Live data from Hacker News

StarDict sends X11 clipboard to remote servers

lwn.net

281–290 of 350 posts

Re: StarDict sends X11 clipboard to remote servers

#281
post #28

Earlier quoted context omitted.

> My key has "Apartment Name, Apartment Number" engraved into the head Hotels learned not to do such silly things several decades ago. I'm surprised that your building management lacks such obvious wisdom.

It's been a real lifesaver, whenever a guest loses the guest key it just ends up back in my mailbox eventually. Also, like 80% of the hotels I've stayed at in the last year have the hotel name on the keycard, though admittedly they usually don't include the room number. The remaining 20% had physical keys with keychain fobs that had the room number and often hotel name (typically japanese ryokans do this)

Interesting. I might live in a lower-trust society than you do.

I'd greatly prefer to lose keys forever, anonymously, than to trust that a random human who is presented with a key and instructions for finding the lock it fits, will not be the sort to take advantage of the situation.

In the latter case, I'm changing my locks anyway, which is far more onerous than just making a new copy of the key.

Re: StarDict sends X11 clipboard to remote servers

#282

Earlier quoted context omitted.

I'm not going to fault you for that, but no, you really can not sign away your right-to-life even with assisted death. The process is explicitly tooled around this to ensure that people's rights are not violated. I am not saying that there will never be a mistake made here or even that that has not possibly already happened but in principle your right-to-life is not violated by this procedure, and I realize that I wi…

> you really can not sign away your right-to-life even with assisted death. The process is explicitly tooled around this to ensure that people's rights are not violated I’m saying that on a practical level the difference is unobservable. Part of your right to life, in this formulation, is your right to sign it away. The terminality of a right to life makes it a poor comparison to privacy, which has no comparably-irre…

> I’m saying that on a practical level the difference is unobservable.

To you.

Re: StarDict sends X11 clipboard to remote servers

#283

Earlier quoted context omitted.

> Part of the fun of free software is that it might do terrible things Yeah you lost me here

Freedom is the freedom to say rm -rf /* and accept the consequences. If you want to give someone else control over what you can and can't do with your machine, iOS is over there -->

False dichotomy.

Why should I expect that merely installing a dictionary will silently opt me in to sending everything in my clipboard to some third party?

You don't need some strawman tyrant to want it to require a user opt-in if that's what you really want to do

Re: StarDict sends X11 clipboard to remote servers

#284
Apple did something similar in 2015:

CVE-2015-3774

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3774

https://lists.apple.com/archives/security-announce/2015/Aug/...

You had to three-finger press to trigger it, though. Similarly, it used unencrypted HTTP. I reported it and it was fixed to use TLS.

The dev defending this unencrypted behavior is really wild, though.

Re: StarDict sends X11 clipboard to remote servers

#285

> of course a dictionary program will include code to talk to dictionary-providing web sites. I wouldn't say that is just a given, if I've apt-get installed a dictionary I might expect that is the whole thing on my machine. It's not like we haven't had dictionaries in physical books for centuries... It seems like stardict is very much an online thing, which I suppose could be legit, but the whole thing does seem like…

I's a generational thing. I would guess that someone who expects applications to phone home, on the off chance that they are actually otherwise local, is likely someone pretty young who hasn't lived in a world of locally installed software that doesn't talk to anything. If we search for the author's bio, that seems to check out. They are a well-credentialed CS person; obviously they know that dictionary programs such…

Dictionaries are small! It's insane to think that a dictionary requires network access. If it did, why would I install it locally??

> Today, an application being locally installed and works with offline data is like a a statement of quaint chivalry, promulgated by a few remaining Don Quixotes of computing.

But a dictionary package has no valid reason to be online.

Re: StarDict sends X11 clipboard to remote servers

#286

Earlier quoted context omitted.

For me it’s been about 25, but since this is the opening premise, and a throwback to the opening scene I think it’s probably one of the most memorable.

Ha, you might have better memory than me. From the opening of the books - I remember more vividly Arthur meeting Ford Prefect and his house being demolished. And vaguely something about a pub? So I think I remember the gist of the first chapter, but not the actual quotes :)

Oh, lucky you! You can read it again and discover all the fun twists for the second time. I envy you.

Re: StarDict sends X11 clipboard to remote servers

#287
post #270

Earlier quoted context omitted.

I disagree; it's basically lawyerspeak for "sucks to be you". If one is expected to go through all the documentation of both the main package and all dependency packages, and also through whatever specific configuration details to your case, just to be able to catch a specific IMPORTANT detail that's not clearly spelled out in the main package, that's malicious. "A dependency we use captures your clipboard data and s…

> That sentence right there would kill their userbase No, it wouldn't. People don't take privacy very seriously.

This is Debian, of course they do.

But it wouldn't kill their userbase because nobody reads the package descriptions anyway.

Re: StarDict sends X11 clipboard to remote servers

#288
Whatever is making plain HTTP requests in 2025 should be a cause of concern. Wouldn't it be nice to have a low resource daemon watching for common pitfalls alerting users so we eliminate or minimise classes of problems like this?

I think lots of windows antivirus come with features like this? Perhaps with vast crystalized kno eledge nowadays we can afford to create OSS system level package that offers some level of protection.

I might actually do it, any down side?

Re: StarDict sends X11 clipboard to remote servers

#290
post #101

Earlier quoted context omitted.

Hanlon's razor applies here, I think. It's just ignorance, not malice. I doubt the maintainer has connection, or was pressured by these two random dictionary websites to include this - nor do I think that they gain any advantage of it. People need to be on the lookout though, the xz incident showed that FOSS is indeed vulnerable.

I think Hanlon's razor is outdated. Plausible deniability is the new meta. On top of that, the maintainer seems intent on not fixing the problem.

Not only is it outdated, the Nolnah's razor (reverse form of Hanlon) is more likely to be true nowadays: "Never attribute to incompetence that which is adequately explained by malice".
Post reply on HN