Intent or not, that developer is a risk to the project.
Note that clipboard data can be just about anything and is a valuable dataset, more so if the source of the data isn't aware of being a source, besides, there is no history so you won't even know what you've lost.
Select to translate is almost a standard feature for translation software. Not sure if the situation gets better now, but back then the software was written, using clipboard as temporary storage is a very robust and maybe the only way to implement such feature.
Trivia: It's likely sending Ctrl+C and reading clipboard to get the selected text. No easy cross-platform API for this lol.
Also note that the software is very old and poorly maintained.
Is the difference meaningful? It’s proof of a value set so different from the community’s as to merit the same response: expulsion.
> Is the difference meaningful? It’s proof of a value set so different from the community’s as to merit the same response: expulsion.
We expel people for different values now? I'm not Christian, should I be expelled?Is there a defined set of values that one must uphold, or at least believe in theoretically, to be a welcome member?
Yes, that's what core values mean. If they're not embraced by everyone, they cease to be core.
If X11 tolerates developers who think piping data unseen to remote servers is okay, the project as a whole ceases to be trustworthy.
> I'm not Christian, should I be expelled?
From a listserv? No. From, like, a religious group? Maybe.
If one is expected to go through all the documentation of both the main package and all dependency packages, and also through whatever specific configuration details to your case, just to be able to catch a specific IMPORTANT detail that's not clearly spelled out in the main package, that's malicious.
"A dependency we use captures your clipboard data and sends it to remote servers"
That sentence right there would kill their userbase, so they omit warning you about it. And on top of the "...user should have read the description..." non-apology, "just split the packages, bro".
That's malicious.
No, it wouldn't. People don't take privacy very seriously.
The overlap between Linux desktop users and digital privacy concerns is pretty large.
But it wouldn't kill their userbase because nobody reads the package descriptions anyway.
It could be that they were caught with their pants down and posted an ill-thought response, but I'd lean strongly towards malice with such a poor defense, it borders on confession. Clipboards are one of the most critical privacy/security features, you don't ever want to leak them unintentionally.
Did we already forget about the XZ Utils backdoor? There have to be multiple efforts to infiltrate backdoors in Linux going right now.
I agree a lot with this. You're supposed to trust your distributions packages. If you can't trust your distro, who can you trust? If you don't, find one you do trust, as that's a viable alternative. If none are trustworthy to you, then the only real option is to become your own package maintainer and have fun with Linux From Scratch.
People need to be on the lookout though, the xz incident showed that FOSS is indeed vulnerable.
Stuff like this can fly under the radar for a long time because lots of people will assume how it works without actually verifying that it really works like that.
> the same kind of problem was reported by Pavel Machek in 2009 and again by "niekt0" in 2015. The 2009 bug was solved by patching the application's default configuration to disable networked dictionaries. That appears to have worked for a time, but the YouDao plugin, which was added in 2016, does not respect the configuration option. The 2015 problem was not fixed until August 6 of this year (although the package was removed from Debian for unrelated reasons for a few months from 2020 to 2021). That fix just removed the stardict_dictdotcn.so plugin, which also sent translation requests to dict.cn and was later subsumed by the YouDao plugin, from the package.
This whole trend of adding a service to stuff that doesn't need a service is very annoying.
1. making "scanning" (the clipboard capturing feature opt-in, with a huge notification for the implications
2. disabling the English-Chinese online translation plugin by default
Will the existence or lack thereof excuse the absolute lack of security and privacy this package exhibits? And the lack of interest from the developer?
At least try to keep up with the main concern: "sending potentially private or security impacting information in plaintext across the internet".
"Does not exist blah blah"
That has to be one of the most inane replies I've read in a while.
Yeah this is the world we now live in.
Maybe incentivized? $1000? $10000? Would be interesting to hear from the developer himself.
We truly live in an utopia!
(but malware authors usually cover their tracks better)
malice & typical CCP behavior IMHO. The responses from the maintainer are unacceptable and he should have his privileges stripped
Fundamentally, always-online, home-phoning features are the norm, and it should be up to OS distributions to manage security postures such as allowlists for network access. Think something along the lines of "StarDict wants to connect to dict.cn. Allow/Deny?".
They can, but framing this as a mere disagreement is disingenuous: One approach might slightly inconvenience someone, while the other (as was taken here) inflicts irreparable damage.
> Fundamentally, always-online, home-phoning features are the norm,
No. Although common on certain platforms, they are not a fundamental norm in software, nor should they be.
In particular, we're talking about Debian here.
That is what opensnitch provides, as do some other detection tools.
Security illiteracy? Yes. Malicious intent? Probably no.
Does being security illiterate equal malicious? Debatable.
I think the bar for trust in terms of evil intent is on the floor.
When you use Debian, you have a reasonable expectation of privacy.
People who handwave that away or say it's not as bad as something else either have an agenda or are ignorant about the history of Debian.
You can literally do both in the EU with informed consent.
Informed consent is (1) always going to be specific and (2) ends when the legal base for procession is no longer supported.
That requires a complete re-thinking of your moral framework if you are not familiar with the concept.
Just like for some people gay marriage is inconceivable and results in them being ready to man the barricades and for others it doesn't even move the needle. And then there is abortion and bodily autonomy. Large swathes of humanity are not going to be able to understand the remainder when it comes to those subjects, they all arrive at their own conclusions through a mixture of tradition, religion, philosophy and cultural exposure (media, mostly) as well as peer pressure.
I've long ago decided that the only party that will hopefully be able to get all of those right using an objective frame of reference will be born a few thousand years from now, assuming humanity will make it that far.
I’m saying that on a practical level the difference is unobservable. Part of your right to life, in this formulation, is your right to sign it away.
The terminality of a right to life makes it a poor comparison to privacy, which has no comparably-irreversible end state like death.
To you.
how many times does everyone need to be totally compromised by some shitty software before people start to care?
innocent individuals each days are suffering hacks and malicious interactions. people are losing their livelihoods. companies are getting shutdown... what more need to happen?? :S
LLMs are only going to make this worse. We're going to see a plethora of vibe coded slop everywhere.
I think it's just a cultural difference. Sogou, a super popular Chinese input program for Windows iOS and Android does the same with everything you type and nobody cares.
Just because Microsoft did it that doesn't make it a valid defense, in fact it shows the opposite (after all, they too did not have the best interests of their users at heart). The fact that the recipient of the data sits on the other side of the GFW and that clipboards can contain very interesting data you really should wonder about the intentions of the author, they do not get the benefit of the doubt. In fact, open source software that to all intents and purposes looks like it runs locally but pumps your (private) data out without your consent is a very large red flag to me: it gains access to data that otherwise likely would never be found in the wild. At a minimum this is a fairly serious GDPR violation.