Live data from Hacker News

Faker.js is now a community controlled project

fakerjs.dev

281–290 of 357 posts

Re: Faker.js is now a community controlled project

#281
post #30

Earlier quoted context omitted.

It was malicious act to Github's users. Github first responsibility comes to the community of users it supports, then to any individual user. Free speech/ personal choice / Freedom of expression come secondary to the welfare of its users. Is it a slippery slope ? Yes, but Github does not have a choice if it cared about the interest its community

> It was malicious act to Github's users. I'm not sure why it matters they are Github users. The packages were hosted on npm through Cloudflare - does that allow Cloudflare to take over the packages too? And NS1 since they host the fakerjs domain?

People point at github repositories all the time for packages.

Re: Faker.js is now a community controlled project

#282
post #262

Earlier quoted context omitted.

> professional then pay him? I'd admit that this person didn't really contribute anything really worthy. But please do not require someone to be "professional" when you did not pay him a dime.

Unprofessional as in done by a person I wouldn't hire in his current mental state.

> hire him

So what you do mean is someone had to spend hundreds of hours maintaining some projects you've been using and also should have perfect personality and well behaved enough before you hire him?

Re: Faker.js is now a community controlled project

#283
post #225

Earlier quoted context omitted.

It's a bit mind-boggling that FOSS authors who give their work away for free are the selfish baddies, and Microsoft of all people, are the communistic heroes in your telling.

> It's a bit mind-boggling that FOSS authors who give their work away for free are the selfish baddies This is a straw man. No one made this generalization. Marak, specifically, is a "selfish baddy", and it has nothing to do with FOSS. It has to do with his abuse of Github, npm, and Faker.js (which other people also contributed to ) to distribute malware. None of that can be generalized to a position about FOSS, Micr…

> or any other nonsense you're trying to extrapolate.

Sorry you were complaining about straw man arguments?

Re: Faker.js is now a community controlled project

#284

It doesn't feel like there was enough criticism against GitHub for their decision to ban the developer of faker/colors. This was his own corner of the internet for him to publish his own personal projects. I understand the decision for npm to take ownership of his packages, because npm is a community package repository owned by, and for, the community. All community package repositories have some sort of policy for p…

I am completely baffled by folks defending Marak, or putting any sort of blame on GitHub. What Marak did was not "political speech". If he wanted to, he could have easily done any of the following: 1. Pulled down his repo, or replace his repo by whatever message he wanted to send. 2. Output his political message during the build. 3. Heck, all faker.js does is output fake data for things like names and addresses. I th…

Indeed, he definitely could do his protest in a way which wouldn’t inconvenience billion dollar companies or even anyone.

Just like BLM could protest in a remote location or do an online petition. Except that no one would give a fuck about that. The same about a message during the build.

You call it a DoS attack, I call it a brownout warning about unsustainable open source funding. After all old versions are unaffected. No hidden RCE there. Only ones who opted in for pulling a new version without due diligence (aka free shit lovers) experienced a minor inconvenience. He didn’t do anything a malware author would do with such distribution channel.

I would definitely do it some other way, but can’t blame him. If he had put a notice during the build, no one would see it. If he added an unskippable five minute timeout to that message it would a DoS attack as well.

I suffered a similar “DoS attack” myself. By Microsoft. They did one hour brownout of Devops pipelines still using windows server 2016 or something, to warn about unsustainably of supporting them (striking similarity). Right at the moment we had to deploy an urgent hot fix for our client. If there was a notice somewhere, I didn’t read it. No one does. Which is why they do brownouts. He didn’t put an early warning, but that might be a difference between a multibillion company and some random guy on the internet.

He is unprofessional, but well, don’t expect professional behavior from people you don’t have professional relation with. Who I would call unprofessional, are the developers who expect free working shit from some random internet guy and have audacity to complain when he intentionally releases a broken version to protest taking free stuff without giving back.

I’m mildly entertained by the uproar caused by his protest. Reverting to an older version of a library is not an end of the world. I think it is not caused by the minor inconvenience he caused to the lazy devs, but by the threat of the end of relying on free work from open source devs.

We will have to do it ourselves or pay for it. Like in any other industry.

Re: Faker.js is now a community controlled project

#285
post #215

It doesn't feel like there was enough criticism against GitHub for their decision to ban the developer of faker/colors. This was his own corner of the internet for him to publish his own personal projects. I understand the decision for npm to take ownership of his packages, because npm is a community package repository owned by, and for, the community. All community package repositories have some sort of policy for p…

Chalk maintainer here. I said before I wouldn't comment on Marak but I don't want to stand by and watch him profit from this like he is, monetarily or otherwise, nor should GitHub receive ANY hate for their actions. He's not banned. It was most likely an initial response to a suspected compromised account situation. Once they determined the actions were carried out by the account holder, they reinstated it. There are…

maybe community should claim his personal account and get hold of those sponsors as well. in order to help marak and the whole community of course.

Re: Faker.js is now a community controlled project

#286

Earlier quoted context omitted.

I've already posted this before, but what Marak has done is anything but reasonable. If anyone was being a "dick", it was him. If he just wanted corporations to pay, there are plenty of other alternatives like changing the license for future versions like SugarCRM did. It's been years since they've done that and they have plenty of customers. https://sugarclub.sugarcrm.com/engage/b/sugar-news/posts/sug... Since the d…

Morally the author is in the wrong according to many. He did publish malicious versions against the short term interest of the community. However he also distributed the software under the MIT license - that is "as-is" and "without warranty of any kind". So I'm having some trouble understanding why would you point out his personal life, psychological state, or his past projects as justification for anything related t…

No court in the world will accept the MIT liability waiver as a defense, when the vendor intentionally distributed malicious code.

Re: Faker.js is now a community controlled project

#287
post #215

Earlier quoted context omitted.

Chalk maintainer here. I said before I wouldn't comment on Marak but I don't want to stand by and watch him profit from this like he is, monetarily or otherwise, nor should GitHub receive ANY hate for their actions. He's not banned. It was most likely an initial response to a suspected compromised account situation. Once they determined the actions were carried out by the account holder, they reinstated it. There are…

maybe community should claim his personal account and get hold of those sponsors as well. in order to help marak and the whole community of course.

This is a bad faith argument and a complete misinterpretation of what it is I've said.

Re: Faker.js is now a community controlled project

#288

Earlier quoted context omitted.

He chose to put a package online. He didn't sign any contract stating the package would meet some kind of quality obligations. He had no obligation to do anything. Yes, it is particularly shitty to intentionally screw it up. But the system that put so much value on something not happening without any safeguards or obligations is the real problem. The move fast and break things attitude of web development is the cause…

He did something much worse than break a contract, he committed a crime that he could probably be prosecuted for. He did the whole thing with malice aforethought. It looks like fraud at the very minimum - he released a version with the intent to deceive, victims relied on his deception, and they suffered damages as a consequence.

Fraud requires that he used deception (I don't see any evidence that he did) to obtain something of value (again, I don't see it).

The code was open source. The code was published under a new major version number. The code had a descriptive change log that definitely didn't seem congruent with earlier versions. And he wasn't getting paid for it. What thing of value did Marak Squires defraud people of?

I get the sense that people are reacting with extreme hyperbole in their accusations, out of anger that he did something assholish.

Serious question: how is this different from 1Password publishing an upgrade that removes the ability to use standalone vaults in the iOS Safari extension?

At the end of the day, Marak published an update, knowing some people would update the software automatically due to their own workflows, and the update had negative effects on the users. Companies do this all the time and nobody accuses them of installing a "Trojan Horse" or committing a felony.

How did it come to this? Where HN, a place that is supposed to be genuine and curious, believes an act should be acquiesced to or branded a felony based on the individual's personality? Because that seems to be the consensus here and I find it disturbing.

Re: Faker.js is now a community controlled project

#289
post #248

Earlier quoted context omitted.

> You aren’t in control on a platform that isn’t yours I wish everyone to read the above about 5 times and try to let it sink in.

I don't think I've seen a single person struggle with this concept. This isn't a "lesson" anyone needs learning, including Marak.

It absolutely is if you’ve read all the comments about this saga. So many people completely shocked that MS will unilaterally take access away for something they claim to be the right of the author.

“He can do whatever he wants. Users should just not download it.” Well, Microsoft can do whatever they want. And they did.

Re: Faker.js is now a community controlled project

#290
post #266

Earlier quoted context omitted.

I've already posted this before, but what Marak has done is anything but reasonable. If anyone was being a "dick", it was him. If he just wanted corporations to pay, there are plenty of other alternatives like changing the license for future versions like SugarCRM did. It's been years since they've done that and they have plenty of customers. https://sugarclub.sugarcrm.com/engage/b/sugar-news/posts/sug... Since the d…

> he must do this, he must do that. how about you do it for him? like forking and maintaining your own copy of faker.js and all the nodejs packages you are actively using in the first place? ad hominem does not help your argument.

The word "must" never appears in the comment you quoted.

Please read the comment before accusing its author of ad hominem attacks.

Post reply on HN