GPaste icon indicating copy to clipboard operation
GPaste copied to clipboard

Security defaults should be improved

Open neg3ntropy opened this issue 3 years ago • 0 comments

I enjoy gpaste via the gnome extension and I maintain a custom Fedora "spin" for my organization as well as family and friends, where I have GPaste preinstalled and active by default. This issue is constructive criticism from a user about the security/privacy features and default settings. I think they are bad and a bit lacking respectively.

Defaulting to a history size of 100, persisted to disk is really not prudent. Plus, there's no time-based expiration. Most of the time a user would not think about clipboard history and just be glad it's there when they need it. However, unless they went and change the configuration or manually intervened at the right time to protect sensitive data, it is very easy to leave secrets on the computer for a long time.

I would consider a good default to be;

  1. no disk persistence
  2. 10-20 items max (1 page, easy to check)
  3. items expire after 24h

Furthermore the min number of entries setting appears to be 100. I am not sure if the faults lie in the extension or the daemon. Thanks for the consideration.

neg3ntropy avatar May 25 '21 07:05 neg3ntropy