Live data from Hacker News

Sourceforge Hijacks the Nmap Sourceforge Account

seclists.org

111–120 of 201 posts

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#111
The original nmap page in the article is back live now.

As much as I hate malware, can we confirm it was sourceforge that got rid of the old page? Maybe someone set up the mirror after a data problem or error rendered the old page blank and just wanted to get it up, or that person was nefarious? (Occasionally people can be "too helpful" on community sites by registering other people's projects).

I guess the question is really who owns sf-editor1/2/3/4.

The reason being I can't see a lot of bonus for someone doing it this way. I'd just put adware in the margins. The site looks sketchy anyway these days so it's not doing them a lot of good...

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#112
What I don't understand about any of this is why anyone wouldn't just either move their project to Github or self host. Why would you even still have your project hosted on SourceForge?

I understand the author's grief and anger. I feel bad for them really as this will hurt the NMap brand, but come on, avoid the whole situation and just remove the project from SourceForge completely.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#113

The only viable long term way for any open source project is to selfhost[1] [1] https://www.enalean.com/en/Open-source-community-host-yourse...

A site like Github that hosts open source projects brings a lot of value to the community. Great search, and the same UI when going from project to project. This would be much more cumbersome and time consuming if every project was on a different site with a different interface.

Also, many open source projects don't have the money to afford bandwidth costs of providing large software downloads.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#114
post #55

Earlier quoted context omitted.

To be clear - there is a difference between mirroring (which is good netizen behavior, and to be complimented), and trojaning (which is modifying the upstream sources before delivering them to users - which is decidedly not good netizen behavior). It's important to understand which is which for those accounts.

As long as one of those accounts is trojaning (or even just suspected of possibly having been trojaning once) it instantly poisons all the mirrors. Even if they are perfect netizens 99% of the time, that 1% makes all their other efforts useless.

Whoa what. Are you suggesting that suspicion of possibly maybe having put a trojan in someone else's files somewhere is grounds to make all one's efforts useless and poisons everything else you do?

Geeze, I guess we should stop using Google. They've been accused and suspected of much worse by a lot of people. I hope that's not what you meant.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#115
post #112

What I don't understand about any of this is why anyone wouldn't just either move their project to Github or self host. Why would you even still have your project hosted on SourceForge? I understand the author's grief and anger. I feel bad for them really as this will hurt the NMap brand, but come on, avoid the whole situation and just remove the project from SourceForge completely.

I was wondering the same thing.

Clean up your mess when you're done and you won't have rats.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#116
post #67

The BOFH in me is more upset with the software projects that abandonded those accounts without properly closing them.

The problem is that it is basically impossible to completely close and remove a software project from Sourceforge. The best you can do is tag it as "inactive" or "relocated" and provide a link to the new site, but the project site will still exist.

Can you delete all the code from it? Or do they prevent that as well?

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#117
post #112

What I don't understand about any of this is why anyone wouldn't just either move their project to Github or self host. Why would you even still have your project hosted on SourceForge? I understand the author's grief and anger. I feel bad for them really as this will hurt the NMap brand, but come on, avoid the whole situation and just remove the project from SourceForge completely.

> What I don't understand about any of this is why anyone wouldn't just either move their project to Github or self host. Why would you even still have your project hosted on SourceForge?

They won't let you "move" a project.

http://arstechnica.com/information-technology/2015/06/source...

> At SourceForge.net, we feel a commitment to ensuring the long-term availability of the Open Source code released by the projects we host. We will weigh requests for project removal against the community value of leaving the project intact...Projects which have moved to another hosting provider are typically retained at SourceForge.net (though you can make a note on the project web site and project summary page directing users to the new home) for sake of retaining materials of historical value.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#118
post #112

What I don't understand about any of this is why anyone wouldn't just either move their project to Github or self host. Why would you even still have your project hosted on SourceForge? I understand the author's grief and anger. I feel bad for them really as this will hurt the NMap brand, but come on, avoid the whole situation and just remove the project from SourceForge completely.

I think the problem is that abandoning your project on Sourceforge doesn't have the intended effect.

"SourceForge, the code repository site owned by Slashdot Media, has apparently seized control of the account hosting GIMP for Windows on the service, according to e-mails and discussions amongst members of the GIMP community—locking out GIMP's lead Windows developer. And now anyone downloading the Windows version of the open source image editing tool from SourceForge gets the software wrapped in an installer replete with advertisements."

http://arstechnica.com/information-technology/2015/05/source...

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#119
post #106

Earlier quoted context omitted.

Not sure how profitable GitHub is, but there are users paying for private repositories or for the Enterprise version and the revenues thus far seem to be enough to support the free users as well and to an outsider like me being a win-win situation, since GitHub is now the place to be on, with open-source projects giving them free exposure, with the Enterprise version starting to win against other established solution…

Github are indeed the heroes of the day and have an enterprise revenue model. So far, so good. But Sourceforge is sixteen years old. Will Github still be the good guys in 2030? It's impossible to know.

SourceForge used to have an enterprise revenue model, too. They bet the company (or at least the name) on it - VA Research -> VA Linux -> VA Software -> SourceForge -> GeekNet -> {Dice and HotTopic^WGameStop}.

If Github ever pivots to selling t-shirts, run.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#120
post #55

Earlier quoted context omitted.

As long as one of those accounts is trojaning (or even just suspected of possibly having been trojaning once) it instantly poisons all the mirrors. Even if they are perfect netizens 99% of the time, that 1% makes all their other efforts useless.

Whoa what. Are you suggesting that suspicion of possibly maybe having put a trojan in someone else's files somewhere is grounds to make all one's efforts useless and poisons everything else you do? Geeze, I guess we should stop using Google. They've been accused and suspected of much worse by a lot of people. I hope that's not what you meant.

Are you suggesting that suspicion of possibly maybe having put a trojan in someone else's files somewhere is grounds to make all one's efforts useless and poisons everything else you do?

Short answer: Yes. Downloading and running arbitrary binaries from the web inherently a quite dangerous thing do to, and I only feel comfortable taking such a risk with sites I trust. I no longer trust Sourceforge and there is very little they can promise me to make me start wanting to download from them again.

Post reply on HN