Live data from Hacker News

Sourceforge Hijacks the Nmap Sourceforge Account

seclists.org

161–170 of 201 posts

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#161
post #129

Earlier quoted context omitted.

>What I don't understand about any of this is why anyone wouldn't just either move their project to Github or self host. Personally, I like their download stats: https://sourceforge.net/projects/apng/files/libpng/stats/tim... But generally, why would I move if I never had problems with the service?

Because perhaps--just fucking perhaps--you don't want malware injected into any of your projects when they're downloaded?

I keep complete control over my projects, and I'll make sure it won't happen.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#162
post #60

Earlier quoted context omitted.

The problem now is raising the alarm all the way out to the endest of end users, that this formerly trusted site cannot be trusted anymore. Perhaps Google could step up and de-list them, but that is a pretty slippery slope.

Patio11 suggested that in relatoin to Gimp. Also, someone helpfully posted the google link to report websites: https://www.google.com/safebrowsing/report_badware/ Suggested reason is "embeds malware/adware with downloads".

I doubt this would ever happen. A large portion of Google's own ad revenue comes from companies distributing adware. I worked for a company that was in the adware distribution business and we funnelled millions to Google--to the point that we had dedicated account reps at Google who helped us to make sure we stayed compliant with Google's adwords policies so we could keep peddling our adware installers.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#164

Earlier quoted context omitted.

Plenty popular names on there. That's shocking.

To be clear - there is a difference between mirroring (which is good netizen behavior, and to be complimented), and trojaning (which is modifying the upstream sources before delivering them to users - which is decidedly not good netizen behavior). It's important to understand which is which for those accounts.

Interesting weaseling of SourceForge is to add a "downloader" which fetches either the actual unmodified installer/sources. The "downloader" installs adware while fetching the real installer for the software. In the case of GIMP the filename of the downloader was made to be the same as the filename expected of the installer for a given version. This dirty approach might be thwarting ways of protecting with cryptographic signatures, or even trademarks/copyleft.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#165
post #151

Earlier quoted context omitted.

>Everything internet sucked around 2000. Search engines where either semi-curated listing or covered a fraction of what was a much smaller internet. I disagree, and in fact preferred the internet of 2000 to the internet of 2015. Google search worked fine in 2000: although SEO existed in 2000, it was much less refined and extensive than in 2015. The main problem in search results today is that profit-motivated content…

You probably mean that you like the good design from 2000 (and well I share your opinion on that). But there was also the bad ones and there was a lot of them. The majority of banking sites required you to use ActiveX, very frequently the shopping websites would use weirdo content plugins or have their content in PDF. Those were the times of multi-frame abuse, webpage with sound and no control, site trying to be clev…

Those were the times of multi-frame abuse, webpage with sound and no control, site trying to be clever and disabling right-click. Pop-ups everywhere, site hijacking your browser window and resizing, moving it around. Stupid cursor that make your computer grind to a halt. Site designed for 640x480 and nothing else.

A lot of these still happen, except they are using different technologies and look slightly different. We have parallax scrolling, Bootstrap-like modal windows, unlinkable single-page apps, websites that screw up "back" button and above all we have pages that require you to download several megabytes of junk and execute tons of JavaScript just to read several kilobytes of text.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#166

Earlier quoted context omitted.

>Everything internet sucked around 2000. Search engines where either semi-curated listing or covered a fraction of what was a much smaller internet. I disagree, and in fact preferred the internet of 2000 to the internet of 2015. Google search worked fine in 2000: although SEO existed in 2000, it was much less refined and extensive than in 2015. The main problem in search results today is that profit-motivated content…

I prefer using wikipedia or stackexchange for information rather than searching for hours

Wikipedia and Stack Exchange provide only one kind of information. There are several other types of websites that either went extinct or turned to garbage. Dr. Dobbs is a good example. StackOverflow might be the thing that helps you find a workaround for some API stupidity, but you are not going to "read" StackExchange on daily basis.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#167

Earlier quoted context omitted.

The problem now is raising the alarm all the way out to the endest of end users, that this formerly trusted site cannot be trusted anymore. Perhaps Google could step up and de-list them, but that is a pretty slippery slope.

No it isn't. The site was relevant before as it served what people needed, and was ranked high. It no longer is serving folks' interests, so it can be ranked lower, or de-listed. Completely fine.

I agree with you. To clarify my slippery slope comment, it applies in general to all users of censorship powers. Who is a fit judge to decide what you and I get to see?

D-listing from Google is basically being taken off the internet, so wielding that power too often might get Big G into alot of trouble with agencies like the European Commission.

On balance I think SourceForge deserves a browser level "here be malware" warning, trusting that most users will make the right choice if informed.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#169
I might be asking too late, but what's stopping someone from: 1. Identifiying hijacked accounts 2. Forking to GitHub 3. Waiting for the inevitable ranking change 4. Handing over the project to the owner when/if they are identified.

I realize there's a good deal of handwaving here--particularly at 3 and especially 4. But, is this a bad idea? Seems like 4 can be replaced simply by the owner reforking, too.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#170
This bit is inaccurate:

"Of course this goes directly against Sourceforge CEO Michael Schumacher's promise less than two years ago:"

Michael Schumacher is not SourceForge's CEO, but a GIMP developer. The article quoted in the mail was written by Roberto Galoppini.

Post reply on HN