Live data from Hacker News

Major bank accidentally published a private package to the public NPM Registry

twitter.com

11–20 of 236 posts

Re: Major bank accidentally published a private package to the public NPM Registry

#12
post #8
post #4

Earlier quoted context omitted.

How much of them sending takedown notices was a desperate posturing of "omg please please please please don't use our code!!!" I can't possibly see how they would possibly have any case.

If their code is proprietary, no one can use it. Even if they accidentally uploaded it to a public site.

[deleted]

Re: Major bank accidentally published a private package to the public NPM Registry

#13
post #2

Next tweet: “We sell a thing that prevents this kind of mistake ...” Just sayin.

They're a little SMH'd over this. And they have to pay their lawyer to deal with it. This cost them money so it is completely appropriate to mention Enterprise.

Re: Major bank accidentally published a private package to the public NPM Registry

#14

Earlier quoted context omitted.

How would you prefer free software be funded? :-P

OSS developers should just work for free, and live in destitution. Obviously. ;)

Everyone should live in destitution. Then they'll be free, just like their OSS.

Re: Major bank accidentally published a private package to the public NPM Registry

#16
post #4
post #3

This really isn't news, folks. It happens every week. I was just grumpy this morning.

How much of them sending takedown notices was a desperate posturing of "omg please please please please don't use our code!!!" I can't possibly see how they would possibly have any case.

Streisand effect.

Re: Major bank accidentally published a private package to the public NPM Registry

#17
post #2

Next tweet: “We sell a thing that prevents this kind of mistake ...” Just sayin.

They're a little SMH'd over this. And they have to pay their lawyer to deal with it. This cost them money so it is completely appropriate to mention Enterprise.

Naw, the bank probably thought “wow, it’s a good thing we have lawyers on standby for dealing with this kind of thing”.

Re: Major bank accidentally published a private package to the public NPM Registry

#18
post #8
post #4

Earlier quoted context omitted.

How much of them sending takedown notices was a desperate posturing of "omg please please please please don't use our code!!!" I can't possibly see how they would possibly have any case.

If their code is proprietary, no one can use it. Even if they accidentally uploaded it to a public site.

Has it been tested in court? :)

Re: Major bank accidentally published a private package to the public NPM Registry

#19
post #8
post #4

Earlier quoted context omitted.

How much of them sending takedown notices was a desperate posturing of "omg please please please please don't use our code!!!" I can't possibly see how they would possibly have any case.

If their code is proprietary, no one can use it. Even if they accidentally uploaded it to a public site.

I’m not sure how universally true that is.

When governments fail to redact documents, it’s on them.

If you “accidentally” talk to a reporter about your solicitor-privileged comms, it’s not privileged anymore.

Re: Major bank accidentally published a private package to the public NPM Registry

#20
post #8

Earlier quoted context omitted.

If their code is proprietary, no one can use it. Even if they accidentally uploaded it to a public site.

I’m not sure how universally true that is. When governments fail to redact documents, it’s on them. If you “accidentally” talk to a reporter about your solicitor-privileged comms, it’s not privileged anymore.

This isn't an open question.

If you don't have a license from the copyright holder, you can't legally use it, except for fair use exemptions: perhaps you could write a blog post criticizing it.

Post reply on HN