#1042539 Create face-recognition data package

Package:
digikam
Source:
digikam
Description:
digital photo management application for KDE
Submitter:
Christoph Anton Mitterer
Date:
2023-12-07 17:36:11 UTC
Severity:
normal
Tags:
#1042539#5
Date:
2023-01-12 05:24:07 UTC
From:
To:
Hey.

Every time when starting digikam, a dialog pops up asking to download
some engines for redeye removal and face detection from the internet,
which would cause them to be stored in /home/calestyo/.local/share/digikam/

Could that please be disabled?

a) It's a security risk. It's aboslutely unclear who controls these files
   (at least not debian).
   Further it would be code that circumvents the package management system
   and thus any security support or further things like checking for updates
   via tools like check_apt.

   Any code that's not distributed via Debian archives makes it always
   easier for an attacker to target only specific victims (rather than all
   which would be given if all users are guaranteed to get the same code),
   which makes it less likely to spot any breaches.

   Code ownloaders, even if they do e.g. signature verifications are actully
   much more difficult to do properly than just verfying a signature
   (see downgrade or replay attacks) - things which are all handled by the
   package management but perhaps not by any programs own downloaders.


b) If the files are only available as blobs, they aren't DFSG compatible
   so AFAIU, if digikam would still do so, wouldn't it no longer qualify
   for main.


c) Other packages in Debian, e.g. Firefox disable any such automatic downloads
   of security-wise at best questionable code downloaders or "self-updaters".



I also noticed that digikam, even if not downloading the stuff, creates:
  /home/user/.local/share/digikam/QtWebEngine/Default/blob_storage/
which also sounds a bit fishy.


Thanks,
Chris.

#1042539#12
Date:
2023-05-06 00:31:19 UTC
From:
To:
forwarded 1028507 https://bugs.kde.org/show_bug.cgi?id=438317
thanks

It's coming in version 8.

I hear your concerns.  These files are data that used to be shipped as part of
digikam and were later unbundled, which led to the download prompt.  You can
read through the upstream bug for a full discussion.

#1042539#15
Date:
2023-05-06 00:31:19 UTC
From:
To:
forwarded 1028507 https://bugs.kde.org/show_bug.cgi?id=438317
thanks

It's coming in version 8.

I hear your concerns.  These files are data that used to be shipped as part of
digikam and were later unbundled, which led to the download prompt.  You can
read through the upstream bug for a full discussion.

#1042539#20
Date:
2023-07-07 02:39:35 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
digikam, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1028507@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Steve M. Robbins <smr@debian.org> (supplier of updated digikam package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 06 Jul 2023 21:20:25 -0500
Source: digikam
Architecture: source
Version: 4:8.0.0-2
Distribution: unstable
Urgency: medium
Maintainer: Debian KDE Extras Team <pkg-kde-extras@lists.alioth.debian.org>
Changed-By: Steve M. Robbins <smr@debian.org>
Closes: 1028507 1036738 1037621
Changes:
 digikam (4:8.0.0-2) unstable; urgency=medium
 .
   [ Steve Robbins ]
   * [a8c865a] Add libksanecore-dev dep
   * [e861f33] Disable mediaplayer for upload to unstable.
   * New upstream version.  Closes: #1036738.
     Builds with GCC-13.  Closes: #1037621.
     User able to disable downloading face detection data. Closes: #1028507.
Checksums-Sha1:
 d60f08a9968c93565776ab89f6a87a6b21b6b3ef 3336 digikam_8.0.0-2.dsc
 bdd42f4e31787f9b6d8b011f9746187b537dcc7e 39536 digikam_8.0.0-2.debian.tar.xz
 71a3ec605249e64e21b36ee8b47bd90978cdd96f 36169 digikam_8.0.0-2_source.buildinfo
Checksums-Sha256:
 a776e0f146063736838b61c52419fd379e39c86fccab7e73777d5e1a9cbb0d56 3336 digikam_8.0.0-2.dsc
 561584161471c4e224e3c9d6f5bf995fe6d148d93ab2a30bd37bf1902fdf89d6 39536 digikam_8.0.0-2.debian.tar.xz
 0dab133bb403c56befb47b1c039bfdb3774f798eb5542550c212bbcae76a7160 36169 digikam_8.0.0-2_source.buildinfo
Files:
 aead14daeaf81c0d379f4c8ef0d757cc 3336 graphics optional digikam_8.0.0-2.dsc
 87a5e1d9a6366e2d7ff94fedde83e058 39536 graphics optional digikam_8.0.0-2.debian.tar.xz
 79ee6ab8d2b867f34dabadbea7be711a 36169 graphics optional digikam_8.0.0-2_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJDBAEBCAAtFiEEy89k8fa3rclNjyokyeVeL63I9LkFAmSnd6gPHHNtckBkZWJp
YW4ub3JnAAoJEMnlXi+tyPS54f8P/ROBjhutd4o7EOMMrIbYQ1f8q2kaVmUXyrPI
3QtuVkalcWxCmb5A8bc2WqocnFikGYvJjaQtTgI0cdQ3lLGj5zjuXkL49hJ2J/3e
WfF8J1TTwyuTl30aLSAG5q7WAlWkYDmSVTRdRvPu46z1zNU925y6D0yeUt2X3dC4
zlzVVdz3YLs1hHISxx7bU85Z4Om81dKGc4cqVitzAxt/A4azjeunozS8kcb7EWnY
7FNieVRtN11ljTvLMFID6SrGsj4AWyoRYPBdCnNJxbuW9+83W4wqCtwsd2hjPmyY
l885FDieWFwgaSRR6HzouzjCsARYR5KlkXkwcPRILIPVpnflUp5wnjOYsxhfsf8S
QQD7EanGMpFihxb9hLnP61uML1AUHznvb0OijS3FlDm11F6JeU5jsWkOO09qGAlw
IWepByURYm79v7DLo06K2IbY06QmbaJHRohme6ogJHUJyegYRCm/XbkCLMhtodYJ
6vIwYheYngPs1kO7aM8EiR5Ufm1JiD/Otof8+PuGMEEEqR6pPu006lq6EUnvHkfe
Lxsb89CDTJDyCLG6rmqmk4Rr3o/tORM8HTPd5cLNwQtMNhk4ARYTEjoRelXbHQ2N
gDyGttWGbeNLfDq1yukpvmXg3FpGjiBhQSU2/arU93pu+416MQnNws1w++R2hQNg
esZQAHCo
=oIo1
-----END PGP SIGNATURE-----

#1042539#25
Date:
2023-07-18 10:38:21 UTC
From:
To:
That fixes the immediate issue, but it still doesn't answer the question
if it's legitimate that an application packaged for the Debian main
archive would ask for additional downloads from a 3rd party server to
enable full functionality.

Would it be possible to create a separate Debian package with this data
and add it as a Recommends: dependency?
I believe there is enough precedent for large optional companion data
packages in Debian. (0ad-data and kicad-packages3d come to mind)
This would make it much clearer what the user is getting and from whom,
and it would reduce the burden on the upstream CDN.

#1042539#30
Date:
2023-07-29 23:45:51 UTC
From:
To:
clone 1028507 -1
retitle -1 Create face-recognition data package
thanks
https://mail.kde.org/pipermail/digikam-devel/2023-May/112408.html