“I don’t want any of that.”
That’s it. That’s the entire review of Himmelblau 4.0 from one of its users. A single, dismissive line buried under a post celebrating cross-device passkeys, experimental MFA, and expanded OIDC controls. The developers spent months building cutting-edge authentication. And the user response? A shrug. A no. A rejection.
If you manage Linux identity—Entra ID, OIDC, anything that touches your team’s login flow—you’ve felt this tension before. The tool you rely on starts adding features. More options. More complexity. And somewhere between the QR code passkey flow and the new group mapping, you lose the thing that made it great: it just worked.
Let’s be clear: Himmelblau 4.0 is technically impressive. Cross-device passkey login via Bluetooth? That’s clever. Native MFA for Keycloak and Okta? Sure, it fills a gap. But the real story isn’t what’s new—it’s what’s missing: the trust that the next update won’t break your workflow.
Scrolling through the comments, you see the pattern. A few power users cheer the new features. But the top comment—the one that got the most upvotes—isn’t excitement. It’s fatigue. “I don’t want any of that.” That’s the silent majority speaking. The people who don’t tweet about open source, don’t file feature requests, and don’t attend developer conferences. They just update their systems and hope nothing changes.
This is the paradox of open source innovation: the more you add, the more you risk alienating your core users. Feature bloat isn’t a bug—it’s a betrayal of the promise that a tool will stay out of your way. Himmelblau 4.0 isn’t alone. Every major identity project faces this choice: chase the next shiny authentication protocol or double down on stability. The market rewards the former. The users reward the latter.
What’s the practical takeaway? If you’re deploying Himmelblau 4.0, don’t be seduced by the new features. Test them in isolation. Your team’s productivity depends on a login flow that doesn’t require a PhD in passkey protocols. The best authentication is the one your users never think about. And if you’re a maintainer reading this: the next time you plan a major release, ask yourself—is this feature solving a problem, or is it just solving a curiosity?
The Himmelblau controversy is a warning. The loudest voices in the room are the ones who want more. But the quiet ones—the ones who just want their tools to work—are the ones who determine whether your project thrives or fades. Listen to them. Or don’t be surprised when the next top comment is, “I’m switching to something else.”
FAQ
Q: Isn't the backlash just a vocal minority? Most Linux users want new features, right?
A: No. The top comment on the Himmelblau 4.0 announcement—the one that got the most upvotes—was a rejection of the new features. That's a signal that the silent majority, who don't usually engage, are frustrated. Feature requests come from a vocal minority; stability demands come from everyone else.
Q: How should I evaluate whether to upgrade to Himmelblau 4.0?
A: Test the new features in a staging environment first. Don't enable passkey or MFA immediately. Measure the impact on your team's login time and support tickets. If your current setup works, there's no rush to upgrade. The new features are experimental—treat them as such.
Q: Aren't the developers right to innovate? Passkeys and MFA are the future.
A: Innovation is important, but not at the cost of your core user base. The future of authentication means nothing if your current users jump ship. The best approach is to offer features as opt-in or as separate modules. Himmelblau's mistake was bundling experimental features into a major release without a clear 'I don't want any of that' off-ramp.