Live data from Hacker News

Faker.js is now a community controlled project

fakerjs.dev

271–280 of 357 posts

Re: Faker.js is now a community controlled project

#271

Hmm, but as I understand original developer was rather pissed off by situation when devs are working on projects in theirs own time, and those projects sometimes become important tools to lower costs of creating software for big companies, and authors are not getting a dime and are forced to use some kinds of sponsorship and so on.... In such case making one of tools "community" owned smells like some kind of dick mo…

I've already posted this before, but what Marak has done is anything but reasonable. If anyone was being a "dick", it was him. If he just wanted corporations to pay, there are plenty of other alternatives like changing the license for future versions like SugarCRM did. It's been years since they've done that and they have plenty of customers. https://sugarclub.sugarcrm.com/engage/b/sugar-news/posts/sug... Since the d…

Morally the author is in the wrong according to many. He did publish malicious versions against the short term interest of the community.

However he also distributed the software under the MIT license - that is "as-is" and "without warranty of any kind". So I'm having some trouble understanding why would you point out his personal life, psychological state, or his past projects as justification for anything related to Faker?

I haven't checked earlier versions of Faker but 5.5.3 does credit both the Ruby and the Perl libraries.

Re: Faker.js is now a community controlled project

#272
I was out of the loop on this and I stumbled across this -> Neighbor on Queens man with bomb-making equipment: 'Obviously the man is sick'[0]. This is just weird. It isn't like what the OS community could have done for him, it is what he should have done for his mental health.

0: https://abc7ny.com/suspicious-package-queens-astoria-fire/64...

Re: Faker.js is now a community controlled project

#273

Isn’t calling this “malicious” a bit of a stretch? It’s not like he is mining crypto on your machine. It’s a (however misguided) act of protest and demand for attention. Fine GitHub put the breaks on in case it was an account takeover but they should allow him to do whatever he wants with his repos once it confirms it’s really him. Also npm just removes his access…? If I was the author of a popular npm package and de…

I'd argue this is a denial of service attack, inconveniencing the target and possibly costing them money but without stealing or destroying anything.

Re: Faker.js is now a community controlled project

#274

Earlier quoted context omitted.

It was a malicious act to the users of his project, sure. But how was it a malicious act to GitHub? I'm glad to hear that they reversed the suspension, but without understanding why it was suspended in the first place, it leaves open the question of what GitHub's motives were in the whole situation. If DHH decided that Rails was contributing more harm to the world then good, and tried to remove it from GitHub, would…

Github will not allow you to use your personal corner of the platform to propagate malware, and hasn't allowed it for many years.

Breaking a build in a way that is trivially rolled back is not in the same league as pushing code that harvests email addresses, CCs and mines bitcoin.

I'm disappointed to see this kind of comparison made.

Re: Faker.js is now a community controlled project

#275

Earlier quoted context omitted.

It was a malicious act to the users of his project, sure. But how was it a malicious act to GitHub? I'm glad to hear that they reversed the suspension, but without understanding why it was suspended in the first place, it leaves open the question of what GitHub's motives were in the whole situation. If DHH decided that Rails was contributing more harm to the world then good, and tried to remove it from GitHub, would…

Github will not allow you to use your personal corner of the platform to propagate malware, and hasn't allowed it for many years.

It was a bit of code printing ascii art in a loop, with a preceding comment "don't commit this", and we have bo information about whether it was put into the release on purpose or malicious intent afaik. Is it really malware?

Re: Faker.js is now a community controlled project

#276

Earlier quoted context omitted.

I don't think what he did was particularly good but I think he was entitled to do it. And the blame falls on the system we have which relies on random people to do work for free with no contract or obligation. It's like if a business delivered packages by asking some random homeless person on the street to walk it to its destination. And then one day the person just chucks your package in the river instead of deliver…

> I don't think what he did was particularly good but I think he was entitled to do it. And the blame falls on the system we have which relies on random people to do work for free with no contract or obligation. Utter nonsense. You don't put out code under open-source MIT and then want to take it back when you realize other people are using it exactly as you instructed them to use it , which in this case is "anyway t…

The MIT license doesn't prevent you from doing this. If someone cloned the repo, they could continue doing whatever they wanted with it, but the owner is entitled to put up whatever new code they want on their repo.

Re: Faker.js is now a community controlled project

#278
I don't understand how you can "commandeer" the fakerjs identity. I realize you can fork and maintain said fork, but to take a) the name (which should be protected as a copyright, no?), b) the sponsors (this feels very unethical if not illegal). You can't assign yourselves as the successor to a project. You can be a "spiritual successor", but unless Marak officially hands the mantle over to you, you're thing is just a fork. Surely if all 8 of you are engineers as in the intro, you had to learn some sort of curricula on professional ethics.

Re: Faker.js is now a community controlled project

#279
post #262

Earlier quoted context omitted.

What he did was utterly unprofessional, hazardous, and outright dangerous to those who trusted and used his library. By putting it on Github, he surrendered a portion of his right to distribute to Microsoft, and Microsoft did the best course of action to protect their reputation and the interest of their stakeholders. I see nothing wrong with this.

> professional then pay him? I'd admit that this person didn't really contribute anything really worthy. But please do not require someone to be "professional" when you did not pay him a dime.

Unprofessional as in done by a person I wouldn't hire in his current mental state.

Re: Faker.js is now a community controlled project

#280

Earlier quoted context omitted.

> What surprises me is the amount of support he’s garnered for his actions with a lot of people on HN. Well, his motivations were somewhat understandable and his actions were still scratching the realm of acceptable (not cool, but no serious damage and nobody was hurt). It's actually hitting the pretty much perfect spot to generate lots of discussions, since it's very easy and understandable to argue for either side.

What he did was no where near acceptable. Instead of adding an infinite loop to purposely sabotage other projects, he should have either walked away or changed the license for future versions of faker into a much more restricted one. SugarCRM transitioned their software from open source to closed source, and they’re still here with paying customers. There are also many restrictive licenses that change depending on th…

> What he did was no where near acceptable.

It was a rebellious act against (what seems like) overbearing organizations, comparable to spraying a graffiti on their walls. As I said, there was no serious damage and nobody was hurt; it's not like he burned down buildings or shot at people. I'm of the opinion that this was not the right way as well, but in the end it really wasn't that bad.

Post reply on HN