Live data from Hacker News

StarDict sends X11 clipboard to remote servers

lwn.net

271–280 of 350 posts

Re: StarDict sends X11 clipboard to remote servers

#271

Earlier quoted context omitted.

Such responses to me are proof of malicious intent.

i agree. if in 2025 ppl dont understand plaintext of user data to places on the net is bad, they should not write code nor be maintainers of oss software -_-. how many times does everyone need to be totally compromised by some shitty software before people start to care? innocent individuals each days are suffering hacks and malicious interactions. people are losing their livelihoods. companies are getting shutdown..…

> i agree. if in 2025 ppl dont understand plaintext of user data to places on the net is bad, they should not write code nor be maintainers of oss software -_-.

LLMs are only going to make this worse. We're going to see a plethora of vibe coded slop everywhere.

Re: StarDict sends X11 clipboard to remote servers

#272

This article smacks of paternalism. Part of the fun of free software is that it might do terrible things. Debian is not a distro that promises you a walled garden run by an iron-fisted tyrant who beats programmers into submission so they'll respect your privacy Nothing in Debian will install StarDict invisibly. Only you install StarDict. Only you run StarDict. Wayland is not a panacea. If you want StarDict to transla…

> Part of the fun of free software is that it might do terrible things

Yeah you lost me here

Re: StarDict sends X11 clipboard to remote servers

#273
post #147

Earlier quoted context omitted.

For the uninformed: this is a quote from The Hitchhiker's Guide to the Galaxy.

[flagged]

Is the Hitchhiker's guide to the Galaxy still part of the geek culture for people in their twenties?

I still think 42 is pretty well known, but it doesn't mean people have actually read the books and recognize that part.

Re: StarDict sends X11 clipboard to remote servers

#274

Earlier quoted context omitted.

Your link is about privacy issues in upstream software that Debian hasn't sufficiently worked around yet . The main advantage of the Distro model (as opposed to developer-maintained package ecosystems) is exactly that there is someone protecting you from questionable software "features".

I don't think Debian intentionally shields you from privacy-invading software. Other distros may differ on this point. Debian does not mandate anything about privacy in its Policy Manual (which are the standards for selecting and packaging software that maintainers must adhere to): https://www.debian.org/doc/debian-policy/search.html?q=priva... There's also no insistence on privacy in the Debian Social Contract or DF…

> I don't think Debian intentionally shields you from privacy-invading software.

Don't they change the Firefox defaults for more privacy?

Re: StarDict sends X11 clipboard to remote servers

#275

Earlier quoted context omitted.

>The software could just as well hook into your downloads folder correct which is why wayland is only one piece in improving security, you still need proper sandboxing

By the time you have something that allows you to safety run malware you have a usability nightmare.

Qubes OS is the solution. It's indeed less convenient than ordinary GNU/Linux but still quite usable. My daily driver, can't recommend it enough.

Re: StarDict sends X11 clipboard to remote servers

#276

Earlier quoted context omitted.

That simply makes them one of today's lucky 10,000 https://xkcd.com/1053/

Lots of people are outside of the US

The Hitchhiker's Guide to the Galaxy is British.

Also, I know it, it has been translated in my language (French), the movie made out to the theaters, and we even have a well known school named after it (42). So it is known even to non-English speakers.

Re: StarDict sends X11 clipboard to remote servers

#277

This article smacks of paternalism. Part of the fun of free software is that it might do terrible things. Debian is not a distro that promises you a walled garden run by an iron-fisted tyrant who beats programmers into submission so they'll respect your privacy Nothing in Debian will install StarDict invisibly. Only you install StarDict. Only you run StarDict. Wayland is not a panacea. If you want StarDict to transla…

> Part of the fun of free software is that it might do terrible things Yeah you lost me here

Freedom is the freedom to say rm -rf /* and accept the consequences.

If you want to give someone else control over what you can and can't do with your machine, iOS is over there -->

Re: StarDict sends X11 clipboard to remote servers

#278
post #270

Earlier quoted context omitted.

I disagree; it's basically lawyerspeak for "sucks to be you". If one is expected to go through all the documentation of both the main package and all dependency packages, and also through whatever specific configuration details to your case, just to be able to catch a specific IMPORTANT detail that's not clearly spelled out in the main package, that's malicious. "A dependency we use captures your clipboard data and s…

> That sentence right there would kill their userbase No, it wouldn't. People don't take privacy very seriously.

If this were about a Windows or MacOS program, sure.

The overlap between Linux desktop users and digital privacy concerns is pretty large.

Re: StarDict sends X11 clipboard to remote servers

#279

Earlier quoted context omitted.

>The software could just as well hook into your downloads folder correct which is why wayland is only one piece in improving security, you still need proper sandboxing

By the time you have something that allows you to safety run malware you have a usability nightmare.

Flatpak'd wayland applications are super usable and they prevent the clipboard spying and the download folder shenanigans. You can edit permissions straight from KDE settings.

Of course, you can't safety just run malware in flatpak.

Re: StarDict sends X11 clipboard to remote servers

#280
post #179

In my Windows, it wouldn't be a problem. The firewall I use would pop up for any new program that tries to connect somewhere. But Linux doesn't have a per-program firewall. ... and even if it did, there's no way to do popups/questions from the kernel, ... and even if there was, most programs would just run curl or wget or openssl. That would mean a popup for each and every connection attempt through those programs.

Opensnitch is really good on Linux
Post reply on HN