Live data from Hacker News

Faker.js is now a community controlled project

fakerjs.dev

321–330 of 357 posts

Re: Faker.js is now a community controlled project

#321
post #194

Earlier quoted context omitted.

You don't get to tell other people what they should do for you.

But you do get to criticize poor judgement and provide reasonable alternative courses of action.

Nice bait-and-switch, but we can scroll back and see how relevant your defense of the comment I responded to really is.

Declamations are fine; declarations about what is "acceptable" and what "they should have done" are more than mere criticism of poor judgement, etc., and are what the author of the comment I responded to actually wrote.

Re: Faker.js is now a community controlled project

#322

Earlier quoted context omitted.

Except that it was his code, and it's open source therefore the risk of using said code is your own. It's his project, He's under no obligation to maintain it in a functional state or at all just because you happen to use it. That's just egotistical and narcissistic on your part

You're wrong. If I routinely share my lunch with someone at work, I don't get to poison it because "It's my sandwich, I'm under no obligation to make sure it's safe just because you happen to eat it." Hell, I can't poison it even if someone's stealing my lunch. I can't create code with malware. I can't modify my code to make it malware. That's a crime. You're wrong

Everything about your comment is wrong. For one you're not giving your lunch to anyone, More analogously you're putting something in the refrigerator, and people can take at their own leisure and risk. You can poison it if you want, in fact it's a pretty common workplace tactic for people to mix in something like a laxative to THEIR OWN food because they're tired of it being stolen everyday. Again you make the choice to use the software, or take the food, the risk is on your head.

And the cybersecurity industry would like to have a word with you since you don't believe it's possible to create malware.

Re: Faker.js is now a community controlled project

#323
post #306

Earlier quoted context omitted.

GitHub is under no obligation to distribute further versions. Neither is Marak under any obligation to maintain and upkeep the repository. While in bad faith of the community, you are the consumer who CHOSE to use his software, free and at no cost to yourself. You have no right to dictate how that repository is used, especially if you never donated or contributed to the project itself.

> While in bad faith of the community, you are the consumer who CHOSE to use his software, free and at no cost to yourself. You have no right to dictate how that repository is used, especially if you never donated or contributed to the project itself. Either we're going by a legalistic interpretation of the terms in which case Marak was free to fuck up his project and github was free to kick him off npm for it, or we…

I don't have a problem with GitHub or NPM taking down his project. Just like I don't have a problem with him poisoning it if he so chose. I do have a problem with people here whining about their own selfish wants. Again not one person is obligated to use faker.js, if you wanted the security that parts of your code base would not be tampered with, then you probably shouldn't have been using a third party library that wasn't under your control in the first place. Common sense is all too lacking here across the first world.

Re: Faker.js is now a community controlled project

#324
post #307

Earlier quoted context omitted.

If we're stressing the analogy, Marak put food out in a park with a sign "Take the food, just tell everyone you got it from Marak, quality not guaranteed". Then one day the food had laxatives because he felt not enough people put money in the tip jar. I think that would still be actionable. Most people wouldn't bother, just like I don't think anyone is seriously thinking of taking Marak to court over what is mostly b…

There was no more "food". An loop in a script isn't malicious, as a user can terminate a script and by running an unknown script they are assuming some liability as well. What you're advocating for is that if an open source developer changes their code, even to say, prompt the user to confirm executing when before they didn't prompt and that somehow breaks automation that the user has built (not the developer) then t…

"By eating food of unknown provenance they are assuming some liability as well" isn't really an argument that would hold up in a court of law if someone intentionally taints the food.

> What you're advocating for is that if an open source developer changes their code, even to say, prompt the user to confirm executing when before they didn't prompt and that somehow breaks automation that the user has built (not the developer) then they should be liable for harm.

We should probably divide the conversation into two threads: one on the tainted-food analogy, and one on the changing-code reality. Because they aren't the same, and one can reach weird conclusions trying to conflate them.

Liability for tainted food is pretty settled law. If someone eats your food and gets sick, it's a problem for you. If they eat it and get sick and can prove you poisoned it, it's a real problem with real legal consequences. Food handlers and preparers go out of their way to avoid both of those scenarios.

Intentionally modifying code knowing you'll break downstream consumers hasn't been tested (to my knowledge) in court, so we can set that aside. But is it immoral? That's going to depend on one's morality, but I have a hard time seeing my way to agreeing with the standpoint "Sure, it's moral. User beware." That principle, written large, creates a strictly worse world, where people are hiding in their digital caves, unable to trust anything outside. A lot of people (including GitHub and NPM's owners) are trying ot build something better than that.

Marak had a right to do what he did, but that doesn't mean it was right, we don't have to agree that "because he could, it was good" (that's just rule-by-power, and almost nobody thinks that's a good moral philosophy), and I applaud the open-source community who stepped in to minimize his harm.

Re: Faker.js is now a community controlled project

#325
post #321

Earlier quoted context omitted.

But you do get to criticize poor judgement and provide reasonable alternative courses of action.

Nice bait-and-switch, but we can scroll back and see how relevant your defense of the comment I responded to really is. Declamations are fine; declarations about what is "acceptable" and what "they should have done" are more than mere criticism of poor judgement, etc., and are what the author of the comment I responded to actually wrote.

> Instead of adding an infinite loop to purposely sabotage other projects, he should have either walked away or changed the license for future versions of faker into a much more restricted one

Then from the context, you can clearly read the comment you responded to did not mention that Makar needed to do anything for him specifically.

Re: Faker.js is now a community controlled project

#326
post #306

Earlier quoted context omitted.

> While in bad faith of the community, you are the consumer who CHOSE to use his software, free and at no cost to yourself. You have no right to dictate how that repository is used, especially if you never donated or contributed to the project itself. Either we're going by a legalistic interpretation of the terms in which case Marak was free to fuck up his project and github was free to kick him off npm for it, or we…

I don't have a problem with GitHub or NPM taking down his project. Just like I don't have a problem with him poisoning it if he so chose. I do have a problem with people here whining about their own selfish wants. Again not one person is obligated to use faker.js, if you wanted the security that parts of your code base would not be tampered with, then you probably shouldn't have been using a third party library that…

At the end of the day, open source is built on trust. Even the more paranoid-architected flows outside of npm (checksums via side-channel, curated package distributions maintained by a third-party such as debian) don't protect the end-user from actual malicious action on the part of the trusted source. Consider the story of how Univesity of Minnesota got banned from adding patches to Linux (https://www.theverge.com/2021/4/30/22410164/linux-kernel-uni...). In that case, they were caught. But if they weren't caught (or if a critical mass of Linux maintainers went rogue and were in on it)? Enough malicious actors with the right credentials can publish and checksum a damaging package in any system that allows code reuse. It is, perhaps, riskier to rely on a system with one maintainer. If that's the case, moving Faker .js to community controlled was a great first step in restoring trust in the package; it's harder to compromise a group.

We can sit here and cluck our tongues and say "Should have known better than to trust someone else's code," but that's just victim-blaming. Marak broke trust. He took advantage of a system with a vulnerbility and he exploited it. And everybody uses a system that is vulnerable in some way.

Because he did this, the system interpreted his actions as damage and routed around them. The system may change to make this attack harder in the future. And the result will be more complex and have more failure modes, and everything will be slightly worse as a result because we have to replace with process what we were previously able to do with human-to-human trust. "Nice job breaking it, hero."

Re: Faker.js is now a community controlled project

#327

Earlier quoted context omitted.

You're wrong. If I routinely share my lunch with someone at work, I don't get to poison it because "It's my sandwich, I'm under no obligation to make sure it's safe just because you happen to eat it." Hell, I can't poison it even if someone's stealing my lunch. I can't create code with malware. I can't modify my code to make it malware. That's a crime. You're wrong

Everything about your comment is wrong. For one you're not giving your lunch to anyone, More analogously you're putting something in the refrigerator, and people can take at their own leisure and risk. You can poison it if you want, in fact it's a pretty common workplace tactic for people to mix in something like a laxative to THEIR OWN food because they're tired of it being stolen everyday. Again you make the choice…

You're wrong. You literally just described assault or (best case scenario) a tort

https://law.stackexchange.com/questions/966/can-one-be-liabl...

> I can't create code with malware. I can't modify my code to make it malware.

I guess I can appreciate your confusion but I still think I was clear in my previous comment. I'm willing to concede I would have been more clear if I had written:

I can't legally create code with malware to distribute without a warning. I can't legally modify my code to make it malware if I know people are using it.

PS I'm not discussing this further

Re: Faker.js is now a community controlled project

#328

Earlier quoted context omitted.

I've already posted this before, but what Marak has done is anything but reasonable. If anyone was being a "dick", it was him. If he just wanted corporations to pay, there are plenty of other alternatives like changing the license for future versions like SugarCRM did. It's been years since they've done that and they have plenty of customers. https://sugarclub.sugarcrm.com/engage/b/sugar-news/posts/sug... Since the d…

Morally the author is in the wrong according to many. He did publish malicious versions against the short term interest of the community. However he also distributed the software under the MIT license - that is "as-is" and "without warranty of any kind". So I'm having some trouble understanding why would you point out his personal life, psychological state, or his past projects as justification for anything related t…

In the spirit of the law, that license is meant to protect authors from honest mistakes. I highly doubt that purposely made malicious changes will fully protect authors.

Re: Faker.js is now a community controlled project

#329
post #266

Earlier quoted context omitted.

I've already posted this before, but what Marak has done is anything but reasonable. If anyone was being a "dick", it was him. If he just wanted corporations to pay, there are plenty of other alternatives like changing the license for future versions like SugarCRM did. It's been years since they've done that and they have plenty of customers. https://sugarclub.sugarcrm.com/engage/b/sugar-news/posts/sug... Since the d…

> he must do this, he must do that. how about you do it for him? like forking and maintaining your own copy of faker.js and all the nodejs packages you are actively using in the first place? ad hominem does not help your argument.

You either didn’t read my comment, or you meant to respond to a different one. He didn’t have to do anything. He could have just walked away.

I only wrote the other stuff to show that there are other better alternatives to getting paid as a response to people who supported the terrible thing that Marak did to open source.

Re: Faker.js is now a community controlled project

#330

Earlier quoted context omitted.

What he did was no where near acceptable. Instead of adding an infinite loop to purposely sabotage other projects, he should have either walked away or changed the license for future versions of faker into a much more restricted one. SugarCRM transitioned their software from open source to closed source, and they’re still here with paying customers. There are also many restrictive licenses that change depending on th…

> What he did was no where near acceptable. It was a rebellious act against (what seems like) overbearing organizations, comparable to spraying a graffiti on their walls. As I said, there was no serious damage and nobody was hurt; it's not like he burned down buildings or shot at people. I'm of the opinion that this was not the right way as well, but in the end it really wasn't that bad.

Changing the license would be just as “rebellious” and it wouldn’t have hurt anyone. It also would have drastically increased his chances of getting paid. Given his bomb making activities, I feel that this was more of an excuse to watch the world burn.
Post reply on HN