Live data from Hacker News

Faker.js is now a community controlled project

fakerjs.dev

131–140 of 357 posts

Re: Faker.js is now a community controlled project

#131
post #69

Earlier quoted context omitted.

> It was malicious act to Github's users. I'm not sure why it matters they are Github users. The packages were hosted on npm through Cloudflare - does that allow Cloudflare to take over the packages too? And NS1 since they host the fakerjs domain?

It’s cool that you’re internet rules-lawyering and all but ultimately he used his free account with intent to harm others, just as surely as if he backdoored his code. Freedom of speech is good, and protest is fine, but why would GitHub amplify the speech of a nutso who abused his position of trust?

They don't have to amplify anything. This is why open source is valuable; if the current maintainer is considered to be unfit or unreliable in some way, the community that disagrees with their rhetoric/leadership can fork the package and keep going like nothing happened. If you don't care/the package is still usable, then ideally no further action has to be taken.

At no point down the road should that involve revoking someone's ownership of a software project, though. Software ownership is sacred, not just because of tradition but because understanding who owns your packages and libraries is paramount to auditing security. Some of the most valuable contributions to computer science have been ones that allow people to verify integrity, be it SHA, TLS or GPG. If Microsoft abuses their position of power to break that chain of integrity, how can we be sure that other repos belong to their respective authors?

I can understand if you, the individual don't find this interesting or consider it inconsequential to your workflow. But other people rely on it, and you can't pretend like an honest chain of custody is somehow valueless.

Re: Faker.js is now a community controlled project

#132
post #98

I'm surprised the blockchain gang isn't coming up with a solution for trustless npm packages or is it that a blockchain can't solve the problem of a trusted developer suddenly becoming untrustworthy?

Packages are written by people not algorithms. People you have to explicitly trust to install the package.

Ethereum scripts are written by people too

Re: Faker.js is now a community controlled project

#133
Kudos to the new faker.js 'team'

On the other hand, this further proofs exactly how replaceable one can be... especially those who want to `sacrifice` themselves for opensource work.

Get a job to sustain yourself and your family; then contribute to open source when you are bored or for fun...

Re: Faker.js is now a community controlled project

#134

Earlier quoted context omitted.

Blockchain is a solution to a problem that doesn't exist in the real world in any appreciable sense.

Oh it definitely exists, and this might be one place where it could help, but it's not sexy, and it won't make you rich, so nobody is bothering. A lot easier to pretend NFTs are more important than collecting stamps.

I think this is the right answer

Re: Faker.js is now a community controlled project

#135
post #23

Earlier quoted context omitted.

> It doesn't feel like there was enough criticism against GitHub for their decision to ban the developer of faker/colors. HN, at least, had a ton of discussion on this[1]. People advocated both ways. > This was his own corner of the internet for him to publish his own personal projects. No, it wasn't. It was Github's corner of the internet and then it was Microsoft's. If he just wanted a place to publish his personal…

> By putting them on a social network, like Github, he is submitting to their whims. He doesn't have any legal right to stay on that site if they want to kick him off of it. Of course, legally speaking, Github can do whatever they want with their website, but we're not talking about the legal aspect. The developer community has put some trust on Github not to do whatever they want. It's an implicit, non-legal, non-en…

> but we're not talking about the legal aspect

Yes we are. I was responding to someone[1] who was alluding to the legal aspect using legal terms s/he clearly doesn't understand.

> > "What GitHub policy did he violate? The really outrageous thing is that the developer going "rogue" was actually him expressing his freedom of speech..."

1. https://news.ycombinator.com/item?id=29961662

Re: Faker.js is now a community controlled project

#136
post #78

Earlier quoted context omitted.

> By putting them on a social network, like Github, he is submitting to their whims. He doesn't have any legal right to stay on that site if they want to kick him off of it. Of course, legally speaking, Github can do whatever they want with their website, but we're not talking about the legal aspect. The developer community has put some trust on Github not to do whatever they want. It's an implicit, non-legal, non-en…

What you are going to get is people separating out into 2 camps, those that believe in individuality, and those that believe in more collectivism. This is a divide that extends well beyond programming and this topic. People that support GitHub actions believe in the concept of "greater good" and believe the actions of GitHub are ethical because it prevented harm to the community People that oppose GitHub actions reje…

> What you are going to get is people separating out into 2 camps, those that believe in individuality, and those that believe in more collectivism.

I am extremely individualistic. Github is also an "individual" that has its own private rights.

The author of this library absolutely had the right to write code, change it, etc. He does not have the right to use Github as a delivery mechanism for malware.

Re: Faker.js is now a community controlled project

#137

It doesn't feel like there was enough criticism against GitHub for their decision to ban the developer of faker/colors. This was his own corner of the internet for him to publish his own personal projects. I understand the decision for npm to take ownership of his packages, because npm is a community package repository owned by, and for, the community. All community package repositories have some sort of policy for p…

Freedom of speech doesn’t mean you can do whatever you want on someone else’s server. The project was hosted on GitHub, so GitHub can take significant action to protect the community. He can host his project elsewhere if he doesn’t agree with GitHub’s actions

Of course, no one is saying GitHub wasn't allowed to do what they did. What people are saying is GitHub shouldn't have done that.

Re: Faker.js is now a community controlled project

#138

It doesn't feel like there was enough criticism against GitHub for their decision to ban the developer of faker/colors. This was his own corner of the internet for him to publish his own personal projects. I understand the decision for npm to take ownership of his packages, because npm is a community package repository owned by, and for, the community. All community package repositories have some sort of policy for p…

[deleted]

Re: Faker.js is now a community controlled project

#139

It doesn't feel like there was enough criticism against GitHub for their decision to ban the developer of faker/colors. This was his own corner of the internet for him to publish his own personal projects. I understand the decision for npm to take ownership of his packages, because npm is a community package repository owned by, and for, the community. All community package repositories have some sort of policy for p…

I am completely baffled by folks defending Marak, or putting any sort of blame on GitHub. What Marak did was not "political speech". If he wanted to, he could have easily done any of the following: 1. Pulled down his repo, or replace his repo by whatever message he wanted to send. 2. Output his political message during the build. 3. Heck, all faker.js does is output fake data for things like names and addresses. I th…

Correct. You basically never have the right to commit sabotage

Re: Faker.js is now a community controlled project

#140

It doesn't feel like there was enough criticism against GitHub for their decision to ban the developer of faker/colors. This was his own corner of the internet for him to publish his own personal projects. I understand the decision for npm to take ownership of his packages, because npm is a community package repository owned by, and for, the community. All community package repositories have some sort of policy for p…

> "The really outrageous thing is that the developer going "rogue" was actually him expressing his freedom of speech, again on his own personal GitHub account, in his own personal (not organization) repositories. He spoke about his thoughts about open source, businesses, and economics. Defending this type of political speech is especially important and GitHub banning his account and censoring this type of speech(whet…

He wasn't crippling his own functionality though, he was deliberately crippling the functionality of everyone who trusted him.
Post reply on HN