Live data from Hacker News

Open source ‘protestware’ harms Open Source

opensource.org

471–480 of 575 posts

Re: Open source ‘protestware’ harms Open Source

#471

Earlier quoted context omitted.

There's a difference between providing information ("Someone significant to many members of this community has died recently") and providing a (arguably very superficial) signal of support for a cause dear to some of the developers.

I'm afraid I don't see the difference. Can you clarify?

What HN does is less obtrusive, less likely to stoke heated division amongst its users, and more relevant to the content of the site.

Re: Open source ‘protestware’ harms Open Source

#472

And this is why I hate the JS ecosystem. Everything is monkey patched by a bunch of randoms who published a package that scratched their itch and you have 0 assurances of their intent or stewardship. If you want to vet dependencies- good luck - the standard library is so shit that pulling one dependency might bring in a 100+ packages with it. Even the "big corporate sponsored" libraries depend on random crapware - li…

Why do you think .NET's NuGet is immune? Are you aware, that Microsoft bought NPM (or at least tried to)?

Because most nuget packages I get are from Microsoft, and if I use something that's not there is usually a Microsoft employee on the team or it's a trusted community package without random third party dependencies. Meanwhile half of npm was broken because of left pad.

It's got nothing to do with npm as a repository - I don't trust the community.

Re: Open source ‘protestware’ harms Open Source

#473

Earlier quoted context omitted.

After ISIS rose I gave up the idea that countries like Syria, Iraq etc can ever become anything more than "hellholes", at least in my lifetime. Certain areas like Kurdistan excepted (and I hope and support their recognization as a state), but in general there will always be one strongman or another. But Ukraine was different (and I hope it still will be), turning from the world of the strongman and toward Europe and…

All this comment shows to me is you knew very little about Syria & Iraq. The cultural & population centers of Syria were never taken by ISIS and Damascus prior to 2011 would not have felt as "hellhole"-esque as I think you are imagining. > turning from the world of the strongman and toward Europe and modern freedoms Towards Europe, certainly, but also towards nationalism - undoubtedly. It is not a "modern freedom" to…

> to ban minority languages from schools

Please, it's not a ban. The relevant law only applies to state-funded schools and makes sure that students who don't speak Ukrainian gradually learn it over the years and start using it in school:

_https://ukrainian-studies.ca/2020/08/01/ukraines-russian-lan...

If Ukraine hasn't been the target of Russian territorial expansionism, we could argue that this law is overreaching. However Russia had claimed the right to "defend Russian-speaking people" outside of Russia before invading Ukraine in 2014 (the law was passed in 2017). Under these conditions, passing such a law was practically a question of self-preservation.

Re: Open source ‘protestware’ harms Open Source

#474

Earlier quoted context omitted.

> noticed that their "#BlackLivesMatter #DefundThePolice" banner scrolls under the rest of the content, leaving this annoying gap People get killed and a HNer is annoyed by a gap around a banner.

The banner wavers have moved on to the next trendy thing and people are still getting killed. What was achieved by annoying HNers?

You’re at war. Maybe you don’t realize it because you can still go on with your life as if nothing was happening.

It’s not a trendy thing, it won’t go away because of some random trendy thing.

HNers annoyance couldn’t be more irrelevant. And people are still getting killed because the world has decided that this war , as bad as it is, shouldn’t interfere with business too much.

People are still getting killed because we don’t want our precious little irrelevant easy lives to be disturbed too much.

The world still hasn’t waked up. We should be alarmed and fully supporting freedom. But the world is just annoyed. I thought moral values were important to open source.

Re: Open source ‘protestware’ harms Open Source

#475

Earlier quoted context omitted.

> general I am for personal expression. I’m for signal, not noise. I don’t want stupid personal expressions, I want meaningful or beautiful or somehow useful. I used to work with a person who would raise their hand in every presentation and say “security is important how is this software secure” even when it wasn’t anywhere remotely relevant. It was counterproductive and distracting and wasted valuable time that we c…

While I agree with you on broad strokes, I'm sure, somewhere, someday, somebodies concerns over the security implications of a logging framework (e.g. Log4J) were brushed under the table by a statement like that.

I think security is extremely important (as is BLM), my issue in this example is that the person brought up security as questions where it was not relevant. I think that actually hurts security as it made people tune out because it wasn’t relevant. So it was like the boy who cried wolf in that when security was important it wasn’t paid attention to.

I’m not saying that security reviews shouldn’t be performed. They should. Security should be part of design and code review. But it’s not a relevant question in every single situation.

Re: Open source ‘protestware’ harms Open Source

#476
post #90
post #34

Do people think the people protesting like this don't know that this is damaging? They presumably feel that the issue at hand is more important than that damage. Every protest every has been met with "but this protest is being done the wrong way, don't inconvenience me", but that's the point: protest has to disrupt things to make people take notice and make changes. Would I do this? No. I don't think it's effective o…

The problem is that that the node.js filesystem deletion "protests" was an indiscriminate digital attack that harmed people who are doing a much better job of actively opposing the invasion. I believe that the developer who implemented that attack should face criminal charges. Our ability to trust our open source is a critical part of our economy. People who abuse that trust to directly harm others should know they w…

An excerpt from node-ipc's license:

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Re: Open source ‘protestware’ harms Open Source

#477

Was talking with a friend about the peacenotwar thing. I think its pretty interesting to view so many of the decisions like this through the “we have to do something” mindset so many people have, especially on social media. All of these companies shutting down in Russia, people pressuring others to take a stand or shut down their services, upset the population. On HN I remember the namecheap thing and the service tha…

[deleted]

Re: Open source ‘protestware’ harms Open Source

#478
post #454

Earlier quoted context omitted.

It's annoying that the politicians don't seem to think about this. Are they worried that they'd get fever votes? What if everyone wrote to their politicians (in one's respective country) and said that they'd happy wear extra clothes indoors

> It's annoying that the politicians don't seem to think about this. Are they worried that they'd get fever votes? They're probably worried about stated preference vs revealed preference. People say that they stand with ukraine and they're willing to make tremendous sacrifices to help ukraine/hurt russia. That might be true, but they might not be willing to actually pay the cost (eg. higher gas prices).

Good point.

Maybe in some cases, people won't know until afterwards, if they actually want more sanctions or not -- until after they've gotten to try it and discover how it was. Especially problems with transportation could cause anger, I suspect. Whilst extra clothes is maybe simpler.

Now I start thinking that more buses and bike lanes in a way can be seen as part of a military defense strategy, hmm. (If the population does mostly ok without oil)

Re: Open source ‘protestware’ harms Open Source

#479

Earlier quoted context omitted.

> I don’t want stupid personal expressions, I want meaningful or beautiful or somehow useful. I guess I feel that improving our world, ending war, making our society more just and fair, these are meaningful, useful, and beautiful things to do. They might be some of the most meaningful things actually. > It was counterproductive and distracting and wasted valuable time that we could use to do something better. This is…

None of the signalling achieves anything. Its annoying, the signalling people really stand out. Seeing them doing the "Notice me, I'm standing for the right thing, im a good person!"-move makes me cringe. I wish they would stop.

How do you know that it achieves nothing? Genuinely curious.

Re: Open source ‘protestware’ harms Open Source

#480
post #228

Earlier quoted context omitted.

> In theory the same things could happen for PIP, Maven, Gradle, their Rust and Go counterpart and any such package manager. Any data on this? in theory, but why is it always node.js/npm? I work on completely different things... is it a different community culture? is it the thousands of tiny low quality packages people include to do the most basic things?

A perfect example is webpack. Indirectly depends on many thousands of different packages, is run during development, and has 225k packages that depend upon it. https://github.com/webpack/webpack/network/dependencies i.e. even if you are careful about dependencies, your build tools are not. I also checked esbuild which is written in go, but it still has a dependency on babel and webpack (via scripts/package.json fuse.…

esbuild doesn't depend on babel or webpack if you're just using esbuild (maybe it does if you want to build esbuild from source?) My pet project uses esbuild and the relevant part of the dependency tree only shows 'esbuild@0.14.27' which depends on 'esbuild-linux-64@0.14.27' (which is the binary package) - it doesn't extend any further than that.
Post reply on HN