Live data from Hacker News

Sourcehut will blacklist the Go module mirror

sourcehut.org

211–220 of 365 posts

Re: Sourcehut will blacklist the Go module mirror

#211

Earlier quoted context omitted.

Why? Google has quite a reputation for wrongfully banning people from things. This doesn't seem unusual for them at all.

> Google has quite a reputation for wrongfully banning people from things. Extraordinary claims require extraordinary evidence.

Extraordinary claims do. Ordinary claims only require ordinary evidence.

Re: Sourcehut will blacklist the Go module mirror

#212

From the GitHub issue, by a Googler: > For boring technical reasons, it would be a fair bit of extra work for us to read robots.txt […] This is coming from one of the biggest, richest, most well-staffed companies on the planet. It’s too much work for them to read a robots.txt file like the rest of the world (and plenty of one-man teams) do before hammering a server with terabytes of requests. If this is too much for…

Why did sourcehut not take the offer to be added to the refresh exclusion list like the other two small hosting providers did? It seems like that would have resolved this issue last year.

For a number of reasons. For a start, what does disabling the cache refresh imply? Does it come with a degradation of service for Go users? If not, then why is it there at all? And if so, why should we accept a service degradation when the problem is clearly in the proxy's poor engineering and design?

Furthermore, we try to look past the tip of our own nose when it comes to these kinds of problems. We often reject solutions which are offered to SourceHut and SourceHut alone. This isn't the first time this principle has run into problems with the Go team; to this day pkg.go.dev does not work properly with SourceHut instances hosted elsewhere than git.sr.ht, or even GitLab instances like salsa.debian.org, because they hard-code the list of domains rather than looking for better solutions -- even though they were advised of several.

The proxy has caused problems for many service providers, and agreeing to have SourceHut removed from the refresh would not solve the problem for anyone else, and thus would not solve the problem. Some of these providers have been able to get in touch with the Go team and received this offer, but the process is not easily discovered and is poorly defined, and, again, comes with these implied service considerations. In the spirit of the Debian free software guidelines, we don't accept these kinds of solutions:

> The rights attached to the program must not depend on the program's being part of a Debian system. If the program is extracted from Debian and used or distributed without Debian but otherwise within the terms of the program's license, all parties to whom the program is redistributed should have the same rights as those that are granted in conjunction with the Debian system.

Yes, being excluded from the refresh would reduce the traffic to our servers, likely with less impact for users. But it is clearly the wrong solution and we don't like wrong solutions. You would not be wrong to characterize this as somewhat ideologically motivated, but I think we've been very reasonable and the Go team has not -- at this point our move is, in my view, justified.

Re: Sourcehut will blacklist the Go module mirror

#213
post #152

Earlier quoted context omitted.

Why should you opt-in to a No-DDOS list ? Why is it not the default ?

You are basically arguing that sr.ht is taking a "principled stand" against google. If that is what they are doing they should just say that and not pretend like there were no other options. I'm ok with saying "google should do better!" But the compromise solution from the Go team seems reasonable to solve the immediate issue in a way that doesn't harm end users. The author should at least address why they have chose…

Or, we should not assume that Google's stance is correct, that sr.ht is expected to explain themselves. We should ask why is Google continuing on that path of DOSing upstream servers by default, not willing to use standards for properly using network resources, expecting all of them to do all the work.

EDIT: Moreover, sr.ht doing a workaround only for sr.ht, and lubar doing a workaround for lubar, etc... is not what Free Software is about. The point is that we're supposed to act as a community, for the betterment of the collective. Individualism is not a solution.

Re: Sourcehut will blacklist the Go module mirror

#214

Earlier quoted context omitted.

> [1]: https://www.slideshare.net/dberkholz/assholes-are-killing-yo ... This is the kind of thing I'm asking about. Lots of numbers are trotted out but where's the actual data? Where's the methodology? The blurb says, "This talk will teach you, using quantified data and academic research from the social sciences, about the dramatic impact assholes are having on your organization today and how you can begin to repair…

> Social science research has a dramatically poor replication rate, so on that basis alone I'm skeptical of the numbers even if he did interpret them correctly. It's not a perfect science, but that doesn't mean "do nothing" is the best option, or that we can't just use common sense for that matter. If someone joins a community space and their first interaction is being insulted then the chance that they will come bac…

Sure, I'm not suggesting "do nothing", I elaborate on what I'm suggesting in another reply below, re: backoff/retry strategies. I think online community management software needs features to better handle defectors and other non-constructive interactions, and not just focus on features that facilitate or ease communication. Sometimes you don't want to increase communication speed, sometimes you want back pressure to slow things down.

Re: Sourcehut will blacklist the Go module mirror

#215
post #115

Earlier quoted context omitted.

[flagged]

Virtually nobody uses PGP, and it is not at all pivotal. It is one of the least important widely-known cryptosystems on the Internet; like the book "Applied Cryptography", it has a cheering section because of the era in which it was released, and a generation of lay-engineers has taken PGP as a synecdoche for all privacy cryptography. It is also badly broken and has an archaic design. Most notably: Filippo had nothin…

I am no cheering fan, for sure, but I think it's disingenuous to say PGP is one of the least important systems on the internet. Debian package distribution, notably, depends rather pivotally on PGP to ensure authenticity. Keybase uses PGP as it's root trust mechanism. There are plenty of email services that use PGP to secure messages. I've even come across some recent (as in the last few years) startups using PGP to implement their internal or application-level trust relationships (run by quite sane and well adjusted individuals nonetheless). I worked at a Unicorn in the last 10 years that implemented secret storage and distribution using GPG tooling. In fact, recently and close to home for me, we implemented some application level key exchanges and the security person we consulted with for a 2nd set of eyes actually said (paraphrasing), "I don't like this thing it's custom but if you use ElGamal I'd be more comfortable because at least it's well understood."

Of course these are all things that can and probably should be replaced by something more palatable. So why haven't they?

If it's not obvious, my argument is neither for nor against PGP, really. It's that I'm tired of hearing about how much PGP sucks without also hearing about the solution. I think the burden is on the people wishing to eradicate it to muster up the blesséd alternative and shepherd it into the vernacular.

Re: Sourcehut will blacklist the Go module mirror

#216

Earlier quoted context omitted.

https://github.com/golang/go/issues/30141#issuecomment-46427... I don't have a full list of all posts at hand (some of which may be removed), but I've seen some other similar stuff as well; it's not an isolated incident. I was reading through the previous thread on this issue (goproxy sending loads of requests) and this one was posted as an example there.

I was indeed in the wrong when I made this comment four years ago. I have since apologized for it. I don't intend to re-litigate anything on HN at this point, but I have good reason to believe that this incident is unrelated to the reason I am presently banned. The linked comment was indeed out of line, and perhaps you feel justified in thinking that it should be sufficient grounds for a permanent expulsion from the…

> I don't think it's reasonable to use it as grounds to suggest that anyone should have their servers DoSed by Google with no recourse

Of course not; this entire thread isn't necessarily hugely on-topic here, but it got brought up, so ... well ... here we are. And in fairness, you did bring up your ban in the posted article.

> The linked comment was indeed out of line, and perhaps you feel justified in thinking that it should be sufficient grounds for a permanent expulsion from the community. I won't argue with that, fair enough.

No, I don't think anyone should be banned for a singular comment, no matter how egregious. Everyone deserves second chances, and third ones, even fourth ones maybe. There's some decent data from Stack Overflow that shows that after a ban many people keep posting and many don't get a second ban (i.e. their behaviour improves).

> I have good reason to believe that this incident is unrelated to the reason I am presently banned.

I think the thing is that it's part of a pattern. Usually the "final straw" isn't the worst incident, or even that bad of an incident in itself. Incidents like this aren't isolated and previous behaviour does tend to factor in: "oh, that's the same guy who called us a bunch of morons last year".

Re: Sourcehut will blacklist the Go module mirror

#217
post #209

The Go team has been making progress toward a complete fix to this problem. Go 1.19 added "go mod download -reuse", which lets it be told about the previous download result including the Git commit refs involved and their hashes. If the relevant parts of the server's advertised ref list is unchanged since the previous download, then the refresh will do nothing more than the ref list, which is very cheap. The proxy.go…

I suspect they have a problem with this DDoS by default unless you ask to opt out behavior. Why is anyone getting hit with these expensive background refreshes until you have a chance to do it right? Why is it still not done right 2 years after this was first reported?

Maybe it should be an opt-in list where the big providers (such as github) can be hit by an army of bots and everyone else is safe by default.

Re: Sourcehut will blacklist the Go module mirror

#218

Earlier quoted context omitted.

> [1]: https://www.slideshare.net/dberkholz/assholes-are-killing-yo ... This is the kind of thing I'm asking about. Lots of numbers are trotted out but where's the actual data? Where's the methodology? The blurb says, "This talk will teach you, using quantified data and academic research from the social sciences, about the dramatic impact assholes are having on your organization today and how you can begin to repair…

> Social science research has a dramatically poor replication rate, so on that basis alone I'm skeptical of the numbers even if he did interpret them correctly. It's not a perfect science, but that doesn't mean "do nothing" is the best option, or that we can't just use common sense for that matter. If someone joins a community space and their first interaction is being insulted then the chance that they will come bac…

> They just replied with "no, I will not change, fuck off".

As a former Rust moderator, this, so much. So many people don't see this part, where you reach out to folks and spend long grueling hours trying to get them to correct their behavior, precisely because no non-psychopath wants to drop the ban hammer on anyone. (Unless it's for obvious spammers and drive-by trolls.)

And the people saying "well I'm not suggesting do nothing, but just use better tools." Well, yeah, great, let's use better tools. Who's going to get GitHub to implement them? Or whatever other platform you're using? Some platforms have better support for this kind of tooling than others, but GitHub's is (last time I checked) pretty bad and coarse. It is slowly getting better over time. It used to be virtually non-existent.

But in the mean time, the people actually in the trenches doing the hard work of moderation have to do something. If the platform doesn't have this sort of idealistic tooling that's easy to navel gaze about on HN, then they have to do the best with what they have.

Re: Sourcehut will blacklist the Go module mirror

#219

Earlier quoted context omitted.

Why? Google has quite a reputation for wrongfully banning people from things. This doesn't seem unusual for them at all.

> Google has quite a reputation for wrongfully banning people from things. Extraordinary claims require extraordinary evidence.

There's nothing "extraordinary" about that claim. All online service providers do this, Google especially, and everyone on the internet knows that.

Re: Sourcehut will blacklist the Go module mirror

#220

What's the value proposition of not using Github? Github is such an incredibly useful project. I actually go out of my way to avoid projects on Gitlab and co, just because I don't want to have to worry that it's going to just disappear one day because they thought they could out-build Microsoft.

Your argument seems to be based on the idea that Microsoft would do a better job than its competition technically. The fact that you're happy to rely on them also seems to imply you think they're unlikely to act abusively. However, you're writing your comment in a thread about a similar megacorporation, Google, who is acting abusively, because their engineers are saying parsing a robots.txt file would be too difficult.
Post reply on HN