Earlier quoted context omitted.
Quoted post unavailable.
To an automated protection system that detects “repo deletion + index.html rant” commits, deleting the codebase and updating the README would red flag instantly except for the different filename, and catch lots of garden-variety intrusions. The deletion here was more complex, and most likely a human was assigned to review user reports to GitHub Security, who accurately determined it was a defacement from someone clai…
Faker.js is now a community controlled project
241–250 of 357 posts
Re: Faker.js is now a community controlled project
#242Earlier quoted context omitted.
I see only one of those alleged "nutso's", and that was GitHub. Everyone else should have been responsibly consuming the dependency. You don't get to call foul when you knowingly use something for something important and don't check to make sure it is okay.
Setting your package version to allow for minor updates _is_ responsibly consuming the dependency.
If you do test and isolate testing environment then this kind of breaking update is just business as usual.
Re: Faker.js is now a community controlled project
#243It doesn't feel like there was enough criticism against GitHub for their decision to ban the developer of faker/colors. This was his own corner of the internet for him to publish his own personal projects. I understand the decision for npm to take ownership of his packages, because npm is a community package repository owned by, and for, the community. All community package repositories have some sort of policy for p…
The fact that the conversation is happening at all is a sign that GitHub reputation is damaged. As anyone would point out they are certainly within their rights to terminate any account for any reason. But certainly not beyond repair (as injecting adware in your package). Also it is certainly a reminder for everyone that GitHub should not be treated as an archive of your code, and more like a collaboration space.
Re: Faker.js is now a community controlled project
#244It doesn't feel like there was enough criticism against GitHub for their decision to ban the developer of faker/colors. This was his own corner of the internet for him to publish his own personal projects. I understand the decision for npm to take ownership of his packages, because npm is a community package repository owned by, and for, the community. All community package repositories have some sort of policy for p…
he did it to protest billion dollar tech companies making money off open source, which is Github's entire business model. His protest was an existential threat to them so of course they are going to crack down
Re: Faker.js is now a community controlled project
#245It doesn't feel like there was enough criticism against GitHub for their decision to ban the developer of faker/colors. This was his own corner of the internet for him to publish his own personal projects. I understand the decision for npm to take ownership of his packages, because npm is a community package repository owned by, and for, the community. All community package repositories have some sort of policy for p…
I am completely baffled by folks defending Marak, or putting any sort of blame on GitHub. What Marak did was not "political speech". If he wanted to, he could have easily done any of the following: 1. Pulled down his repo, or replace his repo by whatever message he wanted to send. 2. Output his political message during the build. 3. Heck, all faker.js does is output fake data for things like names and addresses. I th…
"1,2,3" Honestly, these ARE better things to do (and probably more effective) than what Marak has done.
"replaced his code with an infinite loop that was a DoS attack" So far I haven't seen anything about this actually causing harm and denying service.
"The fact that his attack wasn't more severe (like, say, encrypting someone's hard drive) doesn't mean it wasn't an actual attack." The fact that his attack wasn't more severe shows that he wanted something that would make an impact without hurting anyone.
" guarantee no legal system is going to let an actual malicious act be defended by a license. " That's the legal system's problem. The license is the license. Somebody's violation of an EULA (because they didn't read it) may be in all ways justified, but that argument probably won't hold up in court.
I wish he did something less controversial while still impactful, but it is incorrect to put it under the same term used to describe real cyberattacks that severely harm and kill innocents.
Re: Faker.js is now a community controlled project
#246Earlier quoted context omitted.
A throwaway line in Wikipedia that does not cite a source ... versus the Jargon File. http://www.catb.org/jargon/html/T/Trojan-horse.html If it isn't security-breaking, it isn't a Trojan. I have not seen any evidence that this prank, immature as it may be, resulted in an actual security breach.
The term is derived from the ancient Trojan Horse. It doesn’t have to involve security breaches because the only requirement is a breach of trust through deceit.
Then it isn't a Trojan. By definition.
"A malicious security-breaking program that is disguised as something benign"
Re: Faker.js is now a community controlled project
#247Earlier quoted context omitted.
Marak isn’t the only one who snapped, but he’s the only one to my knowledge who has introduced malicious commits to this code to purposely hurt other people’s projects. (Even Hans Reiser didn’t do that.) It seems that this might have been a precursor to Marak attempting to hurt people in real life " Hospitalized Queens man charged with reckless endangerment after cops find bomb-making materials in his home " https://…
I'm sure 6.6.6 threw a spanner in the works for folks who didn't lock deps. Not great. But Marak's one of us. This feels a lot bigger than that. I don't have a direct line on what happened to him, or where it took him, mentally or otherwise. But the hints so far aren't great. To one of us. I think the responses from the platforms---GitHub, OpenCollective---get folks thinking, whether they feel it that way or not.
One of who, exactly? Marak needs professional help. This isn't a "personal army" situation.
Re: Faker.js is now a community controlled project
#248You aren’t in control on a platform that isn’t yours. You don’t have rights. If you want to behave like a child, Microsoft may very well just take the keys away from you.
> You aren’t in control on a platform that isn’t yours I wish everyone to read the above about 5 times and try to let it sink in.
Re: Faker.js is now a community controlled project
#249Earlier quoted context omitted.
> That seems exactly like the definition of a Trojan to me. Link to even one report of Marak getting inside someone else's system.
You seem to be misunderstanding what a Trojan is. From Wikipedia: > In computing, a Trojan horse is any malware that misleads users of its true intent. The term is derived from the Ancient Greek story of the deceptive Trojan Horse that led to the fall of the city of Troy. > Trojans generally spread by some form of social engineering; for example, where a user is duped into executing an email attachment disguised to a…
Wikipedia doesn't define industry terms, especially in one-off throwaway lines without citations.
The Jargon File clearly defines a Trojan as something that (1) breaks your security and (2) is disguised as something benign.
http://www.catb.org/jargon/html/T/Trojan-horse.html
Unless you can show Marak Squires breached these folks security systems, it simply is not a Trojan.
(As a separate point, a claim that something distributed as source code is "disguised" simply cannot be in good faith.)
By claiming it is a Trojan, you are accusing Marak Squires of a potential felony by accessing a computer system without authorization. Making serious accusations like that should require some evidence. I don't see any.
Re: Faker.js is now a community controlled project
#250Earlier quoted context omitted.
It was malicious act to Github's users. Github first responsibility comes to the community of users it supports, then to any individual user. Free speech/ personal choice / Freedom of expression come secondary to the welfare of its users. Is it a slippery slope ? Yes, but Github does not have a choice if it cared about the interest its community
This is an opinion you can have, but it's far from clear that it's an obvious or inherent one. What is the Github "community"? Who constitutes it? If I use Github for a personal project, and share the link with my friend, are we "part of the Github community"? How were we harmed by this incident? Did anyone say "We should shut Github down because they're irresponsibly hosting someone who would use his public JavaScri…