Earlier quoted context omitted.
>What I don't understand about any of this is why anyone wouldn't just either move their project to Github or self host. Personally, I like their download stats: https://sourceforge.net/projects/apng/files/libpng/stats/tim... But generally, why would I move if I never had problems with the service?
Because perhaps--just fucking perhaps--you don't want malware injected into any of your projects when they're downloaded?
Sourceforge Hijacks the Nmap Sourceforge Account
161–170 of 201 posts
Re: Sourceforge Hijacks the Nmap Sourceforge Account
#162Earlier quoted context omitted.
The problem now is raising the alarm all the way out to the endest of end users, that this formerly trusted site cannot be trusted anymore. Perhaps Google could step up and de-list them, but that is a pretty slippery slope.
Patio11 suggested that in relatoin to Gimp. Also, someone helpfully posted the google link to report websites: https://www.google.com/safebrowsing/report_badware/ Suggested reason is "embeds malware/adware with downloads".
Re: Sourceforge Hijacks the Nmap Sourceforge Account
#163I think it's pretty clear that DHI has no shame, but what about the mirrors?
Re: Sourceforge Hijacks the Nmap Sourceforge Account
#164Earlier quoted context omitted.
Plenty popular names on there. That's shocking.
To be clear - there is a difference between mirroring (which is good netizen behavior, and to be complimented), and trojaning (which is modifying the upstream sources before delivering them to users - which is decidedly not good netizen behavior). It's important to understand which is which for those accounts.
Re: Sourceforge Hijacks the Nmap Sourceforge Account
#165Earlier quoted context omitted.
>Everything internet sucked around 2000. Search engines where either semi-curated listing or covered a fraction of what was a much smaller internet. I disagree, and in fact preferred the internet of 2000 to the internet of 2015. Google search worked fine in 2000: although SEO existed in 2000, it was much less refined and extensive than in 2015. The main problem in search results today is that profit-motivated content…
You probably mean that you like the good design from 2000 (and well I share your opinion on that). But there was also the bad ones and there was a lot of them. The majority of banking sites required you to use ActiveX, very frequently the shopping websites would use weirdo content plugins or have their content in PDF. Those were the times of multi-frame abuse, webpage with sound and no control, site trying to be clev…
A lot of these still happen, except they are using different technologies and look slightly different. We have parallax scrolling, Bootstrap-like modal windows, unlinkable single-page apps, websites that screw up "back" button and above all we have pages that require you to download several megabytes of junk and execute tons of JavaScript just to read several kilobytes of text.
Re: Sourceforge Hijacks the Nmap Sourceforge Account
#166Earlier quoted context omitted.
>Everything internet sucked around 2000. Search engines where either semi-curated listing or covered a fraction of what was a much smaller internet. I disagree, and in fact preferred the internet of 2000 to the internet of 2015. Google search worked fine in 2000: although SEO existed in 2000, it was much less refined and extensive than in 2015. The main problem in search results today is that profit-motivated content…
I prefer using wikipedia or stackexchange for information rather than searching for hours
Re: Sourceforge Hijacks the Nmap Sourceforge Account
#167Earlier quoted context omitted.
The problem now is raising the alarm all the way out to the endest of end users, that this formerly trusted site cannot be trusted anymore. Perhaps Google could step up and de-list them, but that is a pretty slippery slope.
No it isn't. The site was relevant before as it served what people needed, and was ranked high. It no longer is serving folks' interests, so it can be ranked lower, or de-listed. Completely fine.
D-listing from Google is basically being taken off the internet, so wielding that power too often might get Big G into alot of trouble with agencies like the European Commission.
On balance I think SourceForge deserves a browser level "here be malware" warning, trusting that most users will make the right choice if informed.
Re: Sourceforge Hijacks the Nmap Sourceforge Account
#168The BOFH in me is more upset with the software projects that abandonded those accounts without properly closing them.
https://mail.gnome.org/archives/gimp-developer-list/2015-May...
Re: Sourceforge Hijacks the Nmap Sourceforge Account
#169I realize there's a good deal of handwaving here--particularly at 3 and especially 4. But, is this a bad idea? Seems like 4 can be replaced simply by the owner reforking, too.
Re: Sourceforge Hijacks the Nmap Sourceforge Account
#170"Of course this goes directly against Sourceforge CEO Michael Schumacher's promise less than two years ago:"
Michael Schumacher is not SourceForge's CEO, but a GIMP developer. The article quoted in the mail was written by Roberto Galoppini.