Earlier quoted context omitted.
I think that in today's polarized world, it's very much needed. I think we need to look at each other's fallibilities and failures, and not hate each other for it. But the issue needs to be taken care of, especially since it's known since 2009. It's ridiculous that everyone let if fly for so long.
Yes, but it is a tricky situation when a common tactic is to pretend to be ignorant. For example by "just asking questions". We need more patience and respect in this polarized world but at the same time there are a minority of malicious actors who intentionally abuse any assumption of good faith given
StarDict sends X11 clipboard to remote servers
161–170 of 350 posts
Re: StarDict sends X11 clipboard to remote servers
#162> of course a dictionary program will include code to talk to dictionary-providing web sites. I wouldn't say that is just a given, if I've apt-get installed a dictionary I might expect that is the whole thing on my machine. It's not like we haven't had dictionaries in physical books for centuries... It seems like stardict is very much an online thing, which I suppose could be legit, but the whole thing does seem like…
The venerable ding does well with a local dictionary - and it's packaged in Debian too https://www-user.tu-chemnitz.de/~fri/ding/
Re: StarDict sends X11 clipboard to remote servers
#163Part of the fun of free software is that it might do terrible things. Debian is not a distro that promises you a walled garden run by an iron-fisted tyrant who beats programmers into submission so they'll respect your privacy
Nothing in Debian will install StarDict invisibly. Only you install StarDict. Only you run StarDict.
Wayland is not a panacea. If you want StarDict to translate everything you highlight/clip, you will tell Wayland to let StarDict do that. If Wayland can't do that, it's bad, paternalistic software. There is Android and iOS for idiots who want to be bossed around by their device and have no real freedom.
The real problem are these HTTP lookups by default, which is the fault of the packager, and Debian as a whole for not prodding them into fixing it.
This bug was already reported and fixed as CVE-2009-2260. Then StarDict was kicked out of Debian, and when it came back, so did this bug. The most recent re-reporting of this bug (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806960 raised in 2015) was fixed a few days ago by removing the dict.cn plugin, 2 days after Vincent Lefevre raised this issue on oss-security-list. He also raised CVE-2025-55014 for another dictionary plugin that sends HTTP requests, which has also been fixed by removing that plugin.
Both plugins should be removed from Trixie as of today, and more appropriately, all the "network dictionaries" are now in their own package (stardict-plugin-network-dictionary), not installed by default (stardict-plugin suggests rather than recommends it):
Changelog: https://salsa.debian.org/debian/stardict/-/blob/debian/trixi...
stardict (3.0.7+git20220909+dfsg-8) unstable; urgency=medium
* remove stardict_youdaodict.so plugin from stardict-plugin package, Closes: #1110370
* split network-dictionary plugin to a new binary package stardict-plugin-network-dictionary
* add d/NEWS.Debian
-- xiao sheng wen Mon, 11 Aug 2025 10:46:11 +0800
stardict (3.0.7+git20220909+dfsg-7) unstable; urgency=medium
* d/stardict-plugin.install:not install stardict_dictdotcn.so, Closes: #806960
* d/rules:Added --disable-dictdotcn option, dictdotcn is not provid server now
-- xiao sheng wen Wed, 06 Aug 2025 14:09:39 +0800
Control: https://salsa.debian.org/debian/stardict/-/blob/debian/trixi... Package: stardict-plugin-network-dictionary
Description: [...]
*Warning*
* The query word will send through the network use plain-text in this plugin!
* Please do *NOT* selects any confidential data to query dictionary
* When enable "Scan" function on stardict, the selected text will sended on the net at once.
Package: stardict-plugin
Suggests: [...]
stardict-plugin-network-dictionary (= ${binary:Version}),Re: StarDict sends X11 clipboard to remote servers
#164Earlier quoted context omitted.
Why? Should it use the dict protocol, then?
Because without HTTPS it's trivial to MITM that clipboard content if they're always sending it via http. People in your coffee shop on the same WiFi could read it. I get some people don't realize that's how TCP/IP works and the firesheep stuff all happened 15 years ago. But a bit worrying to see a frequent HN contributor challenging that. That's why we now push for Https everywhere.
Re: StarDict sends X11 clipboard to remote servers
#165Earlier quoted context omitted.
For the uninformed: this is a quote from The Hitchhiker's Guide to the Galaxy.
You mean, for those who couldn't be bothered to click the link under a joke.
In other words might have appreciated the explanation.
Re: StarDict sends X11 clipboard to remote servers
#166Somewhat related, I was quite surprised when I discovered that my Samsung phone was sharing ALL my clipboard with all my other Samsung devices, including passwords copied into the clipboard, and even preserving the history. I can't remember if the sharing was enabled by default or I opted in by accident. I assume it also goes through their servers to reach my other devices. I could disable the sharing, but still can'…
Samsung’s privacy policy is the same for phones and TVs.
Re: StarDict sends X11 clipboard to remote servers
#167Earlier quoted context omitted.
There are dozens of chrome extensions that translate (read: submit to untrusted server) on hover / highlight / context menu / textarea edit / etc. It is implied, that user acknowledges this functionality and accepts the risk. This includes untrusted server (because that's how they proxy requests to Google/Bing/Yandex Translate without exposing API keys). Security illiteracy? Yes. Malicious intent? Probably no. Does b…
[flagged]
Re: StarDict sends X11 clipboard to remote servers
#168Earlier quoted context omitted.
Such responses to me are proof of malicious intent.
Such a response is not considered a valid defence under GDPR. You cannot sign away your right to privacy any more than you can sign away your right to life.
You can literally do both in the EU with informed consent.
Re: StarDict sends X11 clipboard to remote servers
#169Earlier quoted context omitted.
Because without HTTPS it's trivial to MITM that clipboard content if they're always sending it via http. People in your coffee shop on the same WiFi could read it. I get some people don't realize that's how TCP/IP works and the firesheep stuff all happened 15 years ago. But a bit worrying to see a frequent HN contributor challenging that. That's why we now push for Https everywhere.
Https everywhere is a good start, it keeps the other plebs at the coffee shop out of your business. But it's still open to anyone with enough power to coerce a CA, which is the more concerning sort of adversary anyhow. So yes, https everywhere, but let's not stop there.
The first makes such attacks widely known events, browsers report by default, and it s provable. It’s very rare.
The second allows apps to only trust specific certs or CAs, ignoring system root of trust.
I just want to clarify HTTPS in practice is quite secure.
Re: StarDict sends X11 clipboard to remote servers
#170Earlier quoted context omitted.
Such responses to me are proof of malicious intent.
While I think the response was not well thought out, it's still a far cry from "proof of malicious intent".
Is the difference meaningful? It’s proof of a value set so different from the community’s as to merit the same response: expulsion.