Live data from Hacker News

NPM Bans Terminal Ads

zdnet.com

161–170 of 377 posts

Re: NPM Bans Terminal Ads

#161

Earlier quoted context omitted.

The entire advertising industry is scum. I worked in it for two years and wish I never did. That's a sin I now atone for by discouraging younger developers from making the same mistake, using the harshest language I think dang will permit. It doesn't matter if there is no telemetry (and if this were to be normalized, there would eventually be telemetry. Such are the economic incentives in the ad industry. When it's p…

You're too absolutist. How is advertising inherently contrary contrary to the interests of anybody subjected to it? How would you find about a single product people are trying to sell if they don't advertise? E.g. would we better off if we couldn't advertise that free software alternatives exist?

Advertising is not a charitable act done for the benifit of consumers, no matter what anybody in the industry tells you. The relationship between advertisers and consumers is inherently adversarial, and advertising professionals are well aware of this fact even when they pretend otherwise (pretending otherwise is just one aspect of their complex web of lies and deceit. Whenever they do it, they remind me of what utter scum they are.)

If anybody needs proof of this, install an adblocker and observe as your life does not fall apart despite your now limited exposure to advertising.

Re: NPM Bans Terminal Ads

#162

Really ads in a terminal is a needless attack vector that is a dumpster fire for security that is part of the reason /why/ they have so many detractors.

Maybe the ability to run code that shows ad is the attack vector

Re: NPM Bans Terminal Ads

#163
post #50

Earlier quoted context omitted.

>, why is it so alarming to think that these maintainers might think of a clever idea like this to make a couple thousand bucks? [...] But instead of attacking the guy for trying, I really wish the discussion were focussed on how the community of open-source consumers can contribute back to the open source ecosystem You're (possibly unintentionally) distorting/diverting the issue. Nobody is criticizing open source ma…

This is an unfair go at the poster. He said "I'm not arguing that npm install logs should be packed full of ads (it shouldn't)." That's clear as can be. He's asking the same question I am, how do we get sufficient funding for these projects. Re your patreon suggestion, I thought we recently had an article where someone got little to nothing on that. > or getting hired by FAANG So one way to support foss software is t…

Since when are FAANG companies considered to be closed source? Have any of them snatched up maintainers to continue development behind closed doors?

There are examples of large corporations hiring maintainers to work on open source and keep those projects open source. I believe pypi is an example of that.

Re: NPM Bans Terminal Ads

#164

Isn't this a kind of censorship? I guess Go has the same faith.

Of course it is, and that's okay. It is NPM removing a package from its own servers. It is okay just like automatically deleting spam emails is okay and disallowing bad words during children TV shows is also okay.

It's not like NPM is preventing anyone to use some packages no matter where they are hosted.

(or maybe I misunderstood your concern)

Re: NPM Bans Terminal Ads

#165

Earlier quoted context omitted.

Yup, just this week I noticed the npm package `core-js` used by the Babel transpiler was polluting my build logs. It listed opencollective and patreon as possible channels of support. That I didn't mind so much, but then there was a message (repeated countless times in the logs) that the author was looking for a job. That's just spam in my terminal, unacceptable. Background and heated discussion in the following GitH…

It’s not spam, anymore than your comment is. It’s a message from the author of the free software you’re using. Asking for a job. If that offends you you should get over yourself. How entitled and spoiled you are to think you should have a right to use their software for free and not be bothered by a short message from the author.

Your comment seems unnecessarily confrontational.

"to think you should have a right to use their software for free and not be bothered by a short message from the author"

I don't know of any real rules about free software as far as what kind of messages someone should expect or shouldn't, but people can be bothered by it if they want.

Re: NPM Bans Terminal Ads

#166
post #50
post #11

While I don't particularly like the idea of stuffing ads into npm logs, I don't have the same visceral negative reaction that many people have in these HN threads on this topic. The overwhelming majority of the people complaining about this are well-paid tech workers writing code for well-funded companies that profit off of open source code without providing any reciprocal value to the open source projects in return.…

>, why is it so alarming to think that these maintainers might think of a clever idea like this to make a couple thousand bucks? [...] But instead of attacking the guy for trying, I really wish the discussion were focussed on how the community of open-source consumers can contribute back to the open source ecosystem You're (possibly unintentionally) distorting/diverting the issue. Nobody is criticizing open source ma…

> or getting hired by FAANG

But that way, you're still likely funding your project through ad scumbaggery, you're just adding a layer of indirection.

Re: NPM Bans Terminal Ads

#167

Oh god the horror of someone asking for some money when you install their free software while getting paid 6 figures and bitching on HN instead of doing anything productive. Then there’s NPM that feels they have a god given right to make money off of open source while attempting to stop authors from selling or monetizing packages. Fuck You NPM. First you try to stop authors from selling packages, now you want to stop…

Next they will reject packages that allow you to build an NPM competitor

Re: NPM Bans Terminal Ads

#168
post #11

While I don't particularly like the idea of stuffing ads into npm logs, I don't have the same visceral negative reaction that many people have in these HN threads on this topic. The overwhelming majority of the people complaining about this are well-paid tech workers writing code for well-funded companies that profit off of open source code without providing any reciprocal value to the open source projects in return.…

I release a ton of my work with open source licensing and I've never thought of it as a revenue stream. If people are financially burdened by making their project open-source; then don't make it open source. Donating something to the community and then getting offended when nobody reciprocates is disingenuous. It's part of the problem with "freemium" software these days where developers think I should be indebted to…

That’s a good point you bring up...where do we draw the line? Lots of projects use Debian and docker, etc...is it even ethical to donate to an npm package before donating to the dozens of free tech layers node sits on top of?

Re: NPM Bans Terminal Ads

#169

Earlier quoted context omitted.

I am assuming a more traditional terminal set up where it could be used for injection attacks and escape sequences to execute arbitrary code - combined with the dubious tradition of unchecked ads as a vector. It is possible they had learned from mistakes of the past and have proper output and input segregation to prevent such shenanigans entirely. In which case that would still leave social engineering as an attack s…

I really don’t get it. You’re running their code, whether it prints an ad or not. There’s no need for “injection attacks and escape sequences” at that point.

If someone, for instance, takes control of their repo, then they can upload whatever they like. But that auth can be fairly securely guarded, and it's probably a very hard to do it quietly as packages are signed.

But now they're hosting the ads and potentially allowing remote code execution. Now the attacker only needs to get on to a webserver to deploy a payload. That's why it opens a new vector of attack.

Moreover, if they're able to own the server quietly, they can be deploying whatever they like to a ton of people over time.

Re: NPM Bans Terminal Ads

#170

Earlier quoted context omitted.

What about a completely pointless "support the project" license? So you basically chip in for the maintenance, but don't get any additional rights?

Doesn’t make it past accounting.

What if it's a support contract that entitles you to a response to support requests on the basis of 'in less than twenty-four hours' as opposed to the usual 'I might respond on a best effort basis if I have time, but no promises'? Would that make it past accounting?
Post reply on HN