Live data from Hacker News

StarDict sends X11 clipboard to remote servers

lwn.net

331–340 of 350 posts

Re: StarDict sends X11 clipboard to remote servers

#331

Somewhat related, I was quite surprised when I discovered that my Samsung phone was sharing ALL my clipboard with all my other Samsung devices, including passwords copied into the clipboard, and even preserving the history. I can't remember if the sharing was enabled by default or I opted in by accident. I assume it also goes through their servers to reach my other devices. I could disable the sharing, but still can'…

I noticed this happening through KDE connect, where passwords copied on Linux show up in Android's clipboard history, is there a way to block passwords from being transported around like that without completely disabling clipboard sharing altogether?

You might want to disable KDE's clipboard history too btw, or at least find a solution that doesn't involve copying passwords. Either use the selection instead of the clipboard, or use password filling through non-clipboard channels.

Re: StarDict sends X11 clipboard to remote servers

#332
post #37

it looks like a serious "privacy violation" for English-only users. But for many ESL or non-English users out there, the "translation" is a must. On Windoes, I remember some translation programs go extreme, they hijack all GDI calls and scan for all strings on GUIs trying to translate and replace them inline. Local dictionary were pretty limited so many of them use online services. What happens when user input someth…

English-only users need translation too, there are lots of web resources out there only in non-English languages. I found the Bergamot offline translation tool embedded into Firefox helps a lot for that these days.

Re: StarDict sends X11 clipboard to remote servers

#334
post #236

Earlier quoted context omitted.

Does this service exist?

Does it matter? Will the existence or lack thereof excuse the absolute lack of security and privacy this package exhibits? And the lack of interest from the developer?

Yes it matters. Something that doesn't exist cannot be used. Any other insightful comment you wish to make?

Re: StarDict sends X11 clipboard to remote servers

#336

Earlier quoted context omitted.

> --break-system-packages You can avoid that clusterfuck using `uv tool install`. E.g. `uv tool install pre-commit`.

It's also not hard to just manage a damn virtual environment yourself.

That doesn't really work for tools that you want to be available everywhere.

Re: StarDict sends X11 clipboard to remote servers

#338
post #139

Earlier quoted context omitted.

For many languages, there simply isn't a comprehensive dictionary file that could be redistributed legally as part of a free-software offline dictionary application. You either settle for a few thousand words put together by a handful of volunteers, or you redistribute a commercial dictionary illegally, or you have to connect to an online service to provide sufficient coverage legally.

Wiktionary is massive with 1.4M English entries [1] (3x the size of the Merriam Webster's Unabridged dictionary [2], though with a lower average quality), and CC-BY-SA-licensed[3] [1]: https://en.wiktionary.org/wiki/Wiktionary:Statistics [2]: https://www.merriam-webster.com/help/faq-how-many-english-wo... [3]: https://en.wiktionary.org/wiki/Wiktionary:Copyrights

Yes, the abundance of English data is why I felt the need to point out that this isn't the case for other languages. (Also, the raw count from Wiktionary can be misleading if you don't take into account that there are many low-effort entries for different forms of the same word.)

Re: StarDict sends X11 clipboard to remote servers

#339

Earlier quoted context omitted.

You're asking Debian to check out all aspects of a program and hold them liable if it does something you don't like, or their volunteers does something you don't like. That's not what Debian is doing. Debian is asking for volunteers to package the world's free software, also written by volunteers. They have their own checklists, your "dodgy behaviour" concerns aren't on it. Confirming the software meets your expectat…

They did. The article exists. The package manager behavior was changed accordingly. It doesn't automatically include that plug-in. My understanding was you scoffed at the "paternalism" and said part of the fun is that there might be terrible behaviors. Others disagree.

Indeed there were terrible behaviours, and they were fixed. My scoffing is at people who believe these behaviours should never have happened, or it shouldn't be possible.

Unless there is a omnipotent tyrant, there will be the possibility that you encounter terrible behaviours, and the possibility that those who could fix them, don't. You can try advocating to the maintainer that they should fix it, you can even try leading a campaign against the maintainer. If they still disagree, you can fix it yourself, with the source they gave you, and you can publicise your fixed version, which people might adopt over the other version if enough people agree with you. That is the fun!

Re: StarDict sends X11 clipboard to remote servers

#340

Earlier quoted context omitted.

[flagged]

I use a unique email address with the + format for each service, like "me+kagi@email.com". Login with email reveals the service through the address. And yes, I too usually copy-paste both the username and the password, one right after the other. I have often thought that it seems very risky, but good to learn that Wayland already prevents clipboard sniffing.

The reason copy+pasting is risky is it builds a habit where you're vulnerable to phishing sites.

Use the browser extension for your password manager, it auto-fills based on URL, so if you're on "kagii.com", it won't auto-fill and you'll notice something is off, but if you're on "kagi.com" it will.

Auto-filling vs copy+pasting is a security feature.

Post reply on HN