Live data from Hacker News

Open source ‘protestware’ harms Open Source

opensource.org

201–210 of 575 posts

Re: Open source ‘protestware’ harms Open Source

#201

Earlier quoted context omitted.

Arguments like this are superficial and justify bad behavior. Destruction of property isn't murder, but it's still not ok and it still causes harm to living people who have no influence over the issue.

> who have no influence I believe the crux of the political theory is that in a representative democracy, nobody has no influence over the issue.

That is obviously not true, and even if it were, the country in question is Russia, an autocracy. What is our poor hypothetical node developer expected to do, march down to the Kremlin and beat Putin with his MacBook?

Re: Open source ‘protestware’ harms Open Source

#202

I personally think this kind of thing is just a symptom of a larger problem; the modern open source software ecosystem is highly vulnerable to supply chain attacks. Frankly, given how normal it is to just blindly download unverified, unsandboxed code from random developers and execute it on our machines it's surprising this sort of incident isn't more common. What we need are better tools and processes to detect and…

Quorum publishing would help a lot, and is doable. It would guard against supply chain attacks where the identity of a publisher is taken over by an attacker, by multiplying the difficulty and requiring multiple takeovers. However, it would not fully guard against a conspiracy by people willing to burn their reputations, as in the "peacenotwar" attack.

Per-dependency sandboxing and permissions might mitigate things to a degree, just as it has on iOS etc with apps. But it would require a different software module architecture than we have today for common languages.

Re: Open source ‘protestware’ harms Open Source

#203
post #161

Earlier quoted context omitted.

>Javascript developers have a whole different culture than the developer circles I like to frequent. Most Javascript developers I know are just writing code and that's what they're concerned with. Vocal voices on twitter or etc != most Javascript developers. I'd argue most vocal folks on forums or etc don't represent most developers of any given language.

Sure, just like most men aren't violent criminals but men are still statistically more likely to be violent criminals. The point is that JS devs seem (perhaps a proper statistical study will show otherwise) more likely per capita to shit up their ecosystem. There are several reasons contributing to this (the limited JS standard lib being a big one) but a major part of it really seems to be that JS devs are a differen…

> men are still statistically more likely to be violent criminals

I think your meant criminals are more likely to be men.

Re: Open source ‘protestware’ harms Open Source

#204
>The “weaponization of open source” as Gerald Benischke calls it in his March 16 blog post is indiscriminate, and the collateral damage it causes damages the work of developers and operators solely because they have a Russia-assigned IP address. It harms peacemakers as much as the warmongers—even ethical hackers using a VPN to work against the invasion might become collateral damage.

I think this is a weirdly bad argument. All the sanctions against Russia harm pretty much all Russians because they're in Russia even if they're peacemakers. That's just the price of using sanctions. You can absolutely apply that to open source - block all Russian IPs and say "Sorry, but we endorse the sanctions that our government has put on Russia, and we're going to boycott your country for that reason" - just the same way that hundreds of western countries have pulled their businesses out of China.

Now they also make the argument that it's ineffective - that you're ruining your own codebase to try and make Russia suffer, but at the end of the day that's a judgement for the developer of the repo.

It's also naive to think posting "anti-propaganda" in commit logs is in any way an effective way of circumventing censorship, at best you're just hoping that your obscurity prevents you being censored, but that's basically just playing by the censors rules.

Re: Open source ‘protestware’ harms Open Source

#205
post #104

Earlier quoted context omitted.

You pretty much summarise what is wrong with the title. It is not "Protestware" that harms open source. It is politics and ideology harms open source. And the rate things are going may be Open Source will not only be split between permissive and copyleft, but progressive and libreRight. Edit: Now I remember Douglas Crockford's "The Software shall be used for Good, not Evil." license. I wonder if there are still any o…

> It is politics and ideology harms open source. The movement towards free and open source software was created in no small part do to activists with a very strong ideology. Open source would not exist to the same extent without the ideology espoused by the FSF. The problem is that abandoning a key tenant of the free software movement, neutrality towards different uses (part of freedom 0 of the free software definiti…

yeah it's kind of ironic to call for "no politics" in a movement that is essentially based in digital anarchism.

Re: Open source ‘protestware’ harms Open Source

#206
I get why the OSI published this post. They have a vested interest in the conversation and I agree with their points.

But the battle for the narrative has already been lost when people consider this to be a problem with 'open source'. Rather, it's a problem with software that's being given away for reputation brownie points. Here, the author showed exceedingly poor judgment towards users of their software, and this should result in the loss of goodwill and respect towards the author and the forking of their works if the license allows.

Open Source didn't enable this behavior. The author's poor judgement and the author's lack of need to care for the users of one's software is what didn't dissuade this behavior. In this case, it was giveaway software causing harm. In other cases, it's commercial software pushing hamfisted changes users don't want, because the users aren't empowered enough to fight it. The reason commercial software would avoid this particular type of stunt is because it's poor business sense to harm one's direct customers.

So what of Open Source? Open Source allows anyone to review or modify the software that engages in this behavior. So the community can salvage the author's good contributions and better custodians can carry the software forward.

Open Source also allows anyone to discover these cases proactively. Of course, almost nobody does this, because we as an "industry" have gotten used to four troubling trends, and ridicule those who aren't on this "bleeding edge":

* thinking that software that costs $0 to obtain incurs no additional costs

* not auditing our dependencies

* being unconcerned about the sheer quantity of dependencies

* blindly updating dependencies

It's a sad but predictable development that the field of Open Source software has basically merged with the community of authors actively looking to give away software for $0 (for fame or to upsell advanced features). Basically, the Open Source movement was too successful (in its advocacy and in raising the demands of the customers of software), and it has largely subsumed and supplanted the formerly-separate fields of shareware and trialware software.

This development is what truly hurts Open Source: so much software but too little emphasis on (or even demand for) curation, massive imbalance of contributors to users, the decreasing influence programming-language-specific spaces, and increasing dominance of the "move-fast-and-break-things" culture.

The way forward is to achieve stronger curation, more focused maker spaces, tighter (as opposed to larger) communities, and an outreach effort to re-establish the philosophical distinctions between Open Source and freeware.

Re: Open source ‘protestware’ harms Open Source

#207
post #134

> Instead of malware, a better approach to free expression would be to use messages in commit logs to send anti-propaganda messages and to issue trackers to share accurate news inside Russia of what is really happening in Ukraine at the hands of the Russian military, to cite two obvious possibilities. There are so many outlets for open source communities to be creative without harming everyone who happens to load the…

Isn't it likely for Russian ISPs to start blocking infowarship.com, if they haven't already? Since the script is loaded from their domain this would be easy to censor.

Eventually, sure, but I think this would have to become very widespread before that happened - they've only just blocked Google News today.

The instructions above do encourage self-hosting the script though, for both avoiding-block & security reasons.

Re: Open source ‘protestware’ harms Open Source

#209
post #148
post #90

Earlier quoted context omitted.

The problem is that that the node.js filesystem deletion "protests" was an indiscriminate digital attack that harmed people who are doing a much better job of actively opposing the invasion. I believe that the developer who implemented that attack should face criminal charges. Our ability to trust our open source is a critical part of our economy. People who abuse that trust to directly harm others should know they w…

I agree, to some extent. I think it was largely ineffective and poorly targeted protest. The media coverage is not really necessary as it's already highly reported on, and the people harmed have no control over it. With that said, disruptive protest can be (and often is) illegal. I may think it's justified in some cases, but also if I do something illegal I expect to face legal punishment for it. Some people lay down…

I think that blocking your software from running on some computers would be very disruptive but should be legal. (Edit: not endorsing this, just trying to clarify where the line lies)

Actively trying to harm those computers is simply not OK and goes beyond "disruptive" protest into harmful.

To analogize, if your protest blocks traffic, it is disruptive. If you protest goes looking for property owned by Russian speakers to burn down...you have moved beyond disruptive protest an into being a harmful attack.

I do not think the latter is anywhere even close to justifiable.

Re: Open source ‘protestware’ harms Open Source

#210

I'm in Texas. A LOT of Californians disagree with some of the laws that Texas has passed. How long will it be until my hard drive gets reformatted by some protestor in San Francisco who localizes my IP address?

Another fun scenario: your project has two dependencies, made by two different developers: `left-pad` and `right-pad`. `left-pad` will format your hard drive if it geolocates you being in a state that allows X. `right-pad` will format your hard drive if it geolocates you being in a state that criminalizes X.

Dependency hell but with more politics!
Post reply on HN