• mox@lemmy.sdf.org
    link
    fedilink
    arrow-up
    7
    ·
    edit-2
    7 months ago

    I tried Clementine for a while, but I didn’t like how careless the developers were with privacy and security. For example, quietly downloading and executing a Spotify blob (even when I don’t use Spotify), and sending pings to a geolocation service without my permission.

    • arglebargle@lemm.ee
      link
      fedilink
      English
      arrow-up
      4
      ·
      7 months ago

      That is interesting. Now I am going to have to run Wireshark and see if anything is going on with mine.

      Shame if so, it is the most feature rich music player.

      • mox@lemmy.sdf.org
        link
        fedilink
        arrow-up
        4
        ·
        edit-2
        7 months ago

        You might also check to see if it has already downloaded any .so files. (These are executable code, like Windows DLLs.) I found one in $HOME/.config/Clementine/spotifyblob/ when I used it a few years ago, but recent versions may store them elsewhere or do it conditionally.

        • arglebargle@lemm.ee
          link
          fedilink
          English
          arrow-up
          2
          ·
          7 months ago

          I looked and I do not see anything like that. Who packaged your version I wonder.

          • mox@lemmy.sdf.org
            link
            fedilink
            arrow-up
            2
            ·
            7 months ago

            The blob wasn’t packaged with the application. Clementine downloaded the blob after installation. It’s possible that it doesn’t do this automatically any more, or does it under different conditions. I have no reason to investigate further, since I no longer use it.

            • bitchkat@lemmy.world
              link
              fedilink
              English
              arrow-up
              3
              ·
              7 months ago

              I have the same home directory for 20+ years and have been running Clementine since it was released on Fedora. I have no blobs or .so files.

            • arglebargle@lemm.ee
              link
              fedilink
              English
              arrow-up
              2
              ·
              7 months ago

              Cool. I guess I was wondering if the package maintainer had set a configuration to pull those in automatically, or if Clementine was designed to do that. But in any case, thanks for the reply.

        • bitchkat@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          7 months ago

          I have no spotifyblob directory in my ~/.config/Clementine. Just Clementine.conf, clementine.db, jamendo.db and an albumcovers directory