Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security defaults should be improved #357

Open
neg3ntropy opened this issue May 25, 2021 · 0 comments
Open

Security defaults should be improved #357

neg3ntropy opened this issue May 25, 2021 · 0 comments

Comments

@neg3ntropy
Copy link

neg3ntropy commented May 25, 2021

I enjoy gpaste via the gnome extension and I maintain a custom Fedora "spin" for my organization as well as family and friends, where I have GPaste preinstalled and active by default.
This issue is constructive criticism from a user about the security/privacy features and default settings. I think they are bad and a bit lacking respectively.

Defaulting to a history size of 100, persisted to disk is really not prudent. Plus, there's no time-based expiration.
Most of the time a user would not think about clipboard history and just be glad it's there when they need it. However, unless they went and change the configuration or manually intervened at the right time to protect sensitive data, it is very easy to leave secrets on the computer for a long time.

I would consider a good default to be;

  1. no disk persistence
  2. 10-20 items max (1 page, easy to check)
  3. items expire after 24h

Furthermore the min number of entries setting appears to be 100.
I am not sure if the faults lie in the extension or the daemon.
Thanks for the consideration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant