Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. I want this but as a Linux distribution.

I want this but as a Linux distribution.

Geplant Angeheftet Gesperrt Verschoben Uncategorized
91 Beiträge 44 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • mcc@mastodon.socialM mcc@mastodon.social

    My understanding is that Bitwarden and KeePassXC, the two open source password managers, are *both* using random code generators at this point, which is terrifying as those are the exact tools where a small error could have the largest negative impact, and also tools that once you've committed to using it you can't quickly back out if they enter a code quality decline

    https://github.com/bitwarden/clients/tree/main/.claude

    greyduck@wellduck.meG This user is from outside of this forum
    greyduck@wellduck.meG This user is from outside of this forum
    greyduck@wellduck.me
    schrieb zuletzt editiert von
    #19

    @mcc I admit I don't know the KeePass ecosystem terribly well, but does this go "up the chain" to regular KeePass 2.x or is it just XC?

    ratsnakegames@mastodon.socialR just_one_bear@mastodon.socialJ 2 Antworten Letzte Antwort
    0
    • mcc@mastodon.socialM mcc@mastodon.social

      RE: https://mastodon.scot/@kim_harding/116108957641748718

      I want this but as a Linux distribution. I don't think I'm asking for much here. I am just asking for the "open source community" to be to the left of Goldman Sachs

      brett_e_carlock@mastodon.onlineB This user is from outside of this forum
      brett_e_carlock@mastodon.onlineB This user is from outside of this forum
      brett_e_carlock@mastodon.online
      schrieb zuletzt editiert von
      #20

      @mcc I am dropping/switching any FOSS tools that I know are using GenAI/LLMs and it is getting bleak -_-

      mcc@mastodon.socialM 1 Antwort Letzte Antwort
      0
      • mcc@mastodon.socialM mcc@mastodon.social

        My understanding is that Bitwarden and KeePassXC, the two open source password managers, are *both* using random code generators at this point, which is terrifying as those are the exact tools where a small error could have the largest negative impact, and also tools that once you've committed to using it you can't quickly back out if they enter a code quality decline

        https://github.com/bitwarden/clients/tree/main/.claude

        mcc@mastodon.socialM This user is from outside of this forum
        mcc@mastodon.socialM This user is from outside of this forum
        mcc@mastodon.social
        schrieb zuletzt editiert von
        #21

        RE: https://wellduck.me/@greyduck/116110983001607000

        I would like the answer to this question as well.

        djm62@beige.partyD elfin@mstdn.socialE 2 Antworten Letzte Antwort
        0
        • mary@chaos.socialM mary@chaos.social

          @mcc @ariadne I have the same feeling, if something I use start accepting AI code assistant contributions, I am considering it the same way as any proprietary software.

          On the subject of Bitwarden, it seems that Vaultwarden isn't accepting any AI contributions so far (would need to dig more into issues/PRs to be 100% sure), so I will likely fork bitwarden client or make my own client... 🙃

          mcc@mastodon.socialM This user is from outside of this forum
          mcc@mastodon.socialM This user is from outside of this forum
          mcc@mastodon.social
          schrieb zuletzt editiert von
          #22

          @mary @ariadne That's interesting but as you say, vaultwarden without the client is… there's not a way to use it is there?

          mary@chaos.socialM 1 Antwort Letzte Antwort
          0
          • brett_e_carlock@mastodon.onlineB brett_e_carlock@mastodon.online

            @mcc I am dropping/switching any FOSS tools that I know are using GenAI/LLMs and it is getting bleak -_-

            mcc@mastodon.socialM This user is from outside of this forum
            mcc@mastodon.socialM This user is from outside of this forum
            mcc@mastodon.social
            schrieb zuletzt editiert von
            #23

            @Brett_E_Carlock the problem is removing any one tool from my life is a relatively large time investment and projects are adding "boycott me" flags faster than I can switch to or create alternatives

            brett_e_carlock@mastodon.onlineB 1 Antwort Letzte Antwort
            0
            • mcc@mastodon.socialM mcc@mastodon.social

              @glyph @itamarst i'm assuming they'll go directly to "ah, we're already using it, so we can't back it out now" even in orgs where the primary driver of it being used was executive mandates that each employee use a certain number of AI tokens per month

              glyph@mastodon.socialG This user is from outside of this forum
              glyph@mastodon.socialG This user is from outside of this forum
              glyph@mastodon.social
              schrieb zuletzt editiert von
              #24

              @mcc @itamarst my prediction is that they will pretend that once there are a few more truly catastrophic stories in the press, like if a whistleblower shows up to conclusively prove that Microsoft *knows* copilot is causing all the Windows bugs that everyone suspects it is, they will simply change the copy on their website to indicate that they were always against this and they were never fooled, and there will not be consequences for anyone involved

              1 Antwort Letzte Antwort
              0
              • mcc@mastodon.socialM mcc@mastodon.social

                @Brett_E_Carlock the problem is removing any one tool from my life is a relatively large time investment and projects are adding "boycott me" flags faster than I can switch to or create alternatives

                brett_e_carlock@mastodon.onlineB This user is from outside of this forum
                brett_e_carlock@mastodon.onlineB This user is from outside of this forum
                brett_e_carlock@mastodon.online
                schrieb zuletzt editiert von
                #25

                @mcc Yeah, absolutely. Thankfully so far these changes have all been low-stakes for me, but they are disruptive none-the-less.

                As a fairly recent full time Linux everywhere user, something as stupid as changing my music manager app was a pretty significant shakeup. Twice, back to back, no less, after finally settling on each one. Enough that I had to package an entirely different media manager to use, since I had no other options I remotely enjoyed using.

                Again, whinging, but the pattern holds

                brett_e_carlock@mastodon.onlineB 1 Antwort Letzte Antwort
                0
                • greyduck@wellduck.meG greyduck@wellduck.me

                  @mcc I admit I don't know the KeePass ecosystem terribly well, but does this go "up the chain" to regular KeePass 2.x or is it just XC?

                  ratsnakegames@mastodon.socialR This user is from outside of this forum
                  ratsnakegames@mastodon.socialR This user is from outside of this forum
                  ratsnakegames@mastodon.social
                  schrieb zuletzt editiert von
                  #26

                  @greyduck @mcc probably best to ask Mr Reichel here: https://sourceforge.net/p/keepass/discussion/329220/

                  1 Antwort Letzte Antwort
                  0
                  • mcc@mastodon.socialM mcc@mastodon.social

                    My understanding is that Bitwarden and KeePassXC, the two open source password managers, are *both* using random code generators at this point, which is terrifying as those are the exact tools where a small error could have the largest negative impact, and also tools that once you've committed to using it you can't quickly back out if they enter a code quality decline

                    https://github.com/bitwarden/clients/tree/main/.claude

                    reijomancer@defcon.socialR This user is from outside of this forum
                    reijomancer@defcon.socialR This user is from outside of this forum
                    reijomancer@defcon.social
                    schrieb zuletzt editiert von
                    #27

                    @mcc Canceled my subscription, told them why and now am deciding on if I even want to keep my own vaultwarden instance.

                    I can't trust the clients anymore, so i'm freezing updates to the apps - but that's a security time-bomb in and of itself.

                    Guess I'm doing a forced password manager migration in 2026 as well.

                    Thank you (and fuck them) for the information. I'm slightly annoyed that this is the first i've heard of it and Bitwarden published some BS about being all-in on agentic foolishness late last year.

                    1 Antwort Letzte Antwort
                    0
                    • brett_e_carlock@mastodon.onlineB brett_e_carlock@mastodon.online

                      @mcc Yeah, absolutely. Thankfully so far these changes have all been low-stakes for me, but they are disruptive none-the-less.

                      As a fairly recent full time Linux everywhere user, something as stupid as changing my music manager app was a pretty significant shakeup. Twice, back to back, no less, after finally settling on each one. Enough that I had to package an entirely different media manager to use, since I had no other options I remotely enjoyed using.

                      Again, whinging, but the pattern holds

                      brett_e_carlock@mastodon.onlineB This user is from outside of this forum
                      brett_e_carlock@mastodon.onlineB This user is from outside of this forum
                      brett_e_carlock@mastodon.online
                      schrieb zuletzt editiert von
                      #28

                      @mcc Low-stakes, and I have options.

                      What about for more significant/critical tools for folks? What about when there aren't real options?

                      What about for folks that can't just build and package something else?

                      1 Antwort Letzte Antwort
                      0
                      • mcc@mastodon.socialM mcc@mastodon.social

                        My understanding is that Bitwarden and KeePassXC, the two open source password managers, are *both* using random code generators at this point, which is terrifying as those are the exact tools where a small error could have the largest negative impact, and also tools that once you've committed to using it you can't quickly back out if they enter a code quality decline

                        https://github.com/bitwarden/clients/tree/main/.claude

                        luana@wetdry.worldL This user is from outside of this forum
                        luana@wetdry.worldL This user is from outside of this forum
                        luana@wetdry.world
                        schrieb zuletzt editiert von
                        #29

                        @mcc oh yikes wtf please not bitwarden

                        nina_kali_nina@tech.lgbtN 1 Antwort Letzte Antwort
                        0
                        • mcc@mastodon.socialM mcc@mastodon.social

                          @ariadne I am, in a flippant and general way, saying I want to eradicate all code with "AI code assistant" contributions from my computer and VPSes, but I do not currently know a way to do so. I keep having programs I previously installed add the poison after the fact without public notice. https://mastodon.social/@mcc/116110912928005524

                          Perhaps in future I will have to use Alpine Linux if that's how I get my code audited for no "AI" contributions.

                          luana@wetdry.worldL This user is from outside of this forum
                          luana@wetdry.worldL This user is from outside of this forum
                          luana@wetdry.world
                          schrieb zuletzt editiert von
                          #30

                          @mcc @ariadne hmmm there’s probably some really awful way to hack this into NixOS if you want to compile your whole system

                          xarvos@outerheaven.clubX 1 Antwort Letzte Antwort
                          0
                          • mcc@mastodon.socialM mcc@mastodon.social

                            RE: https://mastodon.scot/@kim_harding/116108957641748718

                            I want this but as a Linux distribution. I don't think I'm asking for much here. I am just asking for the "open source community" to be to the left of Goldman Sachs

                            moin@gruene.socialM This user is from outside of this forum
                            moin@gruene.socialM This user is from outside of this forum
                            moin@gruene.social
                            schrieb zuletzt editiert von
                            #31

                            @mcc
                            There is this thing called "debian" and "suse"

                            1 Antwort Letzte Antwort
                            0
                            • mcc@mastodon.socialM mcc@mastodon.social

                              @mary @ariadne That's interesting but as you say, vaultwarden without the client is… there's not a way to use it is there?

                              mary@chaos.socialM This user is from outside of this forum
                              mary@chaos.socialM This user is from outside of this forum
                              mary@chaos.social
                              schrieb zuletzt editiert von
                              #32

                              @mcc Vaultwarden bundle a custom version of the web client but it's basically the official one with stuffs renamed around at best.

                              So yeah in my case, I would fork the client, make a new one or audit the client changes each time I update the server side...

                              (For reference, most of my services are not exposed on the internet so I can limit the downfall of most things by pinning and audit things when updating even if it's not really practical)

                              mcc@mastodon.socialM mary@chaos.socialM 2 Antworten Letzte Antwort
                              0
                              • mary@chaos.socialM mary@chaos.social

                                @mcc Vaultwarden bundle a custom version of the web client but it's basically the official one with stuffs renamed around at best.

                                So yeah in my case, I would fork the client, make a new one or audit the client changes each time I update the server side...

                                (For reference, most of my services are not exposed on the internet so I can limit the downfall of most things by pinning and audit things when updating even if it's not really practical)

                                mcc@mastodon.socialM This user is from outside of this forum
                                mcc@mastodon.socialM This user is from outside of this forum
                                mcc@mastodon.social
                                schrieb zuletzt editiert von
                                #33

                                @mary Still trying to figure out what a pure open source version of React Native would look like. Writing React Native apps currently seems to require using something called "expo" which is theoretically open source but it refuses to run unless you sign up for a specific online service and sign a terms & conditions with questionable terms

                                mary@chaos.socialM 1 Antwort Letzte Antwort
                                0
                                • mary@chaos.socialM mary@chaos.social

                                  @mcc Vaultwarden bundle a custom version of the web client but it's basically the official one with stuffs renamed around at best.

                                  So yeah in my case, I would fork the client, make a new one or audit the client changes each time I update the server side...

                                  (For reference, most of my services are not exposed on the internet so I can limit the downfall of most things by pinning and audit things when updating even if it's not really practical)

                                  mary@chaos.socialM This user is from outside of this forum
                                  mary@chaos.socialM This user is from outside of this forum
                                  mary@chaos.social
                                  schrieb zuletzt editiert von
                                  #34

                                  @mcc I do think we (as a comunmity) should build a database of public repos that have any genAI related commits/config files, that would be a good start to flag thoses.

                                  mcc@mastodon.socialM leo@60228.devL justsoup@mstdn.socialJ 3 Antworten Letzte Antwort
                                  0
                                  • mary@chaos.socialM mary@chaos.social

                                    @mcc I do think we (as a comunmity) should build a database of public repos that have any genAI related commits/config files, that would be a good start to flag thoses.

                                    mcc@mastodon.socialM This user is from outside of this forum
                                    mcc@mastodon.socialM This user is from outside of this forum
                                    mcc@mastodon.social
                                    schrieb zuletzt editiert von
                                    #35

                                    @mary yeah. right now by the time you find out a project has an LLM infection you don't know which commit you even want to fork from

                                    1 Antwort Letzte Antwort
                                    0
                                    • wideeyedcurious@mstdn.socialW wideeyedcurious@mstdn.social

                                      @Lingmops @mcc I’m beginning to feel as if I’m gonna need to head back to just saving my pswds in a text file on my computer again. 🫤

                                      asymmetricblue@mastodon.socialA This user is from outside of this forum
                                      asymmetricblue@mastodon.socialA This user is from outside of this forum
                                      asymmetricblue@mastodon.social
                                      schrieb zuletzt editiert von
                                      #36

                                      @WideEyedCurious @Lingmops @mcc There was a time I used an AES encrypted ZIP file for passwords, and when I wanted one out, I would decrypt it to the console

                                      1 Antwort Letzte Antwort
                                      1
                                      0
                                      • mcc@mastodon.socialM mcc@mastodon.social

                                        My understanding is that Bitwarden and KeePassXC, the two open source password managers, are *both* using random code generators at this point, which is terrifying as those are the exact tools where a small error could have the largest negative impact, and also tools that once you've committed to using it you can't quickly back out if they enter a code quality decline

                                        https://github.com/bitwarden/clients/tree/main/.claude

                                        taschenorakel@mastodon.greenT This user is from outside of this forum
                                        taschenorakel@mastodon.greenT This user is from outside of this forum
                                        taschenorakel@mastodon.green
                                        schrieb zuletzt editiert von
                                        #37

                                        @mcc Let me tell you something more scary: These projects accept code contributions from random people they don't know, they never meet. Nobody knows these contributors' skill level, their mental health status, the acutal intend. They might be sloppy coders introducing bugs every other line. They could be maniacs. They could be evil nations' agents trying to implement backdoors.

                                        Why doesn't this scare you?

                                        1 Antwort Letzte Antwort
                                        0
                                        • mcc@mastodon.socialM mcc@mastodon.social

                                          RE: https://wellduck.me/@greyduck/116110983001607000

                                          I would like the answer to this question as well.

                                          djm62@beige.partyD This user is from outside of this forum
                                          djm62@beige.partyD This user is from outside of this forum
                                          djm62@beige.party
                                          schrieb zuletzt editiert von
                                          #38

                                          @mcc I had a look along those lines a while ago - I'm no longer using keepassxc, but there are independent implementations using the file format which I do use. What I really want is password-age with a good Android support though.

                                          https://beige.party/@djm62/115509364339314873

                                          1 Antwort Letzte Antwort
                                          0
                                          Antworten
                                          • In einem neuen Thema antworten
                                          Anmelden zum Antworten
                                          • Älteste zuerst
                                          • Neuste zuerst
                                          • Meiste Stimmen



                                          Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                                          Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                                          Impressum | Datenschutzerklärung | Nutzungsbedingungen

                                          • Anmelden

                                          • Du hast noch kein Konto? Registrieren

                                          • Anmelden oder registrieren, um zu suchen
                                          • Erster Beitrag
                                            Letzter Beitrag
                                          0
                                          • Home
                                          • Aktuell
                                          • Tags
                                          • Über dieses Forum