Live data from Hacker News

Open source ‘protestware’ harms Open Source

opensource.org

251–260 of 575 posts

Re: Open source ‘protestware’ harms Open Source

#251

On one hand, I don't want to be anywhere near protestware when it comes to my work or the tools I use. On the other hand, Javascript developers have a whole different culture than the developer circles I like to frequent. In npm-land, the societal expectations of quality and solemnity (for lack of a better word) are lower, and this kind of behaviour is even celebrated if it favors the "right cause". The last two case…

I don’t think it is understood. Most people who write JavaScript aren’t keeping up with the latest drama. I hadn’t seen any of these political complaints before this thread and I’m a lead engineer on a full stack typescript stack. Not that I have an opinion either way I just don’t think you can reasonably expect devs to keep up with stuff like this.

I think if you pull in code from all sorts of random people across the Internet, you probably absolutely should have some idea what risks that entails, and stay aware of the "latest drama", so you know when running "npm update" is likely to ruin the rest of your day.

Of course, the ideal solution is just to not use an ecosystem where pulling in code from all sorts of random people is common.

Re: Open source ‘protestware’ harms Open Source

#252

Earlier quoted context omitted.

> who have no influence I believe the crux of the political theory is that in a representative democracy, nobody has no influence over the issue.

That is obviously not true, and even if it were, the country in question is Russia, an autocracy. What is our poor hypothetical node developer expected to do, march down to the Kremlin and beat Putin with his MacBook?

Parent comment originally referred to Black Lives Matter; I had been responding to that part of the comment (and its relation to US politics).

Re: Open source ‘protestware’ harms Open Source

#253

Earlier quoted context omitted.

I have legitimately argued against using NodeJS as the foundation of our next product for this very reason. NodeJS' culture is very much "move fast and break things", and "all software is political". Look at the TSC drama. Leftpad.js. This isn't an ecosystem that you want to build and maintain a product on.

It’s a problem in any ecosystem. It’s not like there haven’t been attacks in nuget packages or the recently famous Log4j vulnerability. I’m not going to pretend there aren’t some pretty deep flaws with nested dependencies in Node modules, but it’s really more an issue with unprofessionalism in my eyes. I’ve never worked a place that would auto-magically roll out things like windows or chrome updates without having th…

Not all ecosystems are the same in the extent to which auditing and maintaining dependency chains is a burden. All of Linux from Scratch consists of something like less than 90 distinct dependencies, for instance. When I went to add a token-replacement library to mdbook so I can interpolate variables in a book, Cargo pulled in 287 dependencies. For better or worse, the newer, hotter languages of the day seem to be predicated on extremely small, something single-function, libraries, and thus enormous and arguably intractable dependency trees.

Re: Open source ‘protestware’ harms Open Source

#254
post #188
post #34

Do people think the people protesting like this don't know that this is damaging? They presumably feel that the issue at hand is more important than that damage. Every protest every has been met with "but this protest is being done the wrong way, don't inconvenience me", but that's the point: protest has to disrupt things to make people take notice and make changes. Would I do this? No. I don't think it's effective o…

This isn't so much of a protest as much as an nonviolent indiscriminate vigilante terrorist attack. > The intent is to disrupt. Presumably the intent is to help Ukraine. People need to stop and think about how their disruptive "protest" is actually going to help their cause rather than blindly chase awareness.

A lot of protest is more about emotion than logic. Most individual actions of protest are not logical, like each of the individual protesting Russians who know they are likely to go to jail. But when enough “illogical” people do enough “illogical” things visibly enough, the Overton window (as it were) can start to shift as they prompt others to ask why they see more and more “illogical” acts in favor of a position. Some will go to far, some not enough, but it’s hard to predict what acts will move the needle.

Re: Open source ‘protestware’ harms Open Source

#255
I absolutely agree with this premise. Software (open source or not) should be usable and perform a useful function, not swarm users with spam to protest this or that.

The developer of the software that made the protestware was rightfully banned by Github. I haven't heard if he ever regained access to his account.

Re: Open source ‘protestware’ harms Open Source

#256

Earlier quoted context omitted.

> men are still statistically more likely to be violent criminals I think your meant criminals are more likely to be men.

No, I meant exactly what I said, more men are violent criminals per capita than women. What you said is also true, but it's not what I meant.

No post body was provided.

Re: Open source ‘protestware’ harms Open Source

#257
post #110

Earlier quoted context omitted.

Vandalism can be a form of protest. Again, every protest ever has had people saying that the disruption to them is over the line. It draws attention and coverage to the issue. It forces people to listen. Protest has to be disruptive to the norm to achieve that, and there will always be people who don't like that. That's the point. As I say, I don't think this one is effective or proportional given the lack of control…

“Crime X can be a form of protest” “Every protest ever has had people saying that the disruption to them is over the line” So which crimes would not be acceptable in a protest? And if people will always complain about the line being crossed, does this mean there can be no line at all?

Indeed, by this logic, the Unabomber was a pretty effective "protester."

Re: Open source ‘protestware’ harms Open Source

#258
post #215

Earlier quoted context omitted.

> Pushing political commit messages is not "power". I'm not debating whether it works or whether it's the right form of activism. I'm responding to your comment. Namely you saying that taking a side is childish. > If you like like everyone around you you are not a rebel, just a conformist. If your goal is to follow the herd, that's bad. If it's to go in the opposite direction, that's the same thing. I'd encourage a p…

> Are you disputing the recent Russia's invasion of Ukraine? Not the GP. I don't specifically dispute that. But in a time when many fictional stories can be told through video, I think it's reasonable to be unsure and neutral on things that we don't have direct knowledge about. Put another way, I think being neutral and silent by default is a necessary defense against manipulation.

>Put another way, I think being neutral and silent by default is a necessary defense against manipulation.

But what if the purpose of the manipulation is to suppress dissent, or at least encourage passive acceptance of the status quo, by convincing people remain to neutral and silent?

Re: Open source ‘protestware’ harms Open Source

#259

Earlier quoted context omitted.

It can be a problem in any language or package manager but in my Golang project, I have a single dependency outside of the standard library, in my Javascript project I conservatively have 200+ (if I consider all the packages installed by my primary dependencies). The surface area is just that much bigger and the packages change so frequently.

So you recon a better (bigger?) node stdlib would solve a lot of this?

Probably, yes. I'd say most mature tech stacks provide most of what you are likely to need first party. .NET is an incredible ecosystem for this: Nearly everything the standard developer needs is available from Microsoft, most common third party packages you might want to pull in were authored by an enterprise company with support available, and if you're pulling in something by an individual, it's probably pretty niche.

Re: Open source ‘protestware’ harms Open Source

#260

Earlier quoted context omitted.

At best, this operation could be construed as an act of vandalism or at worst an act of CYBER terrorism. This indiscriminate and malicious act of hostility was carried by what amounted to be a cyber weapon (think IED) housed in a very ordinary and non-suspicious package to cause the greatest damage to the users' data.

> this operation could be construed as an act of vandalism or at worst an act of CYBER terrorism Could be. But by whom? To what effect? One of the downsides of losing credibility as a nation state is the concepts of deference, retaliation and proportionality lose weight. There is no indication that the facts on the ground would affect whether Putin deems something a cyber attack. Worse, one's own policing actions are…

> Could be. But by whom? To what effect?

The general public. I speculate that publicity was one of the main objectives behind this operation to draw attention to his political grievances and maybe demands.

Perhaps we should focus more on the issue of bragging rights. The perpetrator probably thinks he's some kind of a hero having conducted this operation and it was some kind of a heroic feat sticking up to Putin when he in fact is more of a lousy vandal destroying some poor guy's store window than an epic warrior conquering foreign lands and subduing evil emperors.

The more people realize this and esp. people who are prone to commit these acts, the more innocent people would be spared the damage incurred by those reckless attacks.

Post reply on HN