Live data from Hacker News

Linux dev quits after "personal attacks" from user over antivirus tool

neowin.net

31–34 of 34 posts

Re: Linux dev quits after "personal attacks" from user over antivirus tool

#31
post #25

As the former community manager for ClamAV, there could have been some work done here to correct the situation and make both parties happy. I know ClamAV doesn't want to see third party utilities go away, and it's beneficial to the community for them to exist. Trolls exist, but there are ways to deal with them. I ran ClamAV and Snort for about 15 years, and we had plenty of heat over the years. This could have been a…

A single developer doesn't have a 'community manager' to deal with assholes. That said, why would one try to make the troll happy? What reading this results in "they both have a valid point we should address"?

Also, you can’t make a troll happy. But you can redirect them and shut them down.

Re: Linux dev quits after "personal attacks" from user over antivirus tool

#32

Now hold on a minute. I'm reading the Codeberg posts, and I think Neowin is getting it wrong. The LoucheBear person seems to be saying that their ClamAV scan is clean without Kapitano, but not clean with Kapitano. Anyone want to grab the flatpak quick, just to see if somehow some malware hitched a ride? Anyway, if I'm reading this right, then these two people are just talking past one another, not understanding what…

> Off-topic: It's absolutely mad from a security perspective that you can't download flatpaks as a simple bzip file for security analysis. You can download Flatpak bundles: Flatpak supports exporting apps as .flatpak bundle files, which are single-file archives that can be analyzed offline. These can be created using flatpak build-bundle or downloaded if the distributor provides them. If...

From a security perspective, I don't trust the binary that downloads and installs a package to just download it. Some package installers, such as Bundler, like to run arbitrary code from the package on install. I don't trust that to not be invoked with a simple download. I'd rather use hardened tools like CURL or a web browser. It's just good security hygiene.

Re: Linux dev quits after "personal attacks" from user over antivirus tool

#33
post #5

I think it is a bid problematic that anybody can create an account on github and open issues there (if enabled). No "professional", paid software would allow ordinary users to communicate directly with the programmer. Or allow outsiders to post comments on their products website. Just moving discussions to irc would already filter a lot of spam. As a last resort you could require some kind of proof that you are a mai…

>I think it is a bid problematic that anybody can create an account on github and open issues there (if enabled). I think it's a bit problematic to use GitHub in 2025 if you are doing F/OSS

GitHub wasn't used there. It was on Codeberg.

Re: Linux dev quits after "personal attacks" from user over antivirus tool

#34

Earlier quoted context omitted.

Defamation lawsuit sounds like a perfectly valid avenue if that is the case.

Lawyers take effort, time, and difficulty. It's much easier to shut down a project instead. Alternatively, people can instead choose to NOT be dicks to people who are altruistically developing stuff for no compensation and the net benefit of our industry.

I suspect the person who did this to the maintainer is probably mentally unwell. They likely do this to other people.
Post reply on HN