message to control AT debbugs.gnu.org, with unarchive 27909 in the body.
You can then email your comments to 27909 AT debbugs.gnu.org in the normal way.
Toggle the display of automated, internal messages from the tracker.
Report forwarded
to
guix-patches <at> gnu.org
:
bug#27909
; Package
guix-patches
.
(Tue, 01 Aug 2017 15:09:02 GMT)
Full text and
rfc822 format available.
Acknowledgement sent
to
Efraim Flashner <efraim <at> flashner.co.il>
:
New bug report received and forwarded. Copy sent to
guix-patches <at> gnu.org
.
(Tue, 01 Aug 2017 15:09:02 GMT)
Full text and
rfc822 format available.
Message #5 received at submit <at> debbugs.gnu.org (full text, mbox):
[Message part 1 (text/plain, inline)]
The original keepassx hasn't seen much activity in quite a while, no
bugs fixed or features added. Keepassxc is the community fork of
keepassx.
--
Efraim Flashner <efraim <at> flashner.co.il> אפרים פלשנר
GPG key = A28B F40C 3E55 1372 662D 14F7 41AA E7DC CA3D 8351
Confidentiality cannot be guaranteed on emails sent or received unencrypted
[0001-gnu-Add-keepassxc.patch (text/plain, attachment)]
[0002-gnu-keepassx-Superseded-by-keepassxc.patch (text/plain, attachment)]
[signature.asc (application/pgp-signature, inline)]
Information forwarded
to
guix-patches <at> gnu.org
:
bug#27909
; Package
guix-patches
.
(Tue, 01 Aug 2017 19:44:01 GMT)
Full text and
rfc822 format available.
Message #8 received at 27909 <at> debbugs.gnu.org (full text, mbox):
[Message part 1 (text/plain, inline)]
On Tue, Aug 01, 2017 at 06:08:16PM +0300, Efraim Flashner wrote:
> The original keepassx hasn't seen much activity in quite a while, no
> bugs fixed or features added. Keepassxc is the community fork of
> keepassx.
The last keepassx release was in October 2016. That's not *that* long
unless there are some serious bugs in the program.
Are other distros replacing keepassx?
Is keepassxc a "seamless" replacement for keepassx, or would users maybe
have to adjust somehow?
[signature.asc (application/pgp-signature, inline)]
Information forwarded
to
guix-patches <at> gnu.org
:
bug#27909
; Package
guix-patches
.
(Tue, 01 Aug 2017 20:12:02 GMT)
Full text and
rfc822 format available.
Message #11 received at 27909 <at> debbugs.gnu.org (full text, mbox):
[Message part 1 (text/plain, inline)]
On Tue, Aug 01, 2017 at 03:43:19PM -0400, Leo Famulari wrote:
> On Tue, Aug 01, 2017 at 06:08:16PM +0300, Efraim Flashner wrote:
> > The original keepassx hasn't seen much activity in quite a while, no
> > bugs fixed or features added. Keepassxc is the community fork of
> > keepassx.
>
> The last keepassx release was in October 2016. That's not *that* long
> unless there are some serious bugs in the program.
>
The maintainer is MIA. I'm not aware of serious bugs, other than it
still relying on Qt-4.
> Are other distros replacing keepassx?
>
I don't believe Debian is, but there is active work on packaging
keepassxc. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=855173
> Is keepassxc a "seamless" replacement for keepassx, or would users maybe
> have to adjust somehow?
It is supposed to be a seamless replacement, using the same .kdbx files
as keepassx.
--
Efraim Flashner <efraim <at> flashner.co.il> אפרים פלשנר
GPG key = A28B F40C 3E55 1372 662D 14F7 41AA E7DC CA3D 8351
Confidentiality cannot be guaranteed on emails sent or received unencrypted
[signature.asc (application/pgp-signature, inline)]
Information forwarded
to
guix-patches <at> gnu.org
:
bug#27909
; Package
guix-patches
.
(Tue, 01 Aug 2017 20:28:02 GMT)
Full text and
rfc822 format available.
Message #14 received at 27909 <at> debbugs.gnu.org (full text, mbox):
[Message part 1 (text/plain, inline)]
Wouldn't it be a better option to keep both version for the time being?
Unless of course there is a security issue if we keep keepassx.
Manolis
[Message part 2 (text/html, inline)]
Information forwarded
to
guix-patches <at> gnu.org
:
bug#27909
; Package
guix-patches
.
(Tue, 01 Aug 2017 21:13:01 GMT)
Full text and
rfc822 format available.
Message #17 received at 27909 <at> debbugs.gnu.org (full text, mbox):
[Message part 1 (text/plain, inline)]
On Tue, Aug 01, 2017 at 11:11:50PM +0300, Efraim Flashner wrote:
> On Tue, Aug 01, 2017 at 03:43:19PM -0400, Leo Famulari wrote:
> > The last keepassx release was in October 2016. That's not *that* long
> > unless there are some serious bugs in the program.
>
> The maintainer is MIA. I'm not aware of serious bugs, other than it
> still relying on Qt-4.
Ah, still using Qt-4 is my pet peeve! :) That means it will have to be
removed sooner or later.
> > Are other distros replacing keepassx?
> >
>
> I don't believe Debian is, but there is active work on packaging
> keepassxc. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=855173
>
> > Is keepassxc a "seamless" replacement for keepassx, or would users maybe
> > have to adjust somehow?
>
> It is supposed to be a seamless replacement, using the same .kdbx files
> as keepassx.
Okay, I'll defer to what others think, especially since I'm not using
keepass*.
[signature.asc (application/pgp-signature, inline)]
Information forwarded
to
guix-patches <at> gnu.org
:
bug#27909
; Package
guix-patches
.
(Tue, 01 Aug 2017 21:18:02 GMT)
Full text and
rfc822 format available.
Message #20 received at 27909 <at> debbugs.gnu.org (full text, mbox):
[Message part 1 (text/plain, inline)]
On Tue, Aug 01, 2017 at 11:27:11PM +0300, Manolis Ragkousis wrote:
> Wouldn't it be a better option to keep both version for the time being?
> Unless of course there is a security issue if we keep keepassx.
I think that using Qt-4 is a security issue because it's unmaintained
for a long while now, relative to its complexity.
But we still have it in Guix because some packages would have to be
removed if we remove it, and we don't have a clear or simple policy
about what to do in cases like that. By the way, I'm not suggesting we
need such a policy.
Eventually we should remove those things, because it's not great to
offer users programs that we suspect have security bugs.
If somebody starting publishing details of how to exploit Qt-4 apps,
then I think the choice would be clear. But I haven't read any such
reports, so I don't know for sure that it's vulnerable. I think it's a
good bet, however.
[signature.asc (application/pgp-signature, inline)]
Information forwarded
to
guix-patches <at> gnu.org
:
bug#27909
; Package
guix-patches
.
(Wed, 02 Aug 2017 18:29:01 GMT)
Full text and
rfc822 format available.
Message #23 received at 27909 <at> debbugs.gnu.org (full text, mbox):
On 08/02/2017 12:17 AM, Leo Famulari wrote:
> On Tue, Aug 01, 2017 at 11:27:11PM +0300, Manolis Ragkousis wrote:
>> Wouldn't it be a better option to keep both version for the time being?
>> Unless of course there is a security issue if we keep keepassx.
>
> I think that using Qt-4 is a security issue because it's unmaintained
> for a long while now, relative to its complexity.
>
> But we still have it in Guix because some packages would have to be
> removed if we remove it, and we don't have a clear or simple policy
> about what to do in cases like that. By the way, I'm not suggesting we
> need such a policy.
>
> Eventually we should remove those things, because it's not great to
> offer users programs that we suspect have security bugs.
>
> If somebody starting publishing details of how to exploit Qt-4 apps,
> then I think the choice would be clear. But I haven't read any such
> reports, so I don't know for sure that it's vulnerable. I think it's a
> good bet, however.
>
I tested keepassxc locally and it opens my .kdbx file correctly. I think
there will be no problems with the change.
If no one else objects please push your patch. We don't want a possible
security issue in the future. :)
Thank you,
Manolis
Reply sent
to
Ricardo Wurmus <rekado <at> elephly.net>
:
You have taken responsibility.
(Wed, 16 Aug 2017 15:12:02 GMT)
Full text and
rfc822 format available.
Notification sent
to
Efraim Flashner <efraim <at> flashner.co.il>
:
bug acknowledged by developer.
(Wed, 16 Aug 2017 15:12:02 GMT)
Full text and
rfc822 format available.
Message #28 received at 27909-done <at> debbugs.gnu.org (full text, mbox):
Efraim Flashner <efraim <at> flashner.co.il> writes:
> The original keepassx hasn't seen much activity in quite a while, no
> bugs fixed or features added. Keepassxc is the community fork of
> keepassx.
I’m closing this because I see that this is in master already. (Commits
b7ac10e6da6e2199aa379fdfa19bd43ca8fddc4d and
99672f7b1d255b5cdac73870dfc272ca6799485b).
Thank you!
--
Ricardo
GPG: BCA6 89B6 3655 3801 C3C6 2150 197A 5888 235F ACAC
https://elephly.net
bug archived.
Request was from
Debbugs Internal Request <help-debbugs <at> gnu.org>
to
internal_control <at> debbugs.gnu.org
.
(Thu, 14 Sep 2017 11:24:04 GMT)
Full text and
rfc822 format available.
This bug report was last modified 7 years and 284 days ago.
Previous Next
GNU bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson.