Live data from Hacker News

StarDict sends X11 clipboard to remote servers

lwn.net

161–170 of 350 posts

Re: StarDict sends X11 clipboard to remote servers

#161
post #138

Earlier quoted context omitted.

I think that in today's polarized world, it's very much needed. I think we need to look at each other's fallibilities and failures, and not hate each other for it. But the issue needs to be taken care of, especially since it's known since 2009. It's ridiculous that everyone let if fly for so long.

Yes, but it is a tricky situation when a common tactic is to pretend to be ignorant. For example by "just asking questions". We need more patience and respect in this polarized world but at the same time there are a minority of malicious actors who intentionally abuse any assumption of good faith given

Yeah, I agree, it's tricky. And besides, the clipboard leak should be fixed for sure, malice or not. It's strange that it has been known for so long.

Re: StarDict sends X11 clipboard to remote servers

#162

> of course a dictionary program will include code to talk to dictionary-providing web sites. I wouldn't say that is just a given, if I've apt-get installed a dictionary I might expect that is the whole thing on my machine. It's not like we haven't had dictionaries in physical books for centuries... It seems like stardict is very much an online thing, which I suppose could be legit, but the whole thing does seem like…

The venerable ding does well with a local dictionary - and it's packaged in Debian too https://www-user.tu-chemnitz.de/~fri/ding/

But only english-german, sadly

Re: StarDict sends X11 clipboard to remote servers

#163
This article smacks of paternalism.

Part of the fun of free software is that it might do terrible things. Debian is not a distro that promises you a walled garden run by an iron-fisted tyrant who beats programmers into submission so they'll respect your privacy

Nothing in Debian will install StarDict invisibly. Only you install StarDict. Only you run StarDict.

Wayland is not a panacea. If you want StarDict to translate everything you highlight/clip, you will tell Wayland to let StarDict do that. If Wayland can't do that, it's bad, paternalistic software. There is Android and iOS for idiots who want to be bossed around by their device and have no real freedom.

The real problem are these HTTP lookups by default, which is the fault of the packager, and Debian as a whole for not prodding them into fixing it.

This bug was already reported and fixed as CVE-2009-2260. Then StarDict was kicked out of Debian, and when it came back, so did this bug. The most recent re-reporting of this bug (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806960 raised in 2015) was fixed a few days ago by removing the dict.cn plugin, 2 days after Vincent Lefevre raised this issue on oss-security-list. He also raised CVE-2025-55014 for another dictionary plugin that sends HTTP requests, which has also been fixed by removing that plugin.

Both plugins should be removed from Trixie as of today, and more appropriately, all the "network dictionaries" are now in their own package (stardict-plugin-network-dictionary), not installed by default (stardict-plugin suggests rather than recommends it):

Changelog: https://salsa.debian.org/debian/stardict/-/blob/debian/trixi...

    stardict (3.0.7+git20220909+dfsg-8) unstable; urgency=medium
      * remove stardict_youdaodict.so plugin from stardict-plugin package, Closes: #1110370
      * split network-dictionary plugin to a new binary package stardict-plugin-network-dictionary
      * add d/NEWS.Debian
     -- xiao sheng wen   Mon, 11 Aug 2025 10:46:11 +0800
    stardict (3.0.7+git20220909+dfsg-7) unstable; urgency=medium
      * d/stardict-plugin.install:not install stardict_dictdotcn.so, Closes: #806960
      * d/rules:Added --disable-dictdotcn option, dictdotcn is not provid server now
     -- xiao sheng wen   Wed, 06 Aug 2025 14:09:39 +0800

Control: https://salsa.debian.org/debian/stardict/-/blob/debian/trixi...

    Package: stardict-plugin-network-dictionary
    Description: [...]
     *Warning*
      * The query word will send through the network use plain-text in this plugin!
      * Please do *NOT* selects any confidential data to query dictionary
      * When enable "Scan" function on stardict, the selected text will sended on the net at once.

    Package: stardict-plugin
    Suggests: [...]
     stardict-plugin-network-dictionary (= ${binary:Version}),

Re: StarDict sends X11 clipboard to remote servers

#164

Earlier quoted context omitted.

Why? Should it use the dict protocol, then?

Because without HTTPS it's trivial to MITM that clipboard content if they're always sending it via http. People in your coffee shop on the same WiFi could read it. I get some people don't realize that's how TCP/IP works and the firesheep stuff all happened 15 years ago. But a bit worrying to see a frequent HN contributor challenging that. That's why we now push for Https everywhere.

Https everywhere is a good start, it keeps the other plebs at the coffee shop out of your business. But it's still open to anyone with enough power to coerce a CA, which is the more concerning sort of adversary anyhow. So yes, https everywhere, but let's not stop there.

Re: StarDict sends X11 clipboard to remote servers

#165

Earlier quoted context omitted.

For the uninformed: this is a quote from The Hitchhiker's Guide to the Galaxy.

You mean, for those who couldn't be bothered to click the link under a joke.

I understood the reference, but I’m also on a limited mobile plan at the moment and would absolutely not click on a YT or similar link.

In other words might have appreciated the explanation.

Re: StarDict sends X11 clipboard to remote servers

#166

Somewhat related, I was quite surprised when I discovered that my Samsung phone was sharing ALL my clipboard with all my other Samsung devices, including passwords copied into the clipboard, and even preserving the history. I can't remember if the sharing was enabled by default or I opted in by accident. I assume it also goes through their servers to reach my other devices. I could disable the sharing, but still can'…

Yes, and we know at least Samsung TVs sell your details and what you watch to marketers and everyone.

Samsung’s privacy policy is the same for phones and TVs.

Re: StarDict sends X11 clipboard to remote servers

#167
post #130

Earlier quoted context omitted.

There are dozens of chrome extensions that translate (read: submit to untrusted server) on hover / highlight / context menu / textarea edit / etc. It is implied, that user acknowledges this functionality and accepts the risk. This includes untrusted server (because that's how they proxy requests to Google/Bing/Yandex Translate without exposing API keys). Security illiteracy? Yes. Malicious intent? Probably no. Does b…

[flagged]

Illiterate is "inability to read and write" by definition. I know people who submitted bug reports requesting: "hi, I want to use your API, please add wildcard origin header", after getting explanation they propose "ok, JUST add my domain, I'm an opensource contributor, trust me". They ask to remove security features, recognizing them as security features, but only caring about their convenience (like "don't enforce 2fa", "don't warn about untrusted links"). They don't know about defense in depth and even if you explain them, they will skip your explanation, because they can't read.

Re: StarDict sends X11 clipboard to remote servers

#168
post #103

Earlier quoted context omitted.

Such responses to me are proof of malicious intent.

Such a response is not considered a valid defence under GDPR. You cannot sign away your right to privacy any more than you can sign away your right to life.

> You cannot sign away your right to privacy any more than you can sign away your right to life

You can literally do both in the EU with informed consent.

Re: StarDict sends X11 clipboard to remote servers

#169

Earlier quoted context omitted.

Because without HTTPS it's trivial to MITM that clipboard content if they're always sending it via http. People in your coffee shop on the same WiFi could read it. I get some people don't realize that's how TCP/IP works and the firesheep stuff all happened 15 years ago. But a bit worrying to see a frequent HN contributor challenging that. That's why we now push for Https everywhere.

Https everywhere is a good start, it keeps the other plebs at the coffee shop out of your business. But it's still open to anyone with enough power to coerce a CA, which is the more concerning sort of adversary anyhow. So yes, https everywhere, but let's not stop there.

Yes, but we have widely deployed efforts like certificate transparency, and cert pinning.

The first makes such attacks widely known events, browsers report by default, and it s provable. It’s very rare.

The second allows apps to only trust specific certs or CAs, ignoring system root of trust.

I just want to clarify HTTPS in practice is quite secure.

Re: StarDict sends X11 clipboard to remote servers

#170

Earlier quoted context omitted.

Such responses to me are proof of malicious intent.

While I think the response was not well thought out, it's still a far cry from "proof of malicious intent".

> it's still a far cry from "proof of malicious intent"

Is the difference meaningful? It’s proof of a value set so different from the community’s as to merit the same response: expulsion.

Post reply on HN