Live data from Hacker News

Open source ‘protestware’ harms Open Source

opensource.org

461–470 of 575 posts

Re: Open source ‘protestware’ harms Open Source

#461

To be honest, I'm annoyed by the benign protestware messages when they start to get in the way of using the software, particularly on mobile. I was looking at the isomorphic git documentation the other day, and noticed that their "#BlackLivesMatter #DefundThePolice" banner scrolls under the rest of the content, leaving this annoying gap that takes up screen real estate, especially in landscape mode on a phone.[0] Wha…

> noticed that their "#BlackLivesMatter #DefundThePolice" banner scrolls under the rest of the content, leaving this annoying gap People get killed and a HNer is annoyed by a gap around a banner.

The banner wavers have moved on to the next trendy thing and people are still getting killed. What was achieved by annoying HNers?

Re: Open source ‘protestware’ harms Open Source

#462

I'm in Texas. A LOT of Californians disagree with some of the laws that Texas has passed. How long will it be until my hard drive gets reformatted by some protestor in San Francisco who localizes my IP address?

Another fun scenario: your project has two dependencies, made by two different developers: `left-pad` and `right-pad`. `left-pad` will format your hard drive if it geolocates you being in a state that allows X. `right-pad` will format your hard drive if it geolocates you being in a state that criminalizes X.

Write a wrapper project that changes your location before any left-pad or right-pad function calls. Or just fork both and fix them how you see fit if they're open source.

Re: Open source ‘protestware’ harms Open Source

#464

Was talking with a friend about the peacenotwar thing. I think its pretty interesting to view so many of the decisions like this through the “we have to do something” mindset so many people have, especially on social media. All of these companies shutting down in Russia, people pressuring others to take a stand or shut down their services, upset the population. On HN I remember the namecheap thing and the service tha…

Sanctions and boycotts are unfortunately blunt. Yet, every citizen in Russia pays russian taxes. Tax rubles funds the war. Taxes are paid equally by those who support the war, and by those who oppose it. The end result is the same - bombs on Ukrainian maternity wards.

It is a shame that the innocent have to suffer, but I'd rather impose sanctions and boycotts and see a smaller number of bombs rain down over Ukraine.

For this reason, I support every move to cut off anyone in Russia from any and all foreign products and services (perhaps with the exception of medical supplies and children's toys, but the principle stands).

In aggregate all these small actions are having a very real impact on Russia's ability to conduct the war.

Re: Open source ‘protestware’ harms Open Source

#465
post #360

Earlier quoted context omitted.

While the prior post was talking about reticence to trust OSS code in commercial environments, the problem is not limited to that arena. This change hit national news here, albeit very temporarily, not just tech and business news. If an OSS developer can drop a logic bomb on Russian interests, one could do it to anyone else they disagree with, and that might understandably make people uncomfortable. Furthermore, the…

> one could do it to anyone else they disagree with, and that might understandably make people uncomfortable That's why you audit your dependencies and have tests right? Right?

It is one of the reasons why you should. But...

* Many don't.

* Even for those that do something might slip through the cracks, particularly given how deep and wide some dependency trees go in the current JS ecosystem.

* Such attacks would still cause you problems once your audit spots one: you now have to hold back a version, perhaps back-porting security fixes, at least until you can migrate to another package or create your own (or, rather than creating fresh, decide to continue maintaining a fork of the affected one). And you may need a deeper audit, checking to see if anything else slipped by earlier that has left dangerous traces.

And the existence of dependency audits doesn't make damaging protest updates like this right any more than the existence of secure zips makes pick-pocketing those without them fine.

Re: Open source ‘protestware’ harms Open Source

#466

And this is why I hate the JS ecosystem. Everything is monkey patched by a bunch of randoms who published a package that scratched their itch and you have 0 assurances of their intent or stewardship. If you want to vet dependencies- good luck - the standard library is so shit that pulling one dependency might bring in a 100+ packages with it. Even the "big corporate sponsored" libraries depend on random crapware - li…

Why do you think .NET's NuGet is immune?

Are you aware, that Microsoft bought NPM (or at least tried to)?

Re: Open source ‘protestware’ harms Open Source

#467

Earlier quoted context omitted.

> general I am for personal expression. I’m for signal, not noise. I don’t want stupid personal expressions, I want meaningful or beautiful or somehow useful. I used to work with a person who would raise their hand in every presentation and say “security is important how is this software secure” even when it wasn’t anywhere remotely relevant. It was counterproductive and distracting and wasted valuable time that we c…

> I don’t want stupid personal expressions, I want meaningful or beautiful or somehow useful. I guess I feel that improving our world, ending war, making our society more just and fair, these are meaningful, useful, and beautiful things to do. They might be some of the most meaningful things actually. > It was counterproductive and distracting and wasted valuable time that we could use to do something better. This is…

> I guess I feel that improving our world, ending war, making our society more just and fair, these are meaningful, useful, and beautiful things to do. They might be some of the most meaningful things actually.

I feel that way too. I want all those things. Adding “FreeUkraine” or “BLM” doesn’t do that. I don’t think virtue signaling is that big of a problem, but adding these phrases does nothing more than signal.

I don’t think it’s productive to call out virtual signaling in that I would never submit a PR to complain or remove. But I definitely notice it and it seems stupid. I don’t spend a lot of time thinking about it but a second or two while reading docs doesn’t make me think more highly of someone.

I think cynically it just seems like people say this instead of doing meaningful things.

Re: Open source ‘protestware’ harms Open Source

#468

To be honest, I'm annoyed by the benign protestware messages when they start to get in the way of using the software, particularly on mobile. I was looking at the isomorphic git documentation the other day, and noticed that their "#BlackLivesMatter #DefundThePolice" banner scrolls under the rest of the content, leaving this annoying gap that takes up screen real estate, especially in landscape mode on a phone.[0] Wha…

The Svelte banner looks ok on desktop, but yeah seriously problematic on mobile. I think this is an outgrowth of the "use whatever power you have to push for change" culture. It has been highly effective in the past, particularly with gay marriage, and I think those victories gave it enough gas to run for many years even without success. There's also the social points that one gets from it as well. I know of at least…

No post body was provided.

Re: Open source ‘protestware’ harms Open Source

#469

Earlier quoted context omitted.

If a company shows support for the Ukraine, then they are giving aid and comfort to the Ukrainian military who was shelling civilians in the Donbass region for the past decade.

Your comment has the implication (intended or unintended) that Ukraine was the instigator as far as ceasefire violations go. As far as I can tell, that's not true. However, the real way to find out for sure would be to go through the OSCE SMM reports[1] about ceasefire violations and determine what percentage of them were likely from Ukranian-controlled territory versus separatist-controlled territory. [1] https://ww…

Your comment has the implication (intended or unintended) that there are situations where civilian casualties are perfectly acceptable.

My only real point was that who the Good Guys and who the Bad Guys are in Ukraine are predetermined by the set of assumptions you start with. Everybody who was paying attention isn't that surprised by the invasion. It's not even a puzzle as to why Russia would do it. They spelled it out quite clearly, and have been saying it for years.

Which is why I find the media narrative annoying. It's an almost perfect example of gaslighting. The only response to Russia's complaints about NATO meddling in Ukraine being provocative is to make some kind of counter-offer to offset the provocation. To suggest that there wasn't any meddling, or that Russia just invaded out of the blue for no good reason other than sheer evilness, is either staggeringly wrong, or a deliberate lie.

Re: Open source ‘protestware’ harms Open Source

#470
post #450

Earlier quoted context omitted.

What next? Is refusing doing business with Russia a war crime, too? After all, some civilians might lose their livelihoods and starve to death, right?

There's an obvious difference between trying to hurt people and not trading with them yourself. If the distinction is difficult, there are laws to define this 'war crime' thing, you may wish to consult them. Also, Russia is relatively self-sufficient foodwise. There'll be shortages but no starvation. I'm sure though that if starvation was serious possiblity the West would exclude food imports.

I thought that food imports were already excluded from sanctions for this exact reason.
Post reply on HN