Live data from Hacker News

StarDict sends X11 clipboard to remote servers

lwn.net

141–150 of 350 posts

Re: StarDict sends X11 clipboard to remote servers

#141
post #101

Earlier quoted context omitted.

I think Hanlon's razor is outdated. Plausible deniability is the new meta. On top of that, the maintainer seems intent on not fixing the problem.

I think that in today's polarized world, it's very much needed. I think we need to look at each other's fallibilities and failures, and not hate each other for it. But the issue needs to be taken care of, especially since it's known since 2009. It's ridiculous that everyone let if fly for so long.

[flagged]

Re: StarDict sends X11 clipboard to remote servers

#142
The Wayland framing at the end strikes me as misleading. This gets it exactly right:

> Or maybe StarDict would have started asking for special permissions to let it work on Wayland, and users would have accepted those defaults the same way they currently do.

Yes, that’s what it would do. Its installer might even configure that special permission automatically, without user intervention.

Malware’s gonna mal. Wayland might help defend against some things, but it’s not going to defend against packages installed as part of the distro.

Re: StarDict sends X11 clipboard to remote servers

#143

Earlier quoted context omitted.

Malicious intent written in the package description? I would think that really unlikely. I think it's just a cultural difference. Sogou, a super popular Chinese input program for Windows iOS and Android does the same with everything you type and nobody cares.

I think so too. It's cultural difference, and ignorance at most. I doubt the maintainer has control over that two random dictionary websites, or was tasked by them to do this or anything like that. They are just a different person, and they didn't give a fuck.

[flagged]

Re: StarDict sends X11 clipboard to remote servers

#144
post #130

Earlier quoted context omitted.

Such responses to me are proof of malicious intent.

There are dozens of chrome extensions that translate (read: submit to untrusted server) on hover / highlight / context menu / textarea edit / etc. It is implied, that user acknowledges this functionality and accepts the risk. This includes untrusted server (because that's how they proxy requests to Google/Bing/Yandex Translate without exposing API keys). Security illiteracy? Yes. Malicious intent? Probably no. Does b…

A moderately popular Chrome extension is frequently bought for tens of thousands of dollars for various purposes, frequently malware injection. They contact extension makers.

I think the bar for trust in terms of evil intent is on the floor.

Re: StarDict sends X11 clipboard to remote servers

#146

While I have a lot of respect for the effort that goes into Debian, I always disliked this kind of "maximalism" from the package manager. Oh, the user wants "foo"? Let's install every software that might be even remotely useful somehow in combination with foo! Oh there is a network daemon in there? Fantastic, let's start it immediately! I know that there is a flag to disable the installation for "recommended" package…

This is a classic tension between convenience and security - Debian's "recommends" defaults were designed for a pre-cloud era when network connectivity wasn't assumed and local functionality was prioritized over potential security boundaries.

Re: StarDict sends X11 clipboard to remote servers

#147
post #78

Earlier quoted context omitted.

“the plans and the demolition orders have been on display at the local planning office on Alpha Centauri for fifty of your Earth years. If you can't be bothered to take an interest in local affairs...” https://www.youtube.com/watch?v=Z1Ba4BbH0oY

For the uninformed: this is a quote from The Hitchhiker's Guide to the Galaxy.

[flagged]

Re: StarDict sends X11 clipboard to remote servers

#148
post #93

Earlier quoted context omitted.

We're not going to agree on that. The response is clearly there to point to a fig leaf instead of saying 'oh, oops, we will make this more obvious in the UI', the software is working as intended: as a way to gain access to more data. Note that clipboard data can be just about anything and is a valuable dataset, more so if the source of the data isn't aware of being a source, besides, there is no history so you won't…

[flagged]

He could have claimed lack of awareness until it was brought up. After that that excuse no longer holds.

Re: StarDict sends X11 clipboard to remote servers

#149
post #2

There are numerous privacy issues in distros, some known, most probably unknown, some examples from Debian: https://wiki.debian.org/PrivacyIssues Luckily there are things like opensnitch that can block some of these issues: https://github.com/evilsocket/opensnitch

Your link is about privacy issues in upstream software that Debian hasn't sufficiently worked around yet . The main advantage of the Distro model (as opposed to developer-maintained package ecosystems) is exactly that there is someone protecting you from questionable software "features".

I don't think Debian intentionally shields you from privacy-invading software. Other distros may differ on this point.

Debian does not mandate anything about privacy in its Policy Manual (which are the standards for selecting and packaging software that maintainers must adhere to): https://www.debian.org/doc/debian-policy/search.html?q=priva...

There's also no insistence on privacy in the Debian Social Contract or DFSG (not that these would be appropriate places for it, they're mainly about licensing)

Re: StarDict sends X11 clipboard to remote servers

#150
post #78

Earlier quoted context omitted.

“the plans and the demolition orders have been on display at the local planning office on Alpha Centauri for fifty of your Earth years. If you can't be bothered to take an interest in local affairs...” https://www.youtube.com/watch?v=Z1Ba4BbH0oY

For the uninformed: this is a quote from The Hitchhiker's Guide to the Galaxy.

You mean, for those who couldn't be bothered to click the link under a joke.
Post reply on HN