Live data from Hacker News

StarDict sends X11 clipboard to remote servers

lwn.net

91–100 of 350 posts

Re: StarDict sends X11 clipboard to remote servers

#91

> In response, Xiao pointed out that the package description can be read by any user who chooses to install the software, and it does mention the scan feature. Wouldn't be the first (or last) time a Debian maintainer has pulled the "you should read the descriptions of all (hundreds) of your packages (most installed as dependencies)" card in response to a bug report. If someone started reading all the package descript…

That doesn’t even address the problem! The package description does mention the scan feature, but not the automatically-send-it-to-a-server-in-plain-text feature.

Sure, if you read the description and the list of plugins and correctly guess how this plugin is implemented, then you can deduce some of it.

Re: StarDict sends X11 clipboard to remote servers

#92

Earlier quoted context omitted.

Such responses to me are proof of malicious intent.

Malicious intent written in the package description? I would think that really unlikely. I think it's just a cultural difference. Sogou, a super popular Chinese input program for Windows iOS and Android does the same with everything you type and nobody cares.

I think so too. It's cultural difference, and ignorance at most. I doubt the maintainer has control over that two random dictionary websites, or was tasked by them to do this or anything like that. They are just a different person, and they didn't give a fuck.

Re: StarDict sends X11 clipboard to remote servers

#93

Earlier quoted context omitted.

While I think the response was not well thought out, it's still a far cry from "proof of malicious intent".

We're not going to agree on that. The response is clearly there to point to a fig leaf instead of saying 'oh, oops, we will make this more obvious in the UI', the software is working as intended: as a way to gain access to more data. Note that clipboard data can be just about anything and is a valuable dataset, more so if the source of the data isn't aware of being a source, besides, there is no history so you won't…

[flagged]

Re: StarDict sends X11 clipboard to remote servers

#95

> In response, Xiao pointed out that the package description can be read by any user who chooses to install the software, and it does mention the scan feature. Wouldn't be the first (or last) time a Debian maintainer has pulled the "you should read the descriptions of all (hundreds) of your packages (most installed as dependencies)" card in response to a bug report. If someone started reading all the package descript…

Such responses to me are proof of malicious intent.

Hanlon's razor applies here, I think. It's just ignorance, not malice. I doubt the maintainer has connection, or was pressured by these two random dictionary websites to include this - nor do I think that they gain any advantage of it.

People need to be on the lookout though, the xz incident showed that FOSS is indeed vulnerable.

Re: StarDict sends X11 clipboard to remote servers

#96

Earlier quoted context omitted.

Such responses to me are proof of malicious intent.

Hanlon's razor applies here, I think. It's just ignorance, not malice. I doubt the maintainer has connection, or was pressured by these two random dictionary websites to include this - nor do I think that they gain any advantage of it. People need to be on the lookout though, the xz incident showed that FOSS is indeed vulnerable.

But it cannot be adequately attributed to ignorance, so no, Hanlon's razor does not apply. There is an obvious security breach.

Re: StarDict sends X11 clipboard to remote servers

#97

Earlier quoted context omitted.

> a password is worth something only to those who know what the password is for I also copy-paste my username from KeePass, so you'd pretty quickly get everything

[flagged]

People reuse user names and passwords all the time.

It is also quite feasible to test a user+password combo on the most common websites.

Re: StarDict sends X11 clipboard to remote servers

#98

Earlier quoted context omitted.

[flagged]

It's malicious intent! The developer isn't a kid, they're releasing the software for world wide use. It's a simple thing, do not send private data to remote servers without explicitly asking the user!

I'd go one step further and say it's a blatant Chinese SIGINT.

Re: StarDict sends X11 clipboard to remote servers

#99

> of course a dictionary program will include code to talk to dictionary-providing web sites. I wouldn't say that is just a given, if I've apt-get installed a dictionary I might expect that is the whole thing on my machine. It's not like we haven't had dictionaries in physical books for centuries... It seems like stardict is very much an online thing, which I suppose could be legit, but the whole thing does seem like…

The venerable ding does well with a local dictionary - and it's packaged in Debian too

https://www-user.tu-chemnitz.de/~fri/ding/

Re: StarDict sends X11 clipboard to remote servers

#100

Earlier quoted context omitted.

While I think the response was not well thought out, it's still a far cry from "proof of malicious intent".

We're not going to agree on that. The response is clearly there to point to a fig leaf instead of saying 'oh, oops, we will make this more obvious in the UI', the software is working as intended: as a way to gain access to more data. Note that clipboard data can be just about anything and is a valuable dataset, more so if the source of the data isn't aware of being a source, besides, there is no history so you won't…

[flagged]
Post reply on HN