Live data from Hacker News

StarDict sends X11 clipboard to remote servers

lwn.net

101–110 of 350 posts

Re: StarDict sends X11 clipboard to remote servers

#101

Earlier quoted context omitted.

Such responses to me are proof of malicious intent.

Hanlon's razor applies here, I think. It's just ignorance, not malice. I doubt the maintainer has connection, or was pressured by these two random dictionary websites to include this - nor do I think that they gain any advantage of it. People need to be on the lookout though, the xz incident showed that FOSS is indeed vulnerable.

I think Hanlon's razor is outdated. Plausible deniability is the new meta. On top of that, the maintainer seems intent on not fixing the problem.

Re: StarDict sends X11 clipboard to remote servers

#102

Earlier quoted context omitted.

In your eyes maybe (and mine for the record), but different people have different values and expectations of what is privacy.

The "Chinese values" excuse doesn't fly. We're not talking about a random Chinese person, we're talking about a Debian packager. Debian packagers should have values in line with the Debian project's ethos. It's difficult to imagine how somebody to whom Debian's values are alien could even accidentally stumble their way into the position of being a Debian packager.

Don't get me wrong, I'm not saying it's acceptable for a Debian packager, but I think that it's much more likely than malicious intent.

>It's difficult to imagine how somebody to whom Debian's values are alien could even accidentally stumble their way into the position of being a Debian packager

It's not for me.

Re: StarDict sends X11 clipboard to remote servers

#103

> In response, Xiao pointed out that the package description can be read by any user who chooses to install the software, and it does mention the scan feature. Wouldn't be the first (or last) time a Debian maintainer has pulled the "you should read the descriptions of all (hundreds) of your packages (most installed as dependencies)" card in response to a bug report. If someone started reading all the package descript…

Such responses to me are proof of malicious intent.

Such a response is not considered a valid defence under GDPR. You cannot sign away your right to privacy any more than you can sign away your right to life.

Re: StarDict sends X11 clipboard to remote servers

#104

[flagged]

I'm sure if people discovered that a Debian package offering "AI suggestions" would send the clipboard over unencrypted HTTP to two Chinese servers, it would make a similar noise.

Actively listening to the clipboard, and immediately, automatically sending the content elsewhere is akin to keylogging, spyware, plain and simple. It's a questionable practice even after accepting a huge popup, not to mention that the functionality is practically buried in TFA case.

Re: StarDict sends X11 clipboard to remote servers

#105
post #37

it looks like a serious "privacy violation" for English-only users. But for many ESL or non-English users out there, the "translation" is a must. On Windoes, I remember some translation programs go extreme, they hijack all GDI calls and scan for all strings on GUIs trying to translate and replace them inline. Local dictionary were pretty limited so many of them use online services. What happens when user input someth…

Translation isn't the problem, sending data over the network by default is. Data is leaked to Chinese dictionary servers even if you're translating between European languages using a local language according to https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806960 . With the GDI hijacking programs you usually download them for specific languages with the knowledge they're internet connected.

> Data is leaked to Chinese dictionary servers

stardict is a Chinese software and the bug you listed says it "leaks" data to stardict.cn which is one of its official website.

https://stardict-4.sourceforge.net/index_en.php

Btw looks like the stardict.cn is dead today

> with the knowledge they're internet connected

Yeah that's pretty much the whole argument.

I do agree that programs should not send data in an arbitrary way. Clear text over public network is not OK

Re: StarDict sends X11 clipboard to remote servers

#106

> In response, Xiao pointed out that the package description can be read by any user who chooses to install the software, and it does mention the scan feature. Wouldn't be the first (or last) time a Debian maintainer has pulled the "you should read the descriptions of all (hundreds) of your packages (most installed as dependencies)" card in response to a bug report. If someone started reading all the package descript…

I do agree with your point, specially when it is not the first time a package maintained by that guy does non-expected behavior like https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1010165 (Inappropriate package, modifies other package's (conf) files, should be removed from archive).

Re: StarDict sends X11 clipboard to remote servers

#107
post #37

it looks like a serious "privacy violation" for English-only users. But for many ESL or non-English users out there, the "translation" is a must. On Windoes, I remember some translation programs go extreme, they hijack all GDI calls and scan for all strings on GUIs trying to translate and replace them inline. Local dictionary were pretty limited so many of them use online services. What happens when user input someth…

> But for many ESL or non-English users out there, the "translation" is a must. As an ESL user, I vehemently disagree. You're only going to need translations as long as you keep relying on translations. Like it or not but English is the lingua franca of the computing age and you're doing yourself a disservice if you don't learn it.

> English is the lingua franca

Yes, so to learn English, ppl need some kind of "translator" tool, no?

The most comprehensive one (but very old) out there is stardict.

Re: StarDict sends X11 clipboard to remote servers

#108

Earlier quoted context omitted.

Such responses to me are proof of malicious intent.

Hanlon's razor applies here, I think. It's just ignorance, not malice. I doubt the maintainer has connection, or was pressured by these two random dictionary websites to include this - nor do I think that they gain any advantage of it. People need to be on the lookout though, the xz incident showed that FOSS is indeed vulnerable.

> pressured

Maybe incentivized? $1000? $10000? Would be interesting to hear from the developer himself.

Re: StarDict sends X11 clipboard to remote servers

#109

Meanwhile on Android: - The clipboard can not be read by backgrounded applications - Apps by default are unable to use HTTP

Android has its fair share of issues as well. For a recent issue, take a look at the localhost tracking, wherein "Meta devised an ingenious system that bypassed Android’s sandbox protections to identify you while browsing on your mobile phone — even if you used a VPN, the browser’s incognito mode, and refused or deleted cookies in every session":

https://news.ycombinator.com/item?id=44235467

Re: StarDict sends X11 clipboard to remote servers

#110

> In response, Xiao pointed out that the package description can be read by any user who chooses to install the software, and it does mention the scan feature. Wouldn't be the first (or last) time a Debian maintainer has pulled the "you should read the descriptions of all (hundreds) of your packages (most installed as dependencies)" card in response to a bug report. If someone started reading all the package descript…

[flagged]

Except that the description does not tell you that it ships off your clipboard unencrypted to Chinese servers.
Post reply on HN