Live data from Hacker News

Xz: A microcosm of the interactions in open source projects

robmensching.com

251–260 of 353 posts

Re: Xz: A microcosm of the interactions in open source projects

#251
post #31

I do sometimes wonder if by trying to be "nice" to users and try to see the best intentions of commenters, many developers waste huge amounts of mental energy. For context, I've really only worked on "fun" side projects, namely emulators and game remakes, where I've explicitly avoided any mention of donations or similar. Both as it's intended to be a distraction from my job, not become part of it. And generally avoid…

I'm always surprised at how much developers and maintainers will willingly put up with. For example, if you visit the Matrix feed for the Asahi Linux project, you'll see hoards of trolls and time-wasters that are regularly engaged by Asahi team members who are giving them the benefit of the doubt, when they really should be removing those posts without comment or acknowledgement. I believe this masochistic behaviour…

I recently discovered a bug in the react-hooks-form library.

The author there does the absolute minimum of interaction.

Issues not following exactly the template or lack a repro gets closed immediately without any comment, actual bugs also see very limited comment or openness to discussion.

It felt a bit weird at first, but I do get the author and the library is succesful, maybe exactly because of this approach.

It made me reconsider some of the effort I spend in my open source projects with useless issues / comments.

Re: Xz: A microcosm of the interactions in open source projects

#252

Earlier quoted context omitted.

I don't personally know anyone who would run any Debian release that's not stable on production systems. On your desktop? Fine. I do it myself. On a server, with ports open to the public Internet that's a big nope. There's nothing wrong with Debian stable having years-old packages either. In any case: > The current "stable" distribution of Debian is version 12, codenamed bookworm. It was initially released as version…

I didn't say there's anything wrong, I meant that choosing the OS distribution with the oldest packages isn't an indication for how widespread the distribution of this package was.

I was initially responding to

> > It made it to production, for a long time

I never said it didn't make it to production. I was asking if that's the case, and giving one data point.

It apparently didn't make it into Ubuntu LTS either, so there's another one.

If you have information that proves or disproves either point, please present it.

Re: Xz: A microcosm of the interactions in open source projects

#254

Earlier quoted context omitted.

What form should this ignoring take, in your eyes? I’ve never maintained an open source project but I’d imagine this is the hard part, how to politely decline the peanut gallery’s feedback. Do you disable GH issues? Leave them open and ignore them? Decline with some boilerplate language? How do you stop people from being mad that you’re ignoring them? (IME these types of people are likely to take things personally an…

Say no, politely, with your reasons. If they continue to argue: 1) Unwatch the issue/block emails realted to the issue (setup tooling for this) 2) If they continue to harass just block them, they are a waste of your precious time and energy And yes they will go cry on reddit or HN or their own blogs and call you names. Ignore it. Be happy in the knowledge of the thousands or millions of people whose lives you have im…

Don't even engage to begin with. Embrace elitism. Embrace the natural order. "The lion needn't be polite to the sheep." ;p Plus, they're probably Chinese intelligence agency bots.

Re: Xz: A microcosm of the interactions in open source projects

#255
post #52

Earlier quoted context omitted.

No. https://geekfeminism.fandom.com/wiki/Who_is_harmed_by_a_%22R... >

I despise real name policies on social networks, but it's a very different thing to be anonymous while in a position of public trust.

"built a compression lib some people used" seems a stretch for "position of public trust".

How about some responsibility for the IBM devs who could have contributed to the library they decided to paste into sshd?

Re: Xz: A microcosm of the interactions in open source projects

#258
> This thread is a microcosm of the interactions in Open Source projects. Consumers make demands (some polite, some not-so-polite) of one maintainer (rarely two) that does everything.

> Make no mistake. This is the way it works.

> It needs to change.

How?

Re: Xz: A microcosm of the interactions in open source projects

#259

Earlier quoted context omitted.

Usually, I try to use projects in languages I work with so if the issue is not important enough for me to make a PR, then it’s not important enough. One thing I wish were possible is to sponsor an issue. I don’t usually sponsor open source projects, but I would likely sponsor a lot of issues just to speed up resolution. I think this could move a lot of projects in the right direction. Depending on difficulty, the mai…

As long as that money is held in escrow. Otherwise vaporware would make a killing.

You could Make them supply a test case that unlocks the escrow.

This both makes a bar that the bug creator has to pass, filtering some of the drive by time wasters, and gives a reward to the developers for fixing it.

Re: Xz: A microcosm of the interactions in open source projects

#260
post #176

I think the idea this was HUMINT operation by a state sponsored intelligence service is more likely. The twitter thread here was interesting. https://x.com/thegrugq/status/1774392858101039419 Raging about these being inconsiderate people, when they were likely fictional personalities that were part of a long con seems to be a bit foolish to me.

> I think the idea this was HUMINT operation by a state sponsored intelligence service is more likely. It's not an either/or proposition. I definitely think it was state sponsored, AND one method used was social engineering a burned out maintainer.

It seems to me that people are very much exaggerating how "professional" this attack was. Yes, it doesn't look like the actions of a single bored teenager but I don't think the government of a country like the USA or China would deliberately permit their employees to get involved with crap like this. Any backdoor they try to insert would look exactly like an innocent bug. So my (uninformed) guess would be that this is done by criminals, something like a ransomware gang branching out a bit. Though North Korea sometimes sponsors activities that are indistinguishable from those of a criminal gang so it could come from there.

I'm just speculating, of course. I don't know anything really.

Post reply on HN