StarDict sends X11 clipboard to remote servers
291–300 of 350 posts
Re: StarDict sends X11 clipboard to remote servers
#292Apple did something similar in 2015: CVE-2015-3774 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3774 https://lists.apple.com/archives/security-announce/2015/Aug/... You had to three-finger press to trigger it, though. Similarly, it used unencrypted HTTP. I reported it and it was fixed to use TLS. The dev defending this unencrypted behavior is really wild, though.
Re: StarDict sends X11 clipboard to remote servers
#293Earlier quoted context omitted.
For the uninformed: this is a quote from The Hitchhiker's Guide to the Galaxy.
[flagged]
Be it a minor SciFi flick in a written form or some SciFi flick in a live-action form[0]
FYI HHTG is big[1] in anglosphere and known mostly to SciFi enthusiasts in other parts of the world.
[0] https://news.ycombinator.com/item?id=44287254
[1] as big as you want, of course
Re: StarDict sends X11 clipboard to remote servers
#294Earlier quoted context omitted.
Such responses to me are proof of malicious intent.
While I think the response was not well thought out, it's still a far cry from "proof of malicious intent".
It could be that they were caught with their pants down and posted an ill-thought response, but I'd lean strongly towards malice with such a poor defense, it borders on confession. Clipboards are one of the most critical privacy/security features, you don't ever want to leak them unintentionally.
Did we already forget about the XZ Utils backdoor? There have to be multiple efforts to infiltrate backdoors in Linux going right now.
Re: StarDict sends X11 clipboard to remote servers
#295Earlier quoted context omitted.
I think Hanlon's razor is outdated. Plausible deniability is the new meta. On top of that, the maintainer seems intent on not fixing the problem.
Not only is it outdated, the Nolnah's razor (reverse form of Hanlon) is more likely to be true nowadays: "Never attribute to incompetence that which is adequately explained by malice".
Re: StarDict sends X11 clipboard to remote servers
#296Earlier quoted context omitted.
> pressured Maybe incentivized? $1000? $10000? Would be interesting to hear from the developer himself.
>nor do I think that they gain any advantage of it
We truly live in an utopia!
Re: StarDict sends X11 clipboard to remote servers
#297Earlier quoted context omitted.
I think Hanlon's razor is outdated. Plausible deniability is the new meta. On top of that, the maintainer seems intent on not fixing the problem.
Not only is it outdated, the Nolnah's razor (reverse form of Hanlon) is more likely to be true nowadays: "Never attribute to incompetence that which is adequately explained by malice".
Yeah this is the world we now live in.
Re: StarDict sends X11 clipboard to remote servers
#298I don't understand why the whole thing isn't local. A comprehensive Chinese dictionary has less than 400k words. Even at 1k per word that's less than 400MB. It's just poor design to make something require a network connection when it could work offline locally.
Re: StarDict sends X11 clipboard to remote servers
#299Re: StarDict sends X11 clipboard to remote servers
#300Can someone recommend a completely local English-language dictionary for Debian?
For my use case I was more interested in the data than the application and so never installed it and am unable to comment on how usable it is, but will include a link if you want to look. https://sourceforge.net/projects/artha/