Live data from Hacker News

StarDict sends X11 clipboard to remote servers

lwn.net

181–190 of 350 posts

Re: StarDict sends X11 clipboard to remote servers

#181
post #175

Earlier quoted context omitted.

[flagged]

The fix is to remove the package…

And to scan all of the other packages for phoning home without very explicitly informing the user about it and kicking them out if they don't.

Re: StarDict sends X11 clipboard to remote servers

#182
post #176
post #101

Earlier quoted context omitted.

I think Hanlon's razor is outdated. Plausible deniability is the new meta. On top of that, the maintainer seems intent on not fixing the problem.

Can the problem be fixed without making the software useless?

Sure. We've had dictionary software for decades.

This whole trend of adding a service to stuff that doesn't need a service is very annoying.

Re: StarDict sends X11 clipboard to remote servers

#183

Earlier quoted context omitted.

But it cannot be adequately attributed to ignorance, so no, Hanlon's razor does not apply. There is an obvious security breach.

I definitely consider it a security breach. But I do still think it's ignorance. Debian maintainers let it slide since 2009, so for at least 16 years now ( https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534731 ) - are they also malicious? I just think that not enough fucks were given.

It isn't rare at all for bugs to surface many years later and that doesn't mean whoever was responsible for maintenance to be malicious, it is if the bug was planted on purpose, and there are some examples of that (the xz library saga, for instance). Of course, you could argue that that too was incompetence but that's not how this works: lack of oversight by others does not imply malice on the part of those others for failure to catch the issue.

Stuff like this can fly under the radar for a long time because lots of people will assume how it works without actually verifying that it really works like that.

Re: StarDict sends X11 clipboard to remote servers

#184

Earlier quoted context omitted.

He could have claimed lack of awareness until it was brought up . After that that excuse no longer holds.

No they could still be just incompetent/negligent rather than malicious. You also forget that they aren't running the translation services, they don't get any data, that's a separate third party you'd have to believe are in on it too. The more important question is if debian is gonna gkick them for it (they should).

That's a separate third party, with which they can be in cahoots, in fact it may not be that they are 'in on it too', it could well be that they are in fact the originators and sponsors of the way this works. Anyway, regardless of who is the culprit it is clear that the response spells 'wont fix' and that translates (in my book at least, pun intended) into 'works as intended'.

Re: StarDict sends X11 clipboard to remote servers

#185
post #169

Earlier quoted context omitted.

Https everywhere is a good start, it keeps the other plebs at the coffee shop out of your business. But it's still open to anyone with enough power to coerce a CA, which is the more concerning sort of adversary anyhow. So yes, https everywhere, but let's not stop there.

Yes, but we have widely deployed efforts like certificate transparency, and cert pinning. The first makes such attacks widely known events, browsers report by default, and it s provable. It’s very rare. The second allows apps to only trust specific certs or CAs, ignoring system root of trust. I just want to clarify HTTPS in practice is quite secure.

I'll not let go of my distaste for roots of trust in any form, but you likely have a point. I'll have to learn more about this transparency thing.

Re: StarDict sends X11 clipboard to remote servers

#186
post #176
post #101

Earlier quoted context omitted.

I think Hanlon's razor is outdated. Plausible deniability is the new meta. On top of that, the maintainer seems intent on not fixing the problem.

Can the problem be fixed without making the software useless?

Absolutely. In my understanding and approach, it would need two smaller modifications:

1. making "scanning" (the clipboard capturing feature opt-in, with a huge notification for the implications

2. disabling the English-Chinese online translation plugin by default

Re: StarDict sends X11 clipboard to remote servers

#187

Earlier quoted context omitted.

I definitely consider it a security breach. But I do still think it's ignorance. Debian maintainers let it slide since 2009, so for at least 16 years now ( https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534731 ) - are they also malicious? I just think that not enough fucks were given.

It isn't rare at all for bugs to surface many years later and that doesn't mean whoever was responsible for maintenance to be malicious, it is if the bug was planted on purpose, and there are some examples of that (the xz library saga, for instance). Of course, you could argue that that too was incompetence but that's not how this works: lack of oversight by others does not imply malice on the part of those others fo…

I completely agree. Also, these people have a lot of other assignment, as I imagine. I, for one, have certainly let things slide in the past that ended up biting me, for whatever reason, malice not included.

Re: StarDict sends X11 clipboard to remote servers

#189
post #147

Earlier quoted context omitted.

For the uninformed: this is a quote from The Hitchhiker's Guide to the Galaxy.

[flagged]

I’ve read this book exactly once, in my second language (English), 20 something years ago. Guess that makes me worrisome.

Re: StarDict sends X11 clipboard to remote servers

#190

Somewhat related, I was quite surprised when I discovered that my Samsung phone was sharing ALL my clipboard with all my other Samsung devices, including passwords copied into the clipboard, and even preserving the history. I can't remember if the sharing was enabled by default or I opted in by accident. I assume it also goes through their servers to reach my other devices. I could disable the sharing, but still can'…

[flagged]
Post reply on HN