Live data from Hacker News

Sourceforge Hijacks the Nmap Sourceforge Account

seclists.org

171–180 of 201 posts

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#171

This is not hijacking at all. They created a new account, the old one remains blank as the author says. Sure it's morally questionable and leads to having a very bad reputation. But it's not hijacking. GPL code can be forked, mirrored, bundled and distributed. As long as the terms of GPL are obeyed there's nothing technically wrong with what SF is doing. Of course they've completely blown all trust and squandered the…

They may well be GPL2/3 section 2a/5a (prominent notice that they have modified the program... in this case the installer) , and likely 2b/5b,c also (are they also providing the source code for the crapware?). If these are found not to apply (because the court finds it to be mere aggregation ) we may need a minor GPL update :-)

Alternately one could look into trademark law, perhaps?

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#172
post #22

Earlier quoted context omitted.

I didn't know they did this at this scale. I'm suprised by all the big names in the projects they've highjacked: I see apache, drupal, firefox, libreoffice, mysql, postgresql, redmine, sqlite, thunderbird, vlc, virtualbox and many, many others. They're really going all in with that.

From what I remember, even though Firefox is open-source, you can't use the Firefox name on distributing it without getting approval from Mozilla. This is why Debian went at some point with the Iceweasel name. So Mozilla controls what gets distributed with the Firefox name and they could sue for trademark violations if they want to. IMHO, all open-source projects should protect their name. For example last time I tri…

If you have ever uploaded something to sourceforge you have given them the right to use your trademark in perpetuity, something to think about when posting on public sites like this.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#173
This is incredible.

We need end to end security without this https insanity as a bandage more than ever. Ubiquitous signing and audit logs more than ever. Tools that, for normal end users, refuse to work if integrity is broken. What sourceforge is doing should be universally seen as damage and systematized intolerance should make the attempt pancake so hard and so fast that nobody ever even tries it.

It's excellent that the nmap people distribute gpg sigs. Now we need socialize the fact that "https does not mean I'm getting want I wanted from the original authors", and start building (yes, we need to get past the http://www.thoughtcrime.org/blog/gpg-and-me/ problems) and using tools that do better.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#174
post #43

Earlier quoted context omitted.

You either go bankrupt as a hero or live long enough to become the monetisation villain.

This is a bit controversial because people like to remember Sourceforge fondly for some reason, but it was never good. It was merely unchallenged. Google Code was never good either, but people gladly moved from SF to Google Code. And when something actually good came along (Github), Sourceforge simply vanished. Sourceforge was never a hero. It was a horrible website, with horrible UX. It always had pretty terrible ad…

This doesn't seem quite fair. I don't remember anything else like sourceforge when it came out in 1999. If you ran a project, you found a host somehow or paid for one, and you effectively managed and setup all of the services. From just the web site for the project itself, to the source code control, to mailing lists and bug tracking if you need them, forums. Further, colocation was common but VPS wasn't, if you rolled your own host you were on the hook for a computer for it. Now there may have been something else out there but I don't remember it and sourceforge was embraced because of it. They dramatically lowered the cost and effort to putting an opensource project out there. I assume that they basically created the model google code and github and the others have followed.

They've been in trouble, effectively since VA Linux's stock crashed...

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#175

This is the sort of behavior you get from a company that's lost, and is now trying to extract every penny they can from whatever shenanigans they can get away with. If they have no future brand value to be concerned about, then, from a game-theoretic approach, it's actually a pretty rational profit seeking move. (As long as they don't incur any downstream liabilities from outright illegal activity for which they migh…

It can never be rational to violate other people, because if you have a rational system of values, doing so will make you feel bad.

Drag down SourceForge all you want (I applaud that) but don't drag down rationality with it.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#176
post #127

Earlier quoted context omitted.

People remember Sourceforge fondly because the service they offered, for the time, was good. Everything internet sucked around 2000. Search engines where either semi-curated listing or covered a fraction of what was a much smaller internet. Free hosting was a joke, affordable paid hosting was not much better. Your bandwidth at home was not good and anyway your computer was not the powerhouse it is today - you needed…

>Everything internet sucked around 2000. Search engines where either semi-curated listing or covered a fraction of what was a much smaller internet. I disagree, and in fact preferred the internet of 2000 to the internet of 2015. Google search worked fine in 2000: although SEO existed in 2000, it was much less refined and extensive than in 2015. The main problem in search results today is that profit-motivated content…

Here's a good rule of thumb to keep in mind:

Any time you have a "theory" about other people that implies that you have a natural superiority to them based on your belief that you have superior taste, you're almost certainly full of yourself

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#177

Yeah, sad that I at one point thougthey were trustworthy. Hell, at one point I thought CNET was safe...until I downloaded and installed a "BestMp4ToMp3 converter" from there that infected the corporate network. Scumbag city, those sites. That's a major reason I support FOSS like VLC financially.

They were trustworthy at one point. I was a SF.net developer a long time ago and I can assure you that the number one consideration was the Open Source community. Sure there were ads but never once were we asked to compromise any project to increase ad sales.

Honestly, in hindsight I wish we had gone to a model more like Github.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#178

Earlier quoted context omitted.

>Everything internet sucked around 2000. Search engines where either semi-curated listing or covered a fraction of what was a much smaller internet. I disagree, and in fact preferred the internet of 2000 to the internet of 2015. Google search worked fine in 2000: although SEO existed in 2000, it was much less refined and extensive than in 2015. The main problem in search results today is that profit-motivated content…

Here's a good rule of thumb to keep in mind: Any time you have a "theory" about other people that implies that you have a natural superiority to them based on your belief that you have superior taste, you're almost certainly full of yourself

I can usually stay engaged and interested in static documents consisting of black text on a white background for many hours in a row. Some of the people in my life need more mental stimulation than that can provide, and spontaneously tell me as much. (Their main source of mental stimulation is social interaction.)

What part of that or my other comment implies that I think I have superior taste?

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#179

The only viable long term way for any open source project is to selfhost[1] [1] https://www.enalean.com/en/Open-source-community-host-yourse...

It's worth noting that most of the open source software that self hosts becomes an ad page or malware site within a few years once it's abandoned. One advantage to hosting on a shared site is that the project can live on. Or, at least, the binaries and source are still available for interested parties years after the developers moved on, lost interest, or passed away.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#180

In spite of account hijacking, GIMP was still downloaded by almost 15k people this week. Six days ago they took over Audacity project as well, which was downloaded by more than 150k this week[0]. [0] http://sourceforge.net/projects/audacity/

What will happen if I run Audacity installer from sourceforge? I have done that an hour ago. Should I be concerned?

You got the same download as you'd get from Audacity itself. SourceForge is acting as a mirror. Unfortunately, the Audacity installers are not digitally signed, but they are bit-for-bit identical on the SourceForge download to the Audacity website download.

SourceForge never modified installers of projects. Even of ones like FileZilla participating in the program. They push "download offer installers". So, if you try to download FileZilla, you get a 750K download that shows you offers when run and downloads the actual FileZilla installer in the background and runs that after you accept or decline the offers.

Post reply on HN