Live data from Hacker News

Open source ‘protestware’ harms Open Source

opensource.org

131–140 of 575 posts

Re: Open source ‘protestware’ harms Open Source

#131
post #71

Earlier quoted context omitted.

Was anyone surprised people were pissed off?

About half of the comments here appear to be.

Are they? I don't see surprise: I see people defending the action (to some degree), but I can't find a single case of anyone who is surprised at people reacting negatively to it.

Re: Open source ‘protestware’ harms Open Source

#132
post #91

Earlier quoted context omitted.

No, not taking sides is just not taking sides. There's no need to turn such a position into a shortcut to something else. It's as stupid as the kids saying "if you are not with us you are against us". Typical populist bullshit.

How hard is it to just say "I think Russia is wrong for invading Ukraine and killing people"? That's all you have to do. Just write it. If you can't do that, but still want to engage in the discussion on the topic, your standpoint is clear. You're not some holier person not taking a stand. You have taken one, you just don't dare to spell it out.

So by this logic, if your blog/commit logs doesn't contain:

* russia invaded ukraine

* vaccines work

* wear a mask

* black lives matter

* trans women are women

* abortion is a right

then you're a pro-russian, vaccine-denying, anti-mask, white supremacist, transphobic, misogynist?

Re: Open source ‘protestware’ harms Open Source

#134

> Instead of malware, a better approach to free expression would be to use messages in commit logs to send anti-propaganda messages and to issue trackers to share accurate news inside Russia of what is really happening in Ukraine at the hands of the Russian military, to cite two obvious possibilities. There are so many outlets for open source communities to be creative without harming everyone who happens to load the…

Isn't it likely for Russian ISPs to start blocking infowarship.com, if they haven't already? Since the script is loaded from their domain this would be easy to censor.

Re: Open source ‘protestware’ harms Open Source

#135

Earlier quoted context omitted.

I have legitimately argued against using NodeJS as the foundation of our next product for this very reason. NodeJS' culture is very much "move fast and break things", and "all software is political". Look at the TSC drama. Leftpad.js. This isn't an ecosystem that you want to build and maintain a product on.

Basically all big js front ends have the same issue. Most of them had banners or whole pages for the BLM movement which made no sense to anyone outside of the US like myself. I mean a framework or library with a global audience shouldn't push american politics. Vue, React, Preact, Nodejs, Ember (had a whole page and made documentation unavailable for some time), Go lang, ExpressJS (still has the banner up), Typescrip…

> Most of them had banners or whole pages for the BLM movement which made no sense to anyone outside of the US like myself.

It isn't limited to JS frameworks. I remember seeing banners on Kubernetes docs too.

Re: Open source ‘protestware’ harms Open Source

#136

Earlier quoted context omitted.

Basically all big js front ends have the same issue. Most of them had banners or whole pages for the BLM movement which made no sense to anyone outside of the US like myself. I mean a framework or library with a global audience shouldn't push american politics. Vue, React, Preact, Nodejs, Ember (had a whole page and made documentation unavailable for some time), Go lang, ExpressJS (still has the banner up), Typescrip…

> The funny thing is, now when Russia has invaded Ukraine there is no banners on the same websites so it's obvious some lives matters more than others in their views.. Supporting one issue publicly does not mean you think it's more important than every issue you don't support publicly.

> Supporting one issue publicly does not mean you think it's more important than every issue you don't support publicly.

There is a big difference with war and people being systematically killed and a potential unjust legal system. War is obviously many times worse in every aspect and I think it's hilarious on what these people publicly support and what they don't.

It's hypocritical, unfair which makes it a big irony since that was what the BLM movement was all about (unfair treatment).

Re: Open source ‘protestware’ harms Open Source

#137

I'm in Texas. A LOT of Californians disagree with some of the laws that Texas has passed. How long will it be until my hard drive gets reformatted by some protestor in San Francisco who localizes my IP address?

I have legitimately argued against using NodeJS as the foundation of our next product for this very reason. NodeJS' culture is very much "move fast and break things", and "all software is political". Look at the TSC drama. Leftpad.js. This isn't an ecosystem that you want to build and maintain a product on.

It’s a problem in any ecosystem. It’s not like there haven’t been attacks in nuget packages or the recently famous Log4j vulnerability. I’m not going to pretend there aren’t some pretty deep flaws with nested dependencies in Node modules, but it’s really more an issue with unprofessionalism in my eyes.

I’ve never worked a place that would auto-magically roll out things like windows or chrome updates without having them vetted first. If you can’t trust those, then you certainly can’t trust some random NPM package, and if your organisation doesn’t have a strategy for how you handle something that unsafe then you really need to step up your professionalism.

I personally consider NPM packages to be sort or nice, in the very cynical way, that the community tends to beta test updates for you much faster than with any other dependency system.

Re: Open source ‘protestware’ harms Open Source

#138

Earlier quoted context omitted.

Basically all big js front ends have the same issue. Most of them had banners or whole pages for the BLM movement which made no sense to anyone outside of the US like myself. I mean a framework or library with a global audience shouldn't push american politics. Vue, React, Preact, Nodejs, Ember (had a whole page and made documentation unavailable for some time), Go lang, ExpressJS (still has the banner up), Typescrip…

> The funny thing is, now when Russia has invaded Ukraine there is no banners on the same websites so it's obvious some lives matters more than others in their views.. Supporting one issue publicly does not mean you think it's more important than every issue you don't support publicly.

It would seem to.

That was literally the whole thing of "inclusive language" right? It wasn't about what the words actually mean, just how people felt about them. If they felt the word was discriminatory, then it should be fixed.

If you're going to throw up banners on every JS site for one cause and not another, you're saying very loudly you don't care as much about the other. You, under the logic of "discriminatory language" even be engaging in discrimination.

Re: Open source ‘protestware’ harms Open Source

#139
post #46
post #30

Earlier quoted context omitted.

So you’re basically saying, don’t use X tool chain because the 3rd party software doesn’t move on your pace? Or they have different “views” than yours? I don’t see how that makes any sense. Why do you have to be beholden 3rd party developers and the pace they work at?

Did you read the parent article? But, in at least one case—the peacenotwar module in the node-ipc package—an update sabotages npm developers with code intended to wipe data stored in Russia and Belarus. In a March 16 blog post on the malicious code, Liran Tal at Snyk said, “This security incident involves destructive acts of corrupting files on disk by one maintainer and their attempts to hide and restate that delibe…

OK, and how is this something unique to the Node.js package ecosystem? What's stopping someone on PyPI/some other PM from doing the same thing? I personally view these more as malicious copycat acts than anything inherent with the ecosystem. Should NPM start manually reviewing all of the packages that go through them, because the handful of abusers? I'm not so sure. The situation on languages without a widely used package manager/ecosystem like C++ I don't think is any better.

Re: Open source ‘protestware’ harms Open Source

#140
post #33

This is crazy. The monetary system is fracturing, now the open source system could be fracturing. If I was Russia, I might start seeing the need to develop in-country versions of open source packages, as a matter of national security.

It’s open source: If the government’s are willing to pay people to fork the original and vet and merge all the future deltas then they just need to host their own package manager. But would developers trust a government managed set of packages? In the US that is doubtful (I’d assume at some point FBI, CIA, NSA, DOD do something dishonest with it at some point.)
Post reply on HN