[plasmashell] [Bug 437901] Klipper security risks

2021-06-09 Thread Nate Graham
https://bugs.kde.org/show_bug.cgi?id=437901

--- Comment #9 from Nate Graham  ---
It wouldn't help for everything though. For example I manage my passwords with
a browser-addon-based system, so telling Klipper to exclude everything from
Firefox would make no sense. Ultimately the solution is for apps to behave
correctly, not for us to let the user work around broken apps in a zillion
different ways. :)

-- 
You are receiving this mail because:
You are watching all bug changes.

[plasmashell] [Bug 437901] Klipper security risks

2021-06-08 Thread medin
https://bugs.kde.org/show_bug.cgi?id=437901

--- Comment #8 from medin  ---
> you should tell the apps in question to mark
> sensitive clipboard data as such so everything works automatically.

It would be cool to have and option to exclude copied text from specific apps.

-- 
You are receiving this mail because:
You are watching all bug changes.

[plasmashell] [Bug 437901] Klipper security risks

2021-06-08 Thread Nate Graham
https://bugs.kde.org/show_bug.cgi?id=437901

Nate Graham  changed:

   What|Removed |Added

 Resolution|--- |DOWNSTREAM
 Status|REPORTED|RESOLVED
 CC||n...@kde.org

--- Comment #7 from Nate Graham  ---
You don't have to totally disable Klipper; just make it behave like the crude
clipboards of other platforms by reducing the history size to 1. Then the
password in the history will get cleared when another thing is copied.

I agree with David that you should tell the apps in question to mark sensitive
clipboard data as such so everything works automatically.

-- 
You are receiving this mail because:
You are watching all bug changes.

[plasmashell] [Bug 437901] Klipper security risks

2021-05-31 Thread medin
https://bugs.kde.org/show_bug.cgi?id=437901

medin  changed:

   What|Removed |Added

 Status|RESOLVED|REPORTED
 Resolution|NOT A BUG   |---

--- Comment #6 from medin  ---
(In reply to David Edmundson from comment #5)
> Only through the mechanism keepassxc uses.
> Klipper has no other way to determine the source of clipboard data.

It's technically possible, on Mate I did it with CopyQ to avoid saving my
copied data from specific apps like Writer, Eclipse... 
The problem with Plasma desktop is that Klipper cannot be disabled because it
causes a loss of data when the origin app from which the data is copied is
closed.

-- 
You are receiving this mail because:
You are watching all bug changes.

[plasmashell] [Bug 437901] Klipper security risks

2021-05-31 Thread David Edmundson
https://bugs.kde.org/show_bug.cgi?id=437901

David Edmundson  changed:

   What|Removed |Added

 Resolution|--- |NOT A BUG
 Status|REPORTED|RESOLVED

--- Comment #5 from David Edmundson  ---
Only through the mechanism keepassxc uses.
Klipper has no other way to determine the source of clipboard data.

-- 
You are receiving this mail because:
You are watching all bug changes.

[plasmashell] [Bug 437901] Klipper security risks

2021-05-31 Thread medin
https://bugs.kde.org/show_bug.cgi?id=437901

medin  changed:

   What|Removed |Added

 Resolution|WAITINGFORINFO  |---
 Status|NEEDSINFO   |REPORTED

--- Comment #4 from medin  ---
(In reply to David Edmundson from comment #3)
> "save clipboard contents on exit"
> 
> If that doesn't work, please do let me know.

That option just clears the whole Klipper data after logging out. 
What I meant is if there's any way to exclude copied texts within a specific
app from being saved or shown in Klipper like how KeePassXC does it ?

-- 
You are receiving this mail because:
You are watching all bug changes.

[plasmashell] [Bug 437901] Klipper security risks

2021-05-31 Thread David Edmundson
https://bugs.kde.org/show_bug.cgi?id=437901

David Edmundson  changed:

   What|Removed |Added

 Resolution|--- |WAITINGFORINFO
 Status|REPORTED|NEEDSINFO

--- Comment #3 from David Edmundson  ---
"save clipboard contents on exit"

If that doesn't work, please do let me know.

-- 
You are receiving this mail because:
You are watching all bug changes.

[plasmashell] [Bug 437901] Klipper security risks

2021-05-31 Thread medin
https://bugs.kde.org/show_bug.cgi?id=437901

medin  changed:

   What|Removed |Added

 Status|RESOLVED|REPORTED
 Resolution|NOT A BUG   |---

--- Comment #2 from medin  ---
(In reply to David Edmundson from comment #1)
> This is configurable.
I opened Klipper config dialog and couldn't find any option to do it, where can
I find it ? What I want is to avoid Klipper from saving some sensitive info
copied from an application (based on JavaFX) which needs heavy copy/paste
actions to work.

-- 
You are receiving this mail because:
You are watching all bug changes.

[plasmashell] [Bug 437901] Klipper security risks

2021-05-31 Thread David Edmundson
https://bugs.kde.org/show_bug.cgi?id=437901

David Edmundson  changed:

   What|Removed |Added

 CC||k...@davidedmundson.co.uk
 Status|REPORTED|RESOLVED
 Resolution|--- |NOT A BUG

--- Comment #1 from David Edmundson  ---
This is configurable.

There is a mechanism by which sensitive data can be marked as not
being something to save in klipper which is used by keepassxc and
others. This is done by adding an additional mimetype tag when the
selection is saved to the clipboard.

Anything else is out of scope.

-- 
You are receiving this mail because:
You are watching all bug changes.