Live data from Hacker News

StarDict sends X11 clipboard to remote servers

lwn.net

131–140 of 350 posts

Re: StarDict sends X11 clipboard to remote servers

#131

Earlier quoted context omitted.

It's been in Debian for more than 20 years (see changelog here: https://tracker.debian.org/media/packages/s/stardict/changel... ). It's not clear to me if said "autosend off clipboard contents" has been in there the whole time though.

Data leaking bug reported as early as 2009: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534731 , so it's not looking rosy.

Which is interesting (as according to the LWN article) it seems like the general issue of what is sent is an ever-present one for StarDict, as apparently the earlier issue was around the defaults for all dictionaries, whereas the new issue is around a specific plugin.

Personally, if I was using (or a maintainer of) a dictionary tool which autoreads the clipboard (or any dictionary tool), I'd be checking what it is doing and considering whether it is what I would want to use.

Re: StarDict sends X11 clipboard to remote servers

#132

Earlier quoted context omitted.

Who protects you when the packagers decide to trust a shady CA (adding it to the root store) because it's used by the distro's infra?

Is this supposed to be some kind of gotcha argument? Against what?

Not exactly the same thing, but see https://en.wikipedia.org/wiki/GNU_IceCat#Additional_security....

Re: StarDict sends X11 clipboard to remote servers

#134
Somewhat related, I was quite surprised when I discovered that my Samsung phone was sharing ALL my clipboard with all my other Samsung devices, including passwords copied into the clipboard, and even preserving the history. I can't remember if the sharing was enabled by default or I opted in by accident. I assume it also goes through their servers to reach my other devices. I could disable the sharing, but still can't turn off the clipboard history, even switching to a different keyboard, the Samsung keyboard still captures the clipboard and saves the history, when I switch the keyboard to Samsung everything is there... I guess my next phone won't be Samsung.

Re: StarDict sends X11 clipboard to remote servers

#135
post #130

Earlier quoted context omitted.

Such responses to me are proof of malicious intent.

There are dozens of chrome extensions that translate (read: submit to untrusted server) on hover / highlight / context menu / textarea edit / etc. It is implied, that user acknowledges this functionality and accepts the risk. This includes untrusted server (because that's how they proxy requests to Google/Bing/Yandex Translate without exposing API keys). Security illiteracy? Yes. Malicious intent? Probably no. Does b…

Not sure if I would call it malicious but I would call it gross negligence.

Re: StarDict sends X11 clipboard to remote servers

#136
post #78

> In response, Xiao pointed out that the package description can be read by any user who chooses to install the software, and it does mention the scan feature. Wouldn't be the first (or last) time a Debian maintainer has pulled the "you should read the descriptions of all (hundreds) of your packages (most installed as dependencies)" card in response to a bug report. If someone started reading all the package descript…

“the plans and the demolition orders have been on display at the local planning office on Alpha Centauri for fifty of your Earth years. If you can't be bothered to take an interest in local affairs...” https://www.youtube.com/watch?v=Z1Ba4BbH0oY

For the uninformed: this is a quote from The Hitchhiker's Guide to the Galaxy.

Re: StarDict sends X11 clipboard to remote servers

#137

Earlier quoted context omitted.

Data leaking bug reported as early as 2009: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534731 , so it's not looking rosy.

Which is interesting (as according to the LWN article) it seems like the general issue of what is sent is an ever-present one for StarDict, as apparently the earlier issue was around the defaults for all dictionaries, whereas the new issue is around a specific plugin. Personally, if I was using (or a maintainer of) a dictionary tool which autoreads the clipboard (or any dictionary tool), I'd be checking what it is do…

For sure. I hope that due to the noise, they finally clean this up for good.

Re: StarDict sends X11 clipboard to remote servers

#138
post #101

Earlier quoted context omitted.

I think Hanlon's razor is outdated. Plausible deniability is the new meta. On top of that, the maintainer seems intent on not fixing the problem.

I think that in today's polarized world, it's very much needed. I think we need to look at each other's fallibilities and failures, and not hate each other for it. But the issue needs to be taken care of, especially since it's known since 2009. It's ridiculous that everyone let if fly for so long.

Yes, but it is a tricky situation when a common tactic is to pretend to be ignorant. For example by "just asking questions". We need more patience and respect in this polarized world but at the same time there are a minority of malicious actors who intentionally abuse any assumption of good faith given

Re: StarDict sends X11 clipboard to remote servers

#139

> of course a dictionary program will include code to talk to dictionary-providing web sites. I wouldn't say that is just a given, if I've apt-get installed a dictionary I might expect that is the whole thing on my machine. It's not like we haven't had dictionaries in physical books for centuries... It seems like stardict is very much an online thing, which I suppose could be legit, but the whole thing does seem like…

I's a generational thing. I would guess that someone who expects applications to phone home, on the off chance that they are actually otherwise local, is likely someone pretty young who hasn't lived in a world of locally installed software that doesn't talk to anything. If we search for the author's bio, that seems to check out. They are a well-credentialed CS person; obviously they know that dictionary programs such…

For many languages, there simply isn't a comprehensive dictionary file that could be redistributed legally as part of a free-software offline dictionary application. You either settle for a few thousand words put together by a handful of volunteers, or you redistribute a commercial dictionary illegally, or you have to connect to an online service to provide sufficient coverage legally.

Re: StarDict sends X11 clipboard to remote servers

#140
post #130

Earlier quoted context omitted.

Such responses to me are proof of malicious intent.

There are dozens of chrome extensions that translate (read: submit to untrusted server) on hover / highlight / context menu / textarea edit / etc. It is implied, that user acknowledges this functionality and accepts the risk. This includes untrusted server (because that's how they proxy requests to Google/Bing/Yandex Translate without exposing API keys). Security illiteracy? Yes. Malicious intent? Probably no. Does b…

[flagged]
Post reply on HN