Live data from Hacker News

Sourceforge Hijacks the Nmap Sourceforge Account

seclists.org

71–80 of 201 posts

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#71
post #51

Earlier quoted context omitted.

Damn, that's a lot of projects. OpenOffice, Apache server, hadoop, Audacity, CDex, Colloquy, that's all projects I have at one at my computers, and I haven't gotten to "D" yet. This is depressing

Seems weird that I could install Hadoop and get some shitty toolbar as a result.

Looks like an opportunity for cloudera

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#73
post #60

Earlier quoted context omitted.

The problem now is raising the alarm all the way out to the endest of end users, that this formerly trusted site cannot be trusted anymore. Perhaps Google could step up and de-list them, but that is a pretty slippery slope.

Patio11 suggested that in relatoin to Gimp. Also, someone helpfully posted the google link to report websites: https://www.google.com/safebrowsing/report_badware/ Suggested reason is "embeds malware/adware with downloads".

Could also write mails to the mirror providers listed here: http://sourceforge.net/p/forge/documentation/Mirrors/

And ask them to stop mirroring SF because they distribute Malware. I don't know how many of them provide the mirror for free though. I remember quite a few universities provided SF mirrors back in the day.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#74
post #22

If your old account is listed here, you getting fuxxored: http://sourceforge.net/u/sf-editor1/profile/ http://sourceforge.net/u/sf-editor2/profile/ http://sourceforge.net/u/sf-editor3/profile/ Edit: added http://sourceforge.net/u/sf-editor/profile/ which includes MySQL and a few other high profile projects.

I didn't know they did this at this scale. I'm suprised by all the big names in the projects they've highjacked: I see apache, drupal, firefox, libreoffice, mysql, postgresql, redmine, sqlite, thunderbird, vlc, virtualbox and many, many others. They're really going all in with that.

From what I remember, even though Firefox is open-source, you can't use the Firefox name on distributing it without getting approval from Mozilla. This is why Debian went at some point with the Iceweasel name. So Mozilla controls what gets distributed with the Firefox name and they could sue for trademark violations if they want to.

IMHO, all open-source projects should protect their name. For example last time I tried, VLC for iOS was banned from the iTunes Store, yet there were dozens of obscure apps using VLC's name or logo on iTunes Store (this was happening in January). Especially given that there is such a thing as an unregistered trademark, that is valid through usage. Even if you fork it, then authors should have the courtesy to use a different name.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#76
post #42

Sourceforge is now on my personal blocklist for Google search results. Along with expertsexchange which I added years ago, and Quora which may surprise some.

Read that as expert sex change, and thought you were revealing some very personal information on HN.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#77
post #54

Hijacking the account of one of the security community's most loved and used tool. Yeah ... that seems to be a smart idea.

Yep how to fuckoff both the Black , Grey and White Hat communities.

I wonder how many copies of nmap are running against Sourceforge's servers right now?

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#79

This is the sort of behavior you get from a company that's lost, and is now trying to extract every penny they can from whatever shenanigans they can get away with. If they have no future brand value to be concerned about, then, from a game-theoretic approach, it's actually a pretty rational profit seeking move. (As long as they don't incur any downstream liabilities from outright illegal activity for which they migh…

Has Archiveteam, Internet Archive or anyone else taken a shot at mirroring Sourceforge, including binaries? Since its founding there have been a hell of a lot of small projects hosted there whose sites have gone down since. 430,000 projects have been hosted on SourceForge at some point. At least a few tens of thousands of them represent the only remaining copy of a program needed to read a certain sort of data. Maintaining that capability in the face of a company circling the drain represents an extreme historical utility.

Even if you now need a VM to handle the crapware, that's better than losing the apps entirely. If somebody maintained a time-diffed mirror of SourceForge, they could pinpoint the last version before the bundling event occurred in an automated fashion, as well.

EDIT: It seems there's a project to begin this - http://archiveteam.org/index.php?title=SourceForge and an IRC channel, EFNet #coldstorage

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#80
post #43

Earlier quoted context omitted.

You either go bankrupt as a hero or live long enough to become the monetisation villain.

Sounds like a wise saying that I've read on every submission about Sourceforge, problem is that I think it is in general bullshit. If we'll look down in history, I think there are very few villains that have acted as heroes when starting out. The signs that such companies are assholes are in general there, from the start. As an example, I don't remember a time in which Sourceforge was the hero, as much as I try. Sinc…

> I don't remember a time in which Sourceforge was the hero, as much as I try

No offense to you personally, but this is a case where it's about grey hair more than ability.

There was certainly a time when Sourceforge was the wham-bam-snickety-snack boom-blam bomb. It was when Slashdot was the Hacker News, when "LAMP" was a new term, when 10Gbps across the U.S. (vs. your living room) was a Big Deal.

> If we'll look down in history, I think there are very few villains that have acted as heroes when starting out.

This is called playing "I told you so." In reality every organization begins with high ideals then adjusts to reality. The elegance of this transition defines how villainous they've become. Consider McDonalds and Whole Foods. Both seemed delightful at the beginning. We see how McDs is now cancerous (or at least diabetesacious) and Whole Foods is anti-union, but surviving anyway, a "mundane evil."

You can't predict which company will become evil or not.

Post reply on HN