Hacker News new | past | comments | ask | show | jobs | submit login
Tell HN: Citrix Workspace sends everything in your clipboard over network
12 points by kddgooo 9 months ago | hide | past | favorite
Steps to reproduce (tested with macOS, Citrix Workspace 23.11.0.67):

1. Open a Citrix Virtual Desktop with clipboard redirection and put it in the background or on another screen

2. Start a Wireshark capture

3. Copy the text of https://gist.githubusercontent.com/phillipj/4944029/raw/75ba2243dd5ec2875f629bf5d79f6c1e4b5a8b46/alice_in_wonderland.txt

Actual behavior: A sudden spike in network requests to the IP of the virtual desktop appliance

Expected behavior: No sudden spike in network requests because you are doing stuff outside of the Desktop

Freelancers, contractors and people who use their computers for both personal and professional purposes should be aware that they are likely being aggressively spied on. It is very likely that every password, search term and URL you have ever copied on your computer with a Citrix Virtual Desktop running in the background has been sent to your employer/customer if clipboard redirection is enabled. It might even have been logged.




Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: