Live data from Hacker News

A cautionary tale about software dependencies during major geopolitical events

blog.benjaminvr.net

11–20 of 41 posts

Re: A cautionary tale about software dependencies during major geopolitical events

#11

I've had to reread, I was certain I missed something. But no, this is entirely conspiratorial speculation without any basis _or_ even without any point? If at least they explicitly put forward a theory like "it's russian influence to slow down western digital development" it would have some internal consistency, but no. They suppose it's russian influence (again, without basis) without any theory of _why_ Russia woul…

> any theory of _why_ Russia would care about an inconsequential CSS-related lib

Most likely he didn't want to deal with the maintenance burden of CSS-in-JS or React.

I must be Russian because I don't want to deal with that either. Those darn Russians...

Re: A cautionary tale about software dependencies during major geopolitical events

#12
post #2

>> The founder & lead developer is Russian and does not accept donations, perhaps noble, perhaps to avoid a financial trail. In modern Russia, if one receives money transfer from any other country, they may receive "Foreign Agent" (иностранный агент) status https://en.wikipedia.org/wiki/Foreign_agent "prohibited from receiving state funding, teaching at state universities, or working with children"

As per the page you linked to, FA law applies only to this who engage in “political activity”, which most people (regardless of the country) tend not to do.

Re: A cautionary tale about software dependencies during major geopolitical events

#13

I've had to reread, I was certain I missed something. But no, this is entirely conspiratorial speculation without any basis _or_ even without any point? If at least they explicitly put forward a theory like "it's russian influence to slow down western digital development" it would have some internal consistency, but no. They suppose it's russian influence (again, without basis) without any theory of _why_ Russia woul…

Major shifts in behavior from the lead developer does not concern you? Overthrowing the dependencies used and opting in for more experimental and not as battletested JS frameworks does not alarm you?

Going against a strong personal opinion after stagnation of development and a complete pivot on multiple levels is normal to you?

Shall I mention mainframes still run COBOL? Should I introduce the latest version of this library to achieve the same? You do know it entails more chance of something wrong happening, and yes the developer is Russian, didn't we have an advisory against Kaspersky?

Why would a repository with six figure stars be negligible and Kaspersky not? Please read other comments as well. Thanks for your perspective and have a great weekend.

Re: A cautionary tale about software dependencies during major geopolitical events

#14
post #2

>> The founder & lead developer is Russian and does not accept donations, perhaps noble, perhaps to avoid a financial trail. In modern Russia, if one receives money transfer from any other country, they may receive "Foreign Agent" (иностранный агент) status https://en.wikipedia.org/wiki/Foreign_agent "prohibited from receiving state funding, teaching at state universities, or working with children"

As per the page you linked to, FA law applies only to this who engage in “political activity”, which most people (regardless of the country) tend not to do.

[deleted]

Re: A cautionary tale about software dependencies during major geopolitical events

#15
post #8
post #5

Is the author's implication that the developer took the project in a different direction because of the war? I don't understand what the connection is between "major geopolitical events" and the library. It's just a graph that shows that a year after the war started, the developer removed a feature the author liked.

It's more than just this - I wouldn't write a "conspiratorial article" out of nothing, but alas I can not provide depth without risking identification of the people involved and painting a target on my back. I am watching the advisories for the dependencies closely. Please check my other comment as well. Thank you, have a great weekend.

Given that this is the internet and I don't know you, how can I distinguish a sane person making well founded claims backed by hidden evidence they won't share with me, and a crazy person just being paranoid and seeing conspiracy where there is none?

Usually the evidence is what makes the difference, but if you can't/won't share the evidence then what good are the accusations?

Re: A cautionary tale about software dependencies during major geopolitical events

#16
post #10
post #3

I don't really see how this has anything to do with major geopolitical events, other than the fact that the developer of the library is Russian. The author's complaints could have happened with any open source library and don't seem to relate to the war in Ukraine in any way.

To give a more realistic answer to this question, when I was writing an article about npm dependencies[1], I incidentally came upon a case where the developer of node-ipc released a malicious version of the package that affected computers in Russian and Belarusian IPs specifically in response to the Ukraine war[2]. [1]: https://www.preethamrn.com/posts/who-actually-uses-is-odd [2]: https://www.bleepingcomputer.com/ne…

And then claimed his GitHub was "hacked" to save his ass. And was somehow not banned by GitHub despite clearly violating their TOS.

Re: A cautionary tale about software dependencies during major geopolitical events

#17
Have there already been cases where a project switched part of their codebase to protest something(whatever it may be) and it resulted in lower quality/security issues, or is that something we'll see in the future?

Seems like an interesting attack vector. LibFoo was made by BadGroup, use LibBar instead, it's GoodGroup approved!

Meanwhile LibBar has security flaws, known or unknown, intentional or unintentional, which quickly get absorbed into other projects in a political frenzy to expel LibFoo at all costs (and said actions also are incentivized given that they drive publicity, engagement, etc).

I would have thought this completely nuts, prior to the whole node-ipc malware debacle. I would expect state actors to make the most of this expanded Overton window.

Re: A cautionary tale about software dependencies during major geopolitical events

#18
post #7
post #4

Earlier quoted context omitted.

I read the article and got the same impression. It had no conclusion on global event affecting dependencies. More speculations rather than facts.

Thanks for your comments. I have to admit that it is shallow - going in more detail would risk identification of the people involved and paint a target on my back. I do realize that he may have simply changed his opinion - yet it is the most controversial one and he stood by it ideologically as expressed numerous times through a variety of mediums. It's a bit tinfoil hat, but I am disappointed and there's no harm in…

As someone off this thread, lol, I hope you have a great weekend too.

Whether it happened or not, it's a reminder of what can happen. Better to learn from mistakes you haven't suffered from so deeply yet. For starters, when in doubt, it doesn't hurt to get rid of the software dependencies you don't need.

For how to know you can trust a dependency, I'm afraid there is no solution: no theorem prover nor isolation, cryptography nor layerizarion can save you.

Though the dead weight loss of mutual distrust weighs on us all, shouts echo in the void, so go home and read code, and when the next day knocks its ugly knuckles, tears at least wet dry watchful eyes.

Re: A cautionary tale about software dependencies during major geopolitical events

#19
Yeah, of course, there are many much worse effects from this invasion. But one, while less harmful than the many deaths and displaced people, that hits close to home is that it is not really possible to collaborate with folks in Russia anymore. Hopefully their country will relent and allow them to rejoin the international community.

Re: A cautionary tale about software dependencies during major geopolitical events

#20
post #8

Earlier quoted context omitted.

It's more than just this - I wouldn't write a "conspiratorial article" out of nothing, but alas I can not provide depth without risking identification of the people involved and painting a target on my back. I am watching the advisories for the dependencies closely. Please check my other comment as well. Thank you, have a great weekend.

Given that this is the internet and I don't know you, how can I distinguish a sane person making well founded claims backed by hidden evidence they won't share with me, and a crazy person just being paranoid and seeing conspiracy where there is none? Usually the evidence is what makes the difference, but if you can't/won't share the evidence then what good are the accusations?

That's fair, shall I put the names in the article and a link to the repository? Really, it's a war. Do you think I will risk my own wellbeing just to have clout for a few days?

Not to mention opening myself up for the possibility of being sued by one or more contributors for "slander". I chose this approach and won't budge on that - it's not a fairy tale that people are dying and everything is affected by it, the list of embargos is considerable.

Consider that you are connected to the world - including Russia. Would you trust your Russian neighbour if he pivoted his development style, opinions, pace, characteristics? No.

Have a great weekend. Thank you.

Post reply on HN