Live data from Hacker News

Faker.js is now a community controlled project

fakerjs.dev

231–240 of 357 posts

Re: Faker.js is now a community controlled project

#231
post #30

Earlier quoted context omitted.

It was a malicious act to the users of his project, sure. But how was it a malicious act to GitHub? I'm glad to hear that they reversed the suspension, but without understanding why it was suspended in the first place, it leaves open the question of what GitHub's motives were in the whole situation. If DHH decided that Rails was contributing more harm to the world then good, and tried to remove it from GitHub, would…

It was malicious act to Github's users. Github first responsibility comes to the community of users it supports, then to any individual user. Free speech/ personal choice / Freedom of expression come secondary to the welfare of its users. Is it a slippery slope ? Yes, but Github does not have a choice if it cared about the interest its community

This is an opinion you can have, but it's far from clear that it's an obvious or inherent one. What is the Github "community"? Who constitutes it? If I use Github for a personal project, and share the link with my friend, are we "part of the Github community"? How were we harmed by this incident? Did anyone say "We should shut Github down because they're irresponsibly hosting someone who would use his public JavaScript libraries to make a political statement"?

How was Github's community, specifically, harmed? A lot of developers were inconvenienced, but they would have been just as inconvenienced if he pushed the code to NPM from his local git repo, and never touched Github at all. Where does Github come into this?

Re: Faker.js is now a community controlled project

#232
post #193

Earlier quoted context omitted.

I'm just as much an armchair lawyer as the most of the rest of HN but my understanding is that liability waivers aren't considered enforceable if malicious intent or gross negligence is involved. Anybody with more legal expertise want to clarify?

I am also not a lawyer, but this is what I found for NY and would be surprised if it doesn't apply in most states and many other countries too: > Under New York law, a party can waive ordinary negligence, but not gross negligence, reckless conduct, willful/wanton conduct, or intentional acts. See Kalisch-Jarcho v. City of New York, 58 N.Y.2d 377 (1983); See also Restatement (Second) of Contracts § 195 (1981) (“A term…

This would be like suing a food pantry because they stopped giving out free food.

Re: Faker.js is now a community controlled project

#233

Earlier quoted context omitted.

> It was malicious act to Github's users. I'm not sure why it matters they are Github users. The packages were hosted on npm through Cloudflare - does that allow Cloudflare to take over the packages too? And NS1 since they host the fakerjs domain?

> does that allow Cloudflare to take over the packages too? Fundamentally cloudflare can do that if they so chose. If your threat model doesn't account for that sort of action then you should reassess.

Can != Should. we're not discussing whether Cloudflare had the physical capability of being able to take over the packages. We're asking if they should. Many people seem to believe that they should have, or would have been justified in doing so, and others disagree.

Re: Faker.js is now a community controlled project

#234
post #30

Earlier quoted context omitted.

It was a malicious act to the users of his project, sure. But how was it a malicious act to GitHub? I'm glad to hear that they reversed the suspension, but without understanding why it was suspended in the first place, it leaves open the question of what GitHub's motives were in the whole situation. If DHH decided that Rails was contributing more harm to the world then good, and tried to remove it from GitHub, would…

It was malicious act to Github's users. Github first responsibility comes to the community of users it supports, then to any individual user. Free speech/ personal choice / Freedom of expression come secondary to the welfare of its users. Is it a slippery slope ? Yes, but Github does not have a choice if it cared about the interest its community

> malicious act to Github's users

Usually if I modify my car in my own backyard (aka my property) it is nobody's business to intervene, as long as it's on my property.

Legally speaking, fakerjs was Marak's property and GitHub has no right to intervene with a legitimate user action.

I can see that they "tried their best" but we also have to uphold the law here. If GitHub, say, called him on his phone whether or not his actions were intended...they would've had to restore the account and the "broken" repository as it was before the suspension immediately...which I assume they did.

My point is mostly that there is no legal contract between Marak and the "community", as he was never paid anything. Some might argue about mitigations in between disagreeing parties, but as I said there's nobody forcing you to use his library, just as there was nobody forcing you to update.

It cannot be malicious intent if the other party is free to decide to just ignore it and move on.

Re: Faker.js is now a community controlled project

#235

Earlier quoted context omitted.

Funny how well that has worked until one person comes along and uses it to break people's software intentionally. At the very least, Marak is an example of why we can't have nice things. None of us are obligated to applaud him for that.

If someone hands out free food on the corner with a sign that says you aren't entitled to it and so you get used to getting free food there. In fact, you've found ways to save on your budget because of it. You also optimized your route home from work to get there at the most convenient time. One day, you show up and they have a sign up that says... No more free food, vote for Bernie. Are you really the type to compla…

But he didn't withdraw his offering he sabotaged it.

I guess the metaphor would be if you gave out free food all the time with a sign saying people aren't entitled to it, and then one day decided to add laxatives to it because you felt the people were ungrateful.

Which would land you in jail for a long time no matter what the sign said.

Re: Faker.js is now a community controlled project

#236
post #78

Earlier quoted context omitted.

What you are going to get is people separating out into 2 camps, those that believe in individuality, and those that believe in more collectivism. This is a divide that extends well beyond programming and this topic. People that support GitHub actions believe in the concept of "greater good" and believe the actions of GitHub are ethical because it prevented harm to the community People that oppose GitHub actions reje…

Yeah, but most vocal proponents of so-called "individuality" are simply self-centered anti-social assholes who haven't thought through the Libertarian ideologies they parrot deeply enough to realize how extremely dependent on and beneficial from collectivism they actually are, and they continue bitching about "socialism" while sucking the government's tit with their social security and disability benefits and medicar…

[deleted]

Re: Faker.js is now a community controlled project

#237

Earlier quoted context omitted.

> used his free account with intent to harm others, just as surely as if he backdoored his code There's a huge difference between displaying a message and going in an endless loop and backdooring as in providing an alternative access to control a system you're not supposed to have access to. Words have meaning. This wasn't a backdoor.

There is a difference between robbery and burglary.

There’s a difference between a simile and a metaphor too, but GP is ignoring the fact I used one of those entirely.

Re: Faker.js is now a community controlled project

#238

Earlier quoted context omitted.

It's a DoS attack disguised as other, useful software. That's exactly what a Trojan is.

It isn't disguised as anything. If you included a random module in your application package manager, and allowed it to update itself and run scripts then liability is on you for not verifying it and checking the license to see if they provided any warranty.

But is this really a "warranty" issue? Sounds more like a fraud issue (ianal).

Given it was done with the intention of messing up other people's computers which the maintainer did not have legit access to - maybe its even a CFAA criminal hacking issue (ianal).

Anyways, there's a huge difference between accidentally doing something and doing something with the specific intention of hurting someone else. Sure you can disclaim responsibility for accidents & negligence, but i'm pretty sure you can't disclaim responsibility for intentionally malicious conduct in a contract, certainly you wouldn't be able to do so if it was criminal conduct (IANAL).

Re: Faker.js is now a community controlled project

#239

Earlier quoted context omitted.

It was a malicious act to the users of his project, sure. But how was it a malicious act to GitHub? I'm glad to hear that they reversed the suspension, but without understanding why it was suspended in the first place, it leaves open the question of what GitHub's motives were in the whole situation. If DHH decided that Rails was contributing more harm to the world then good, and tried to remove it from GitHub, would…

Github will not allow you to use your personal corner of the platform to propagate malware, and hasn't allowed it for many years.

Exactly this. The changes were intentional malware, designed to break the usage of these two modules. GitHub is under no obligation to assist you in hosting malware. The fact that these changes were intended by the original author has no bearing in this situation.

Re: Faker.js is now a community controlled project

#240

Earlier quoted context omitted.

It was a malicious act to the users of his project, sure. But how was it a malicious act to GitHub? I'm glad to hear that they reversed the suspension, but without understanding why it was suspended in the first place, it leaves open the question of what GitHub's motives were in the whole situation. If DHH decided that Rails was contributing more harm to the world then good, and tried to remove it from GitHub, would…

> It was a malicious act to the users of his project, sure. But how was it a malicious act to GitHub? You can't use GitHub to perform malicious acts, even if the victim isn't GitHub. GitHub isn't obligated to support anyone's malicious acts with their platform. > If DHH decided that Rails was contributing more harm to the world then good, and tried to remove it from GitHub, would GitHub lock his account and restore h…

> GitHub isn't obligated to support anyone's malicious acts with their platform.

Github isn't obligated to support anyone's anything, your relationship with Github is entirely at-will. And yet, I believe that there are moral boundaries on how Github should act, and that different people can disagree on where those boundaries are. I do not believe that "updating a popularly used library to break it's core functionality" is harmful enough to the other users of Github-the-code-hosting-site that it necessitates intervention from the owner of the platform. I think specifically that the way in which Github came to the determination that this change was "malicious" is unclear, and that Github very clearly has a conflict of interest when it comes to determining which sorts of political speech are "malicious", and which sorts are allowed.

> GitHub hasn't done any of these things with faker.js.

Correct, that's why it's a hypothetical question. If Github is willing to intervene against "malicious behavior" on behalf of "the community", then the obvious question is "which behavior, and which community?"

As another hypothetical example, the https://996.icu/ website is hosted on Github. Chinese browser manufacturers have implemented a pop-up that calls it a "illegal and fraudulent site" if you navigate to the repo. Is this "malicious" behavior? Many in China would think so, and definitely the browser manufacturers seem to believe that it's malicious behavior targeted at Chinese tech companies. Should users be allowed to use Github to perform this "malicious" act, even if the victim isn't Github itself? If Microsoft was criticized for their Chinese offices' working conditions on the site, do you think this would change their viewpoint on whether the repo should stay up? Personally, I would hope that those within Github who are responsible for making such a decision wouldn't take such personal matters into consideration.

> Reference to a conspiracy theory

I'll be honest, I didn't know this was in reference to a conspiracy theory. Aaron Swartz was driven to suicide by the relentless and cruel prosecution of the United States government, and the inaction of the MIT administration. That incident is tragic and sad enough as is, and I hope it goes without saying that don't agree with anyone attempting to co-opt that tragedy for their own conspiracy theories about Qanon. But I don't think Github should be responsible for making the call on whether something is "good" enough political speech to be worth protecting.

Post reply on HN