Earlier quoted context omitted.
> The new project taking over the name and URL of the old project doesn't make it "the same" project. Do you really think the sponsors and the people using this code actually care that one person (of many contributors to the project) who wanted to break the project is no longer part of the project? It's a technicality, but in practice nobody actually cares. If they wanted to sponsor Marak they would have done it thro…
Ok, but the question is, what entitles these people, rather than other to claim a fork as "community successor"?
Faker.js is now a community controlled project
211–220 of 357 posts
Re: Faker.js is now a community controlled project
#212Earlier quoted context omitted.
> but you are relying on people (who were never aware of the switch and the new fork) being okay with this, without their consent. Open Collective makes it clear that the sponsorship is for the project, not for a specific person. It's not "without their consent". It's literally the terms of the Open Collective.
Does it matter what Open Collective thinks if most people believe this is immoral?
Re: Faker.js is now a community controlled project
#213Earlier quoted context omitted.
> It was malicious act to Github's users. I'm not sure why it matters they are Github users. The packages were hosted on npm through Cloudflare - does that allow Cloudflare to take over the packages too? And NS1 since they host the fakerjs domain?
It’s cool that you’re internet rules-lawyering and all but ultimately he used his free account with intent to harm others, just as surely as if he backdoored his code. Freedom of speech is good, and protest is fine, but why would GitHub amplify the speech of a nutso who abused his position of trust?
Re: Faker.js is now a community controlled project
#214Earlier quoted context omitted.
Quoted post unavailable.
> I strongly encourage you to stop making false allegations. I encourage you to find out the definition of Trojan[1] and then find out what Marak did to sabotage his code. To qualify as a Trojan, Faker.js needed to be: - advertised as being for a certain purpose - coded to do something to damage the person who installs it (even if it still does the thing it advertises that it does) In this case, Marak allowed people…
http://www.catb.org/jargon/html/T/Trojan-horse.html
If it isn't security-breaking, it isn't a Trojan. I have not seen any evidence that this prank, immature as it may be, resulted in an actual security breach.
Re: Faker.js is now a community controlled project
#215It doesn't feel like there was enough criticism against GitHub for their decision to ban the developer of faker/colors. This was his own corner of the internet for him to publish his own personal projects. I understand the decision for npm to take ownership of his packages, because npm is a community package repository owned by, and for, the community. All community package repositories have some sort of policy for p…
He's not banned. It was most likely an initial response to a suspected compromised account situation. Once they determined the actions were carried out by the account holder, they reinstated it.
There are MANY reasons to be annoyed with GitHub but this isn't one of them. Github's actions here helped, not hurt. I would hope they'd suspend my account if they too thought it was compromised and pushing out malicious updates to packages.
The security of users is of the utmost importance.
Marak needs professional medical help. It is clear he's having a mental break and the people defending him and egging him on are only making things worse. He has a history of erratic behavior (dating back to almost a decade ago) and needs to find healing, not accolades.
Since this whole fiasco, Marak has garnered loads of followers and has increased his sponsor count dramatically. We should not be rewarding this behavior. If you at all dig into this, you'll find not a stable, perhaps loud individual, but a troubled, erratic, unpredictable, and hurting one. He is not martyr. He's not a patriot or a revolutionist. He's an abuser, potential "freedom fighter", malicious OSS maintainer and a beggar.
Please. Let's end this and not give any more attention to Marak. He needs help, and we're all collectively making things worse.
Re: Faker.js is now a community controlled project
#216Earlier quoted context omitted.
I'm not sure how we get to me-first when the story is one actor using the wide-cast popularity of packages he had admin rights to to intentionally cause harm. It's a "the needs of the many outweigh the needs of the few" situation.
It's a bit mind-boggling that FOSS authors who give their work away for free are the selfish baddies, and Microsoft of all people, are the communistic heroes in your telling.
But Marak specifically is, and Microsoft being the good actor is indicative of how badly he messed up.
If his goal was to make a statement about big corporations taking more than they give to FOSS, arranging things so Microsoft gets to be the hero was a foolish way to go about it.
Re: Faker.js is now a community controlled project
#217Earlier quoted context omitted.
> solve the problem of a trusted developer suddenly becoming untrustworthy? This would be an exceptionally hard problem to solve, with-or-without blockchain. Could you develop a system where any new releases are required to be reviewed and "signed off" by a random assortment of users before becoming "active"? Sure. Is "blockchain" necessary for that? No.
I find this line of thinking frustrating and dismissive of new(er) technology. Is "blockchain" necessary for anything? Probably not. Is it potentially the best solution when compared to the alternatives and weighed on its pros and cons? Maybe - but one has to be willing to investigate before dismissing it.
In this situation, you are downloading code from a central authority, and have placed your trust there already. What benefit does a distributed solution give here?
Re: Faker.js is now a community controlled project
#218Earlier quoted context omitted.
I'm not sure how we get to me-first when the story is one actor using the wide-cast popularity of packages he had admin rights to to intentionally cause harm. It's a "the needs of the many outweigh the needs of the few" situation.
It's a bit mind-boggling that FOSS authors who give their work away for free are the selfish baddies, and Microsoft of all people, are the communistic heroes in your telling.
https://twitter.com/seldo/status/712417019686100992
https://blog.npmjs.org/post/141905368000/changes-to-npms-unp...
Re: Faker.js is now a community controlled project
#219Earlier quoted context omitted.
> I strongly encourage you to stop making false allegations. I encourage you to find out the definition of Trojan[1] and then find out what Marak did to sabotage his code. To qualify as a Trojan, Faker.js needed to be: - advertised as being for a certain purpose - coded to do something to damage the person who installs it (even if it still does the thing it advertises that it does) In this case, Marak allowed people…
A throwaway line in Wikipedia that does not cite a source ... versus the Jargon File. http://www.catb.org/jargon/html/T/Trojan-horse.html If it isn't security-breaking, it isn't a Trojan. I have not seen any evidence that this prank, immature as it may be, resulted in an actual security breach.
Re: Faker.js is now a community controlled project
#220Earlier quoted context omitted.
Open source works because we can trust authors to not maliciously harm other people. If it was a bug that's one thing it happens, you move on. But when you purposely do something that you know will cause harm to people that is where I draw the line. Your analogy isn't even close. No one forced him to write faker.js. He chose to do it and he chose to make it open source under a license allowing people to use it. He al…
He chose to put a package online. He didn't sign any contract stating the package would meet some kind of quality obligations. He had no obligation to do anything. Yes, it is particularly shitty to intentionally screw it up. But the system that put so much value on something not happening without any safeguards or obligations is the real problem. The move fast and break things attitude of web development is the cause…