Live data from Hacker News

Police conducted search in the Nginx office due to a copyright claim

twitter.com

101–110 of 228 posts

Re: Police conducted search in the Nginx office due to a copyright claim

#102
post #89

always wondered, is it pronounced 'en-gin-ex' or 'N-ginx', there was a debate in my office

From the official FAQ[1]:

> How do you pronounce “NGINX”?

> Correct: en-juhn-eks, Engine-X

> Incorrect: en-jingks

I wouldn't be surprised if it's actually an abbreviation of "engine-x", but I can't find any better source that explains how they came up with the name. Still, this source pretty much implies it.

[1] https://www.nginx.com/resources/wiki/community/faq/#how-do-y...

Re: Police conducted search in the Nginx office due to a copyright claim

#103

Earlier quoted context omitted.

Then they would definitely advertise it by attacking the company so that the whole world would know about their secret backdoor. Very smart, indeed!

Just thinking about it would have a chilling effect which to the authorities may be better than actual access.

I'm going to switch from nginx to Caddy, so I guess?

Re: Police conducted search in the Nginx office due to a copyright claim

#105
post #26

I see it this way (being a Russian): it's not a copyright claim issue, but rather a hostage situation with bandits involved (a.k.a Russian authorities), and what they want is ransom so that top #1-2 nginx contributors don't go to jail for some 10 years.

wow, I would have thought those dudes would have moved to a more friendly country years ago given the fame and profits from creating nginx.

Re: Police conducted search in the Nginx office due to a copyright claim

#106
post #32

Earlier quoted context omitted.

It feels like an intelligence shakedown. Nginx has a rather large install base. FSB would love to have an entry point in it I'm sure, or maybe they previously had one and are trying to gain it back?

This is what's really concerning. If FSB was able to actually implement something and shell all nginx boxes (and thusly obtain SSL certs, intercept communications, etc..) imagine how much access they'd have.

that's not going to happen, too many security experts constantly monitoring nginx. That's the beauty of it being a high profile open source project.

Re: Police conducted search in the Nginx office due to a copyright claim

#107
post #80

Earlier quoted context omitted.

nginx is open source. I tend to use the distribution provided packages which in case of debian are reproducible builds. (yeah, i know there's a pro version of nginx. never used it)

"It's open source, someone surely is doing regular thorough security audits."

Auditing one of the world's most used pieces of internet facing software that also isn't "a huge codebase"? Yes I do think nginx will be just fine. Security experts are constantly combing through that sort of software looking for holes, as well as AI tools. duh. It ups your brand to find holes.

Re: Police conducted search in the Nginx office due to a copyright claim

#108
post #33
post #26

I see it this way (being a Russian): it's not a copyright claim issue, but rather a hostage situation with bandits involved (a.k.a Russian authorities), and what they want is ransom so that top #1-2 nginx contributors don't go to jail for some 10 years.

I've some kind of reflex to say "come on, it can't be that bad over there", but then I read a thread like this and it's like a slap in my naivete's face. To put the "over there" remark in context, I grew up in a neighbourhing country.

The last company I worked for put together a dev team in the Ukraine and poached some talent from a local company that was connected to the local government. Our company ended up paying a relatively small (significant in the Ukraine) 'fee' to not have the team physically shut down by the locals.
Post reply on HN