Earlier quoted context omitted.
> It was malicious act to Github's users. I'm not sure why it matters they are Github users. The packages were hosted on npm through Cloudflare - does that allow Cloudflare to take over the packages too? And NS1 since they host the fakerjs domain?
It’s cool that you’re internet rules-lawyering and all but ultimately he used his free account with intent to harm others, just as surely as if he backdoored his code. Freedom of speech is good, and protest is fine, but why would GitHub amplify the speech of a nutso who abused his position of trust?
At no point down the road should that involve revoking someone's ownership of a software project, though. Software ownership is sacred, not just because of tradition but because understanding who owns your packages and libraries is paramount to auditing security. Some of the most valuable contributions to computer science have been ones that allow people to verify integrity, be it SHA, TLS or GPG. If Microsoft abuses their position of power to break that chain of integrity, how can we be sure that other repos belong to their respective authors?
I can understand if you, the individual don't find this interesting or consider it inconsequential to your workflow. But other people rely on it, and you can't pretend like an honest chain of custody is somehow valueless.