Earlier quoted context omitted.
But it cannot be adequately attributed to ignorance, so no, Hanlon's razor does not apply. There is an obvious security breach.
I definitely consider it a security breach. But I do still think it's ignorance. Debian maintainers let it slide since 2009, so for at least 16 years now ( https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534731 ) - are they also malicious? I just think that not enough fucks were given.
StarDict sends X11 clipboard to remote servers
241–250 of 350 posts
Re: StarDict sends X11 clipboard to remote servers
#242Earlier quoted context omitted.
Such responses to me are proof of malicious intent.
There are dozens of chrome extensions that translate (read: submit to untrusted server) on hover / highlight / context menu / textarea edit / etc. It is implied, that user acknowledges this functionality and accepts the risk. This includes untrusted server (because that's how they proxy requests to Google/Bing/Yandex Translate without exposing API keys). Security illiteracy? Yes. Malicious intent? Probably no. Does b…
When you use Debian, you have a reasonable expectation of privacy.
People who handwave that away or say it's not as bad as something else either have an agenda or are ignorant about the history of Debian.
Re: StarDict sends X11 clipboard to remote servers
#243Earlier quoted context omitted.
No, you can't. Informed consent is (1) always going to be specific and (2) ends when the legal base for procession is no longer supported.
Struggling to see the relevance of both constraints when it comes to assisted death.
Re: StarDict sends X11 clipboard to remote servers
#244> of course a dictionary program will include code to talk to dictionary-providing web sites. I wouldn't say that is just a given, if I've apt-get installed a dictionary I might expect that is the whole thing on my machine. It's not like we haven't had dictionaries in physical books for centuries... It seems like stardict is very much an online thing, which I suppose could be legit, but the whole thing does seem like…
Maybe to download a dictionary, but not to provide the same services that the dictionary program provides locally.
Re: StarDict sends X11 clipboard to remote servers
#245RPi Foundation hires a cop and brags about how cop used RPis to spy on people. People got upset. RPi Foundation acts clueless and says vegetarians and vegans were upset because they posted a picture of meat.
Now Debian is less concerned with their core tenets and more concerned with winning popularity contests, as can be evidenced by their dropping of i386 support, for instance.
Instead of seeing an issue like this and raising an alarm, examining how this possibly happened, and discussing ways of making sure it doesn't happen again, they're like, "eh, so what?"
Debian, which for ages was the last big holdout of Linuxes becoming corporate, seems to have a bleak future.
Re: StarDict sends X11 clipboard to remote servers
#246Earlier quoted context omitted.
While I think the response was not well thought out, it's still a far cry from "proof of malicious intent".
We can't afford that level of benefit of the doubt for the people that are supposed to guard us from exactly this kind of bs. Intent or not, that developer is a risk to the project.
Re: StarDict sends X11 clipboard to remote servers
#247Earlier quoted context omitted.
> a password is worth something only to those who know what the password is for I also copy-paste my username from KeePass, so you'd pretty quickly get everything
[flagged]
At least keepassxc has IIRC a field for the website, and a button to copy it to the clipboard, right next to the buttons to copy the username and password. It's a great way to make sure you're opening the correct site, and not a typosquatted counterfeit.
Re: StarDict sends X11 clipboard to remote servers
#248Re: StarDict sends X11 clipboard to remote servers
#249Earlier quoted context omitted.
For the uninformed: this is a quote from The Hitchhiker's Guide to the Galaxy.
[flagged]
Re: StarDict sends X11 clipboard to remote servers
#250It's just poor design to make something require a network connection when it could work offline locally.