Live data from Hacker News

StarDict sends X11 clipboard to remote servers

lwn.net

241–250 of 350 posts

Re: StarDict sends X11 clipboard to remote servers

#241

Earlier quoted context omitted.

But it cannot be adequately attributed to ignorance, so no, Hanlon's razor does not apply. There is an obvious security breach.

I definitely consider it a security breach. But I do still think it's ignorance. Debian maintainers let it slide since 2009, so for at least 16 years now ( https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534731 ) - are they also malicious? I just think that not enough fucks were given.

It cannot be ignorance if they have been fully aware of this behaviour. As it stands, it's either maliciousness or negligence.

Re: StarDict sends X11 clipboard to remote servers

#242
post #130

Earlier quoted context omitted.

Such responses to me are proof of malicious intent.

There are dozens of chrome extensions that translate (read: submit to untrusted server) on hover / highlight / context menu / textarea edit / etc. It is implied, that user acknowledges this functionality and accepts the risk. This includes untrusted server (because that's how they proxy requests to Google/Bing/Yandex Translate without exposing API keys). Security illiteracy? Yes. Malicious intent? Probably no. Does b…

No reasonable person expects privacy when using Google and/or Google provided products / software.

When you use Debian, you have a reasonable expectation of privacy.

People who handwave that away or say it's not as bad as something else either have an agenda or are ignorant about the history of Debian.

Re: StarDict sends X11 clipboard to remote servers

#243

Earlier quoted context omitted.

No, you can't. Informed consent is (1) always going to be specific and (2) ends when the legal base for procession is no longer supported.

Struggling to see the relevance of both constraints when it comes to assisted death.

Please stop this sophistry. Assisted dying is in no way comparable to "signing away your right to life". Even if you want to reduce it to such black and white phrasing (which, quite frankly, makes you come across as an asshole), it's actually asserting ultimate control over your own life. At no point in that process are other people allowed to perform acts not specifically authorized by you.

Re: StarDict sends X11 clipboard to remote servers

#244

> of course a dictionary program will include code to talk to dictionary-providing web sites. I wouldn't say that is just a given, if I've apt-get installed a dictionary I might expect that is the whole thing on my machine. It's not like we haven't had dictionaries in physical books for centuries... It seems like stardict is very much an online thing, which I suppose could be legit, but the whole thing does seem like…

>> of course a dictionary program will include code to talk to dictionary-providing web sites.

Maybe to download a dictionary, but not to provide the same services that the dictionary program provides locally.

Re: StarDict sends X11 clipboard to remote servers

#245
Their reaction reminds me of when the Raspberry Pi Foundation tried gaslighting us.

RPi Foundation hires a cop and brags about how cop used RPis to spy on people. People got upset. RPi Foundation acts clueless and says vegetarians and vegans were upset because they posted a picture of meat.

Now Debian is less concerned with their core tenets and more concerned with winning popularity contests, as can be evidenced by their dropping of i386 support, for instance.

Instead of seeing an issue like this and raising an alarm, examining how this possibly happened, and discussing ways of making sure it doesn't happen again, they're like, "eh, so what?"

Debian, which for ages was the last big holdout of Linuxes becoming corporate, seems to have a bleak future.

Re: StarDict sends X11 clipboard to remote servers

#246

Earlier quoted context omitted.

While I think the response was not well thought out, it's still a far cry from "proof of malicious intent".

We can't afford that level of benefit of the doubt for the people that are supposed to guard us from exactly this kind of bs. Intent or not, that developer is a risk to the project.

Finally, a rational argument from the torch and pitchfork crowd. Xiao is not taking security sensitivities to heart : HTTP?? To China‽ and a dismissive BS answer.

Re: StarDict sends X11 clipboard to remote servers

#247

Earlier quoted context omitted.

> a password is worth something only to those who know what the password is for I also copy-paste my username from KeePass, so you'd pretty quickly get everything

[flagged]

> OK, so you have the username and password. But what about where to use the credentials? Is that also copy-pasted from somewhere?

At least keepassxc has IIRC a field for the website, and a button to copy it to the clipboard, right next to the buttons to copy the username and password. It's a great way to make sure you're opening the correct site, and not a typosquatted counterfeit.

Re: StarDict sends X11 clipboard to remote servers

#249
post #147

Earlier quoted context omitted.

For the uninformed: this is a quote from The Hitchhiker's Guide to the Galaxy.

[flagged]

Hitch hikers is by no means a universal cultural reference, and by the way it is 2025. The movie adaptation came out in 2005, 20 years ago. It's entirely possible for lots of people older than 20 to not get that reference.

Re: StarDict sends X11 clipboard to remote servers

#250
I don't understand why the whole thing isn't local. A comprehensive Chinese dictionary has less than 400k words. Even at 1k per word that's less than 400MB.

It's just poor design to make something require a network connection when it could work offline locally.

Post reply on HN