Live data from Hacker News

Major bank accidentally published a private package to the public NPM Registry

twitter.com

21–30 of 236 posts

Re: Major bank accidentally published a private package to the public NPM Registry

#21
post #8
post #4

Earlier quoted context omitted.

How much of them sending takedown notices was a desperate posturing of "omg please please please please don't use our code!!!" I can't possibly see how they would possibly have any case.

If their code is proprietary, no one can use it. Even if they accidentally uploaded it to a public site.

Absolutely not true. Anyone that lives in a country whose legal system does not respect their copyright can use it.

Re: Major bank accidentally published a private package to the public NPM Registry

#23
post #2

Next tweet: “We sell a thing that prevents this kind of mistake ...” Just sayin.

How would you prefer free software be funded? :-P

We are a little tounge in cheek here, but I’ll take this question seriously. While it is great that NPM can develop new and more reliable products, is would also greatly benefit them and everyone else, if enerprises of certain size or stature would be required, legaly or regutoraly, to pay for software they already use. So say you are a bank, and there is a list of regulations that you have to comply with, so here is a new one. FTC (or California law makers) can figure out the mechanics and JP Morgan will write the check. Then NPM will already have a solid foundation to build on, some indie will have a windfall, and the big software guys might say hell yes, that’s a new business model. That’s what I’d prefer, but no one but you is asking me ;)

Re: Major bank accidentally published a private package to the public NPM Registry

#25
post #18
post #8

Earlier quoted context omitted.

If their code is proprietary, no one can use it. Even if they accidentally uploaded it to a public site.

Has it been tested in court? :)

Yes, of course.

Re: Major bank accidentally published a private package to the public NPM Registry

#26

Earlier quoted context omitted.

I’m not sure how universally true that is. When governments fail to redact documents, it’s on them. If you “accidentally” talk to a reporter about your solicitor-privileged comms, it’s not privileged anymore.

This isn't an open question. If you don't have a license from the copyright holder, you can't legally use it, except for fair use exemptions: perhaps you could write a blog post criticizing it.

Thats only true for the US and the countries adhering to US copyright. It's not universally true

Re: Major bank accidentally published a private package to the public NPM Registry

#27
post #21
post #8

Earlier quoted context omitted.

If their code is proprietary, no one can use it. Even if they accidentally uploaded it to a public site.

Absolutely not true. Anyone that lives in a country whose legal system does not respect their copyright can use it.

Basically every country has signed a treaty saying their legal system does respect them: https://en.wikipedia.org/wiki/List_of_parties_to_internation...

If you're saying any country where they don't respect it in practice, then sure.

Re: Major bank accidentally published a private package to the public NPM Registry

#28
post #26

Earlier quoted context omitted.

This isn't an open question. If you don't have a license from the copyright holder, you can't legally use it, except for fair use exemptions: perhaps you could write a blog post criticizing it.

Thats only true for the US and the countries adhering to US copyright. It's not universally true

It's not "US copyright", it's several international copyright treaties, which 90% of all nations have agreed to: https://en.m.wikipedia.org/wiki/Berne_Convention

The few exceptions are where copyright essentially doesn't exist at all. Where it does, this is how it works.

Re: Major bank accidentally published a private package to the public NPM Registry

#29

Abused the DMCA also. SMH.

How is this DMCA abuse? A copyright owner is requesting that a site that has safe harbor protection remove an unauthorized copyrighted work. The employee that originally created the unauthorized package may no longer work for the bank, unable to be identified, or doesn't have the credentials anymore.

Re: Major bank accidentally published a private package to the public NPM Registry

#30

It took them no less than 3 years to actually notice... Holy moly! I wonder what package that is... Just out of curiosity...

You'd think it's like, some proprietary trading algorithm, but in reality it's probably their own implementation of left-pad.
Post reply on HN