Live data from Hacker News

Open source ‘protestware’ harms Open Source

opensource.org

41–50 of 575 posts

Re: Open source ‘protestware’ harms Open Source

#41
post #17

I'm in Texas. A LOT of Californians disagree with some of the laws that Texas has passed. How long will it be until my hard drive gets reformatted by some protestor in San Francisco who localizes my IP address?

Quoted post unavailable.

It's your fault for not giving me the money. If you had done that sooner you'd still have your brain intact.

Re: Open source ‘protestware’ harms Open Source

#42
post #30

Earlier quoted context omitted.

I have legitimately argued against using NodeJS as the foundation of our next product for this very reason. NodeJS' culture is very much "move fast and break things", and "all software is political". Look at the TSC drama. Leftpad.js. This isn't an ecosystem that you want to build and maintain a product on.

So you’re basically saying, don’t use X tool chain because the 3rd party software doesn’t move on your pace? Or they have different “views” than yours? I don’t see how that makes any sense. Why do you have to be beholden 3rd party developers and the pace they work at?

I'm not sure if you being purposely obtuse, but the idea that you'd build your software on top of a technology or platform that might introduce instability due to the whims or politics of its stewards is absolutely and obviously a risk worth considering.

Re: Open source ‘protestware’ harms Open Source

#43
On one hand, I don't want to be anywhere near protestware when it comes to my work or the tools I use.

On the other hand, Javascript developers have a whole different culture than the developer circles I like to frequent. In npm-land, the societal expectations of quality and solemnity (for lack of a better word) are lower, and this kind of behaviour is even celebrated if it favors the "right cause".

The last two cases we've seen (faker/colors, node-ipc) just took it one step further, but we've seen a lack of seriosness from both the npm organization and the community during the last... what? 6 years?. At this point, if you stay in the whole npm ecosystem, it's understood that you do so at your own risk.

Re: Open source ‘protestware’ harms Open Source

#44

I'm in Texas. A LOT of Californians disagree with some of the laws that Texas has passed. How long will it be until my hard drive gets reformatted by some protestor in San Francisco who localizes my IP address?

I have legitimately argued against using NodeJS as the foundation of our next product for this very reason. NodeJS' culture is very much "move fast and break things", and "all software is political". Look at the TSC drama. Leftpad.js. This isn't an ecosystem that you want to build and maintain a product on.

Isn't this mostly a problem of auto-updating and non-pinned dependencies? If you vendor and audit your dependencies this isn't really a problem.

Re: Open source ‘protestware’ harms Open Source

#45

Whatever it takes to bring that dictator down.

This may actually be counterproductive to that end, as it disrupts the ability of the Russian grass roots to develop their own software. That capacity is fairly important to provide the technical ability to avoid state surveillance and to communicate without ending up in the cell next to Navalny.

Re: Open source ‘protestware’ harms Open Source

#46
post #30

Earlier quoted context omitted.

I have legitimately argued against using NodeJS as the foundation of our next product for this very reason. NodeJS' culture is very much "move fast and break things", and "all software is political". Look at the TSC drama. Leftpad.js. This isn't an ecosystem that you want to build and maintain a product on.

So you’re basically saying, don’t use X tool chain because the 3rd party software doesn’t move on your pace? Or they have different “views” than yours? I don’t see how that makes any sense. Why do you have to be beholden 3rd party developers and the pace they work at?

Did you read the parent article?

But, in at least one case—the peacenotwar module in the node-ipc package—an update sabotages npm developers with code intended to wipe data stored in Russia and Belarus. In a March 16 blog post on the malicious code, Liran Tal at Snyk said, “This security incident involves destructive acts of corrupting files on disk by one maintainer and their attempts to hide and restate that deliberate sabotage in different forms.”

This has nothing to do with pace of development, or even the political views of the developers. It has to do with inserting what is essentially malware into open source packages that affect users based on geo-location.

Re: Open source ‘protestware’ harms Open Source

#47
> Instead of malware, a better approach to free expression would be to use messages in commit logs to send anti-propaganda messages and to issue trackers to share accurate news inside Russia of what is really happening in Ukraine at the hands of the Russian military, to cite two obvious possibilities

How about not taking sides instead of acting like a kid believing one side is black and the other white with absolutely no gradient in the middle? Also, propaganda goes both sides, just like in absolutely every conflict in History. Stop being a tool of your own government.

Re: Open source ‘protestware’ harms Open Source

#49

While I am personally disgusted with what transpired with node-ipc and am also completely gutted and outraged at Russias violent invasion of Ukraine - I don’t like the idea of us trying to “tone police” open source projects. If some idiot maintainer wants to pull a stupid stunt like that they should have the right to do so. In my view it’s the software equivalent of “hate speech” which, while vile, should be protecte…

>I don’t like the idea of us trying to “tone police” open source projects. If some idiot maintainer wants to pull a stupid stunt like that they should have the right to do so. In my view it’s the software equivalent of “hate speech” which, while vile, should be protected.

I don't understand your characterization of this issue as "trying to “tone police” open source projects". In this case it's quite likely breaking the law (ie. CFAA), and for good reason. It's one thing to start a website with racist content. It's another to actually damage people's property. Not even US, home of the most liberal free speech laws (at least when it comes to "hate speech") allows this.

Re: Open source ‘protestware’ harms Open Source

#50
post #4

I just don't understand what the node-ipc dev was expecting when he did that. "Hm, maybe if I put malware into a community-trusted module that destroys files of people in a certain geopolitical region, the countless innocent citizens that are affected will realize what they did wrong! Wait, who am I actually targeting again?"

Probably hoped the effects would negatively effect people there so they could put pressure to stop the murder of other innocent civilians. Arguments like this are similar to the BLM protest that try to equate property with human lives.

Arguments like this are superficial and justify bad behavior. Destruction of property isn't murder, but it's still not ok and it still causes harm to living people who have no influence over the issue.
Post reply on HN