Live data from Hacker News

Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

bleepingcomputer.com

581–590 of 1001 posts

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#581
post #349

Earlier quoted context omitted.

That video doesn't discuss marak's "history of mental illness". Do you have some information on this?

Here's some information: https://www.reuters.com/article/us-usa-new-york-bomb/new-yor...

That escalated quickly.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#582

Earlier quoted context omitted.

Programmers have all the power to hurt things but they rarely think about using that power. Sometimes it's not how much value you can create that wins the day, but how much pain you can strike at other people that counts. Politics is like that. Ugly, but necessary.

The sad thing is that some(most?) of them only want to think about the code and do not want to do deal with the real world implications of the software that they are involved in.

That's kinda OK-ish (for them), but politics is a monster that will bite you if you don't care.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#584
post #463

Earlier quoted context omitted.

I've never heard of GitHub enforcing the multiple accounts thing, FWIW. This user was taking clearly malicious actions against millions of consumers of code, in a bait and switch style. GitHub rarely takes action against accounts like that, don't let a sample size of one define them. There are lots of reasons to be annoyed with GitHub but this isn't one of them. As for alternatives, check https://sr.ht

> I've never heard of GitHub enforcing the multiple accounts thing, FWIW correct they don't enforce it but they make it such a royal PITA to switch accounts that I eventually gave up trying. They don't have an account switcher like Google etc. > As for alternatives, check https://sr.ht thank you! Checking it out. Edit: it seems that sr.ht is not self-hosted though? I can see the link to create an account but I can't…

https://man.sr.ht/installation.md

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#585
post #584

Earlier quoted context omitted.

> I've never heard of GitHub enforcing the multiple accounts thing, FWIW correct they don't enforce it but they make it such a royal PITA to switch accounts that I eventually gave up trying. They don't have an account switcher like Google etc. > As for alternatives, check https://sr.ht thank you! Checking it out. Edit: it seems that sr.ht is not self-hosted though? I can see the link to create an account but I can't…

https://man.sr.ht/installation.md

Oh nice, thank you!

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#586

AITA for thinking that if you develop open-source software and your license permits anyone to use it for free, then complaining about no compensation is not a valid complaint? I totally understand that billionaire corporations use software like this for free. But the software maintainer has explicitly allowed _anyone_ to use it for free. If you don't want them to use it for free, license it as such. What am I not see…

There are people who think its reasonable to take all the pennies from the "take a penny leave a penny" plate because "that's what it's there for."

I assume you mean "take a penny" = "use the software for free" and "leave a penny" = "contribute back" (money or time).

With the plate there's a sign that says both "take" and "leave". In this case there is also a sign (the license) which only says "take". The intent is clear in both.

It's further not comparable because taking a literal penny deprives the next person of it, whereas here using the software for free costs the other users nothing.

But I'm not trying to nitpick the analogy, I only want to point out the the obligations (both social and contractual) are not the same, neither are the consequences.

Again, if he wanted to make money from his software, he should've put it in the license and charged the big users for it.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#587
post #24
post #11

Earlier quoted context omitted.

If he can do as he pleases, can't GitHub as well?

GitHub also has rights. They can choose to boot vandals off. They can choose not to host intentional malware.

How does one vandalized her own property? Isn't that just called using it?

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#588

Earlier quoted context omitted.

The maintainer seems a few steps beyond unwell. Seems like he was planning a terrorist act of some sort. Even if one is mentally unwell, I would not first describe them that way should they choose to premeditate harm against others. If you're building bombs, you're almost certainly at that point. At the very least, the maintainer is unstable if not actively malicious and seeking to cause harm however he can.

Let's not start claiming people are planning terrorist acts without any proof. Those claims are extremely hard to get rid of, especially on the internet.

Here's the proof: https://abc7ny.com/suspicious-package-queens-astoria-fire/64...

Another article: https://www.njhomelandsecurity.gov/at-a-glance/9-21-20

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#589
post #134

Earlier quoted context omitted.

That's fine, but then the downstream shouldn't complain either when the code breaks, whether intentionally or unintentionally. The contract on paper disclaims all liability after all. There is a social contract and then there is the literal contract. A lot of commenters here seem to be willfully obtuse or simply ignoring the former.

There's a difference between stopping to give away your stuff for free and acting maliciously. If I give away donuts for free and stop at some point, you have no right to complain. If I poison the donuts because you should've really thrown money at me for those donuts that I explicitly marked as free , I think you could complain after all.

My parents always taught me not to take donuts from unknown people, especially when they're free. It's common sense and corpos take all fault for taking an easy fix to save their own developer hours at someone's else expense. Now, when it turns out there are consequences to this, corpos aren't that happy.

Re: Dev corrupts NPM libs 'colors' and 'faker', breaking thousands of apps

#590

AITA for thinking that if you develop open-source software and your license permits anyone to use it for free, then complaining about no compensation is not a valid complaint? I totally understand that billionaire corporations use software like this for free. But the software maintainer has explicitly allowed _anyone_ to use it for free. If you don't want them to use it for free, license it as such. What am I not see…

There are people who think its reasonable to take all the pennies from the "take a penny leave a penny" plate because "that's what it's there for."

This is how I feel about people who create small but popular libraries and then complain about the workload. They're squatting on a valuable and finite resource, attention, that they don't like or appreciate. If you don't want it, sunset your library and let me write a replacement. I'll happily rewrite faker or left-pad for free, and so will hundreds of other developers.
Post reply on HN