Earlier quoted context omitted.
Such responses to me are proof of malicious intent.
Hanlon's razor applies here, I think. It's just ignorance, not malice. I doubt the maintainer has connection, or was pressured by these two random dictionary websites to include this - nor do I think that they gain any advantage of it. People need to be on the lookout though, the xz incident showed that FOSS is indeed vulnerable.
StarDict sends X11 clipboard to remote servers
101–110 of 350 posts
Re: StarDict sends X11 clipboard to remote servers
#102Earlier quoted context omitted.
In your eyes maybe (and mine for the record), but different people have different values and expectations of what is privacy.
The "Chinese values" excuse doesn't fly. We're not talking about a random Chinese person, we're talking about a Debian packager. Debian packagers should have values in line with the Debian project's ethos. It's difficult to imagine how somebody to whom Debian's values are alien could even accidentally stumble their way into the position of being a Debian packager.
>It's difficult to imagine how somebody to whom Debian's values are alien could even accidentally stumble their way into the position of being a Debian packager
It's not for me.
Re: StarDict sends X11 clipboard to remote servers
#103> In response, Xiao pointed out that the package description can be read by any user who chooses to install the software, and it does mention the scan feature. Wouldn't be the first (or last) time a Debian maintainer has pulled the "you should read the descriptions of all (hundreds) of your packages (most installed as dependencies)" card in response to a bug report. If someone started reading all the package descript…
Such responses to me are proof of malicious intent.
Re: StarDict sends X11 clipboard to remote servers
#104[flagged]
Actively listening to the clipboard, and immediately, automatically sending the content elsewhere is akin to keylogging, spyware, plain and simple. It's a questionable practice even after accepting a huge popup, not to mention that the functionality is practically buried in TFA case.
Re: StarDict sends X11 clipboard to remote servers
#105it looks like a serious "privacy violation" for English-only users. But for many ESL or non-English users out there, the "translation" is a must. On Windoes, I remember some translation programs go extreme, they hijack all GDI calls and scan for all strings on GUIs trying to translate and replace them inline. Local dictionary were pretty limited so many of them use online services. What happens when user input someth…
Translation isn't the problem, sending data over the network by default is. Data is leaked to Chinese dictionary servers even if you're translating between European languages using a local language according to https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806960 . With the GDI hijacking programs you usually download them for specific languages with the knowledge they're internet connected.
stardict is a Chinese software and the bug you listed says it "leaks" data to stardict.cn which is one of its official website.
https://stardict-4.sourceforge.net/index_en.php
Btw looks like the stardict.cn is dead today
> with the knowledge they're internet connected
Yeah that's pretty much the whole argument.
I do agree that programs should not send data in an arbitrary way. Clear text over public network is not OK
Re: StarDict sends X11 clipboard to remote servers
#106> In response, Xiao pointed out that the package description can be read by any user who chooses to install the software, and it does mention the scan feature. Wouldn't be the first (or last) time a Debian maintainer has pulled the "you should read the descriptions of all (hundreds) of your packages (most installed as dependencies)" card in response to a bug report. If someone started reading all the package descript…
Re: StarDict sends X11 clipboard to remote servers
#107it looks like a serious "privacy violation" for English-only users. But for many ESL or non-English users out there, the "translation" is a must. On Windoes, I remember some translation programs go extreme, they hijack all GDI calls and scan for all strings on GUIs trying to translate and replace them inline. Local dictionary were pretty limited so many of them use online services. What happens when user input someth…
> But for many ESL or non-English users out there, the "translation" is a must. As an ESL user, I vehemently disagree. You're only going to need translations as long as you keep relying on translations. Like it or not but English is the lingua franca of the computing age and you're doing yourself a disservice if you don't learn it.
Yes, so to learn English, ppl need some kind of "translator" tool, no?
The most comprehensive one (but very old) out there is stardict.
Re: StarDict sends X11 clipboard to remote servers
#108Earlier quoted context omitted.
Such responses to me are proof of malicious intent.
Hanlon's razor applies here, I think. It's just ignorance, not malice. I doubt the maintainer has connection, or was pressured by these two random dictionary websites to include this - nor do I think that they gain any advantage of it. People need to be on the lookout though, the xz incident showed that FOSS is indeed vulnerable.
Maybe incentivized? $1000? $10000? Would be interesting to hear from the developer himself.
Re: StarDict sends X11 clipboard to remote servers
#109Meanwhile on Android: - The clipboard can not be read by backgrounded applications - Apps by default are unable to use HTTP
Re: StarDict sends X11 clipboard to remote servers
#110> In response, Xiao pointed out that the package description can be read by any user who chooses to install the software, and it does mention the scan feature. Wouldn't be the first (or last) time a Debian maintainer has pulled the "you should read the descriptions of all (hundreds) of your packages (most installed as dependencies)" card in response to a bug report. If someone started reading all the package descript…
[flagged]