Live data from Hacker News

StarDict sends X11 clipboard to remote servers

lwn.net

41–50 of 350 posts

Re: StarDict sends X11 clipboard to remote servers

#41

Earlier quoted context omitted.

> a password is worth something only to those who know what the password is for I also copy-paste my username from KeePass, so you'd pretty quickly get everything

[flagged]

I use a unique email address with the + format for each service, like "me+kagi@email.com". Login with email reveals the service through the address.

And yes, I too usually copy-paste both the username and the password, one right after the other. I have often thought that it seems very risky, but good to learn that Wayland already prevents clipboard sniffing.

Re: StarDict sends X11 clipboard to remote servers

#43
post #14

Earlier quoted context omitted.

Meanwhile on Wayland: > StarDict on Wayland doesn't have this problem, because Wayland prevents applications from being able to capture text from other applications by default.

You are cherry picking. The next statement says that the scan feature doesn't even work on wayland. Lol. That's worse than working + buggy. (security bugs are just bugs. Nothing special about them) > That does mean that it breaks StarDict's scan feature, though.

No, Wayland is clearly better here. Not allowing an app to do a potentially stupid privacy compromising thing is better that allowing it by default and providing no way to block it.

Better does not necessarily mean good though, that Mac approach of block by default but allow users to enable these things for specific apps on settings would be a great improvement.

Re: StarDict sends X11 clipboard to remote servers

#44

> In response, Xiao pointed out that the package description can be read by any user who chooses to install the software, and it does mention the scan feature. Wouldn't be the first (or last) time a Debian maintainer has pulled the "you should read the descriptions of all (hundreds) of your packages (most installed as dependencies)" card in response to a bug report. If someone started reading all the package descript…

Such responses to me are proof of malicious intent.

While I think the response was not well thought out, it's still a far cry from "proof of malicious intent".

Re: StarDict sends X11 clipboard to remote servers

#45
post #19

Meanwhile on Android: - The clipboard can not be read by backgrounded applications - Apps by default are unable to use HTTP

Which Android versions ask for permission before an app can make HTTP requests? I know it's something the app has to declare in the manifest, but other than obscure ROMs every normal version of Android just allows network usage without asking the user.

Android itself doesn't enforce it, but starting with Android 9, you have to opt in to HTTP requests rather than opt out. Most app developers don't even know about this so their applications (and the ads packaged within) cannot do plaintext HTTP calls using the normal system API.

Still doesn't prevent an ad library from bundling libcurl and doing HTTP calls manually, of course, but it's a sane default.

Re: StarDict sends X11 clipboard to remote servers

#46

> In response, Xiao pointed out that the package description can be read by any user who chooses to install the software, and it does mention the scan feature. Wouldn't be the first (or last) time a Debian maintainer has pulled the "you should read the descriptions of all (hundreds) of your packages (most installed as dependencies)" card in response to a bug report. If someone started reading all the package descript…

Such responses to me are proof of malicious intent.

Malicious intent written in the package description? I would think that really unlikely.

I think it's just a cultural difference. Sogou, a super popular Chinese input program for Windows iOS and Android does the same with everything you type and nobody cares.

Re: StarDict sends X11 clipboard to remote servers

#47

Earlier quoted context omitted.

I'll politely disagree. First of all, "Recommends" is reserved for packages which enhance the functionality of the package you're installing. Without these the package will not break, but some very useful functionality might be disabled. The package-class you're talking about is "suggests", IOW, "these packages might also be useful for you, wanna look?" section. These are not installed by default already. On the othe…

Well, as a user of one of the more "IKEAesque" distros, I guess I have made my choice ;) And that's perfectly fine, it just means I don't align with Debian on this one. And that freedom is what Linux is all about, I guess. So it seems it's working as intended :) Edit: And I totally get that users might often want that kind of maximalism. It's just not for me. Although starting network daemons by default might sometim…

While I'll argue that Debian's network daemons come with very sane defaults and an accompanying AppArmor profile to prevent both network disruptions and attack surface increases, I'm certainly not with the developer of StarDict. That thing smells malicious.

...and this is what Debian Testing is actually for. To catch these types of issues.

Of course, people are free to select what they resonates with them. I'm not against more DIY distributions (I'm also contemplating using a LFS VM to explore things even further, but time is an issue), and I'm not against your personal choices. I just wanted to note the tension, and share my observations about Debian.

Re: StarDict sends X11 clipboard to remote servers

#48

> In response, Xiao pointed out that the package description can be read by any user who chooses to install the software, and it does mention the scan feature. Wouldn't be the first (or last) time a Debian maintainer has pulled the "you should read the descriptions of all (hundreds) of your packages (most installed as dependencies)" card in response to a bug report. If someone started reading all the package descript…

[flagged]

Re: StarDict sends X11 clipboard to remote servers

#49

> In response, Xiao pointed out that the package description can be read by any user who chooses to install the software, and it does mention the scan feature. Wouldn't be the first (or last) time a Debian maintainer has pulled the "you should read the descriptions of all (hundreds) of your packages (most installed as dependencies)" card in response to a bug report. If someone started reading all the package descript…

[flagged]

You're fired!

Re: StarDict sends X11 clipboard to remote servers

#50
> StarDict on Wayland doesn't have this problem, because Wayland prevents applications from being able to capture text from other applications by default.

StarDict on Wayland has a different issue, it causes a segfault.

Sat, 02 Aug 2025: Bug#1003710: stardict crash in gnome with message Segmentation fault

https://www.mail-archive.com/debian-bugs-dist@lists.debian.o...

Post reply on HN