Live data from Hacker News

Tell HN: Whole Yandex Git repository leaked

news.ycombinator.com

141–150 of 369 posts

Re: Tell HN: Whole Yandex Git repository leaked

#141

Earlier quoted context omitted.

It also sucks for privacy.

Its good for privacy if you don't live in Russia... I don't think that they share the data with US governments?

Remember this yandex.com is hq in Europe. yandex.ru is hq in russia. Search carefully.

Re: Tell HN: Whole Yandex Git repository leaked

#143
post #60

Earlier quoted context omitted.

Probably Yandex will start watching their infrastructure very closely, and go through all known attack vectors that haven't been prioritized before to fix them ASAP. Won't be a boon for OSS, any author would be idiotic to read stolen source code and then decide to create a OSS library/project based on what they learn from it.

> Won't be a boon for OSS, any author would be idiotic to read stolen source code and then decide to create a OSS library/project based on what they learn from it. This is naive. This generation seems very sensitive to the prospect of computer crime. The stolen source code will almost certainly be read, and if deemed novel enough will be turned into open source projects. It may be tough to figure out those projects a…

Black market repos? Who host those?

Re: Tell HN: Whole Yandex Git repository leaked

#144
post #93

Earlier quoted context omitted.

Tinkering is fine. Even leaking and study is fine. But re-licensing someone's else code is at the very least impolite. People avoid using BSD-licensed code in GPL code base, or vice versa, just to not violate an open-source license of some fellow hacker who won't sue (but would yawp on Twitter, or something). Also, cutting proprietary stuff out of the thick scaffolding of proprietary dependencies is often hard. Remov…

> People avoid using BSD-licensed code in GPL code base Huh? I don't believe they do that. It's completely fine to use BSD in GPL code, but not the other way around.

It is fine to do either but the result is always a GPL license.

Re: Tell HN: Whole Yandex Git repository leaked

#145
post #98
post #64

Earlier quoted context omitted.

I think the problem is people are entering a matured industry, all they know is the professional buttoned up culture we have today. People have no further curiosity beyond working and making money in tech. They do not have memories of a time when people tinkered around doing all kinds of crazy and possibly illegal stuff, just for fun, just to see if the could. Sad really.

> People have no further curiosity beyond working and making money in tech. For some, sure. There are also many who still explore, but qualitatively the overall culture feels very different. Unfortunately, there are employers who seem to want their employees to tinker, but own virtually everything they do, all while still playing lip service to supporting work-life balance, including parenting. So we get mixed messag…

> There are also many who still explore, but qualitatively the overall culture feels very different.

I thought the same, then one day I stumbled onto a discord populated by teens and college students who were doing the same sort of shenanigans my friends and I were up to back in the day.

The S/N ratio is worse, but there are still people out there having fun!

Re: Tell HN: Whole Yandex Git repository leaked

#148

Ukrainians probably hacked Yandex, because they thought, it is a Russian engine, but it is actually from Netherland/EU. They should be careful, otherwise Netherland will stop helping them with weapons pretty quickly.

It's a Russian company incorporated in Netherlands for the same reason why the Chinese buy real estate in Canada rather than at home.

Re: Tell HN: Whole Yandex Git repository leaked

#149

Earlier quoted context omitted.

No? It's 44GB of data. Magnet: magnet:?xt=urn:btih:7e0ac90b489baee8a823381792ec67d465488fef&dn=yandexarc&tr=udp%3A%2F%2Ftracker.openbittorrent.com%3A80%2Fannounce&tr=udp%3A%2F%2F9.rarbg.to%3A2920&tr=udp%3A%2F%2Ftracker.opentrackr.org%3A1337%2Fannounce&tr=udp%3A%2F%2Fexodus.desync.com%3A6969&tr=udp%3A%2F%2Fbt1.archive.org%3A6969%2Fannounce&tr=udp%3A%2F%2Fbt2.archive.org%3A6969%2Fannounce&tr=udp%3A%2F%2Fopen.demonii.co…

I would not build it, but I am sure just looking at code won't be the end of the world ( cue some ridiculous end of world the scenario Family Guy style ). There are risks, but I am not sure those risks are legal risks in this case. They are more along the lines of.. you wouldn't download and build Ghidra without checking would you? Who am I kidding.

>They are more along the lines of.. you wouldn’t download and build Ghidra without checking would you?

Ah, I think Ghidra is trustworthy now that it’s been OSS for years. I’ve heard it’s especially good for debugging performance issues with certain SCADA systems. Your centrifuges aren’t behaving? Better fire up Ghidra and figure it out!

Post reply on HN