Live data from Hacker News

Open source ‘protestware’ harms Open Source

opensource.org

181–190 of 575 posts

Re: Open source ‘protestware’ harms Open Source

#181
You can say what you want but this is a risk in remote unpinned dependencies.

As platforms it is important to protect against this making artifacts immutable. As people we can only protect against it by auditing upgrades depending on risk.

I much preferred the old world, where I could pick pretty much any software package and it would be safe but that is not today’s world. It’s entirely possible that a colorizer scans my disk for ethereum keys.

In practice I rely on social validation but it is not a safe thing in general. Unhappy about the outcome but this tends to happen in time.

In the end, it’s true. If you bomb my house, I will strike back in whatever way I can. If the only thing I can do is burn you and your children, I will. If the only thing I can do is destroy your hard disk, I will. I am limited in retaliation not by morality but by ability.

And if I am like this, then I must assume that others are, too. And that I might get caught in the collateral blast zone.

Re: Open source ‘protestware’ harms Open Source

#182
post #22

Earlier quoted context omitted.

Or, you know, I’ll never touch Vue.js again?

Charitably, it creates a new friction for Russian business in deploying open-source software. That drag further diminishes Russia’s economy, and thus, its warmaking ability.

At best, this operation could be construed as an act of vandalism or at worst an act of CYBER terrorism. This indiscriminate and malicious act of hostility was carried by what amounted to be a cyber weapon (think IED) housed in a very ordinary and non-suspicious package to cause the greatest damage to the users' data.

Re: Open source ‘protestware’ harms Open Source

#183
I personally think this kind of thing is just a symptom of a larger problem; the modern open source software ecosystem is highly vulnerable to supply chain attacks.

Frankly, given how normal it is to just blindly download unverified, unsandboxed code from random developers and execute it on our machines it's surprising this sort of incident isn't more common.

What we need are better tools and processes to detect and block malicious code in dependencies before it has a chance to execute. I wrote up a few suggestions for that several months ago and I think they're still applicable: https://news.ycombinator.com/item?id=29266992

Re: Open source ‘protestware’ harms Open Source

#184
post #161

On one hand, I don't want to be anywhere near protestware when it comes to my work or the tools I use. On the other hand, Javascript developers have a whole different culture than the developer circles I like to frequent. In npm-land, the societal expectations of quality and solemnity (for lack of a better word) are lower, and this kind of behaviour is even celebrated if it favors the "right cause". The last two case…

>Javascript developers have a whole different culture than the developer circles I like to frequent. Most Javascript developers I know are just writing code and that's what they're concerned with. Vocal voices on twitter or etc != most Javascript developers. I'd argue most vocal folks on forums or etc don't represent most developers of any given language.

Sure, just like most men aren't violent criminals but men are still statistically more likely to be violent criminals. The point is that JS devs seem (perhaps a proper statistical study will show otherwise) more likely per capita to shit up their ecosystem. There are several reasons contributing to this (the limited JS standard lib being a big one) but a major part of it really seems to be that JS devs are a different breed.

I've never seen controversies like this in the .NET/Nuget ecosystem, the only controversies I've ever seen there are over libraries changing licenses to make the authors more money, and controversies over Microsoft exercising too much control over the ecosystem.

Re: Open source ‘protestware’ harms Open Source

#185

Earlier quoted context omitted.

> In theory the same things could happen for PIP, Maven, Gradle, their Rust and Go counterpart and any such package manager. Any data on this? Supply chain attacks, such as these, can definitely happen to any language. NPM seems to be a nice target simply because the volume of deps your avg 'simple' node project has (I mean, 'npm generate'ing a simple strapi-backed static site for us and there's ~300mb of node_module…

It can be a problem in any language or package manager but in my Golang project, I have a single dependency outside of the standard library, in my Javascript project I conservatively have 200+ (if I consider all the packages installed by my primary dependencies). The surface area is just that much bigger and the packages change so frequently.

So you recon a better (bigger?) node stdlib would solve a lot of this?

Re: Open source ‘protestware’ harms Open Source

#186
post #132

Earlier quoted context omitted.

How hard is it to just say "I think Russia is wrong for invading Ukraine and killing people"? That's all you have to do. Just write it. If you can't do that, but still want to engage in the discussion on the topic, your standpoint is clear. You're not some holier person not taking a stand. You have taken one, you just don't dare to spell it out.

So by this logic, if your blog/commit logs doesn't contain: * russia invaded ukraine * vaccines work * wear a mask * black lives matter * trans women are women * abortion is a right then you're a pro-russian, vaccine-denying, anti-mask, white supremacist, transphobic, misogynist?

No one said that. I'm saying that if you cannot answer which "side" you're on, but still engage in the discussion (and thus have knowledge / interest in the subject), it's obvious for everyone to see.

Re: Open source ‘protestware’ harms Open Source

#187
post #34

Do people think the people protesting like this don't know that this is damaging? They presumably feel that the issue at hand is more important than that damage. Every protest every has been met with "but this protest is being done the wrong way, don't inconvenience me", but that's the point: protest has to disrupt things to make people take notice and make changes. Would I do this? No. I don't think it's effective o…

This is exactly it. For some people, a world that they relate to is coming to an end, and anything they could do, however insignificant, no matter what the side-effects or personal reputation cost, is worth doing. This isn't some brainy impact-analysis based action. "Something must be done". The disruptions caused by these rogue packages will make it to newspapers and the media, and maybe, just maybe, parrying the ne…

In that case, targeting only Russians is sub-optimal, They could as well have targeted everybody, it would have had more impact. There's no reason to target Russia inhabitants in particular, who, I would guess, are mostly against the war.

Re: Open source ‘protestware’ harms Open Source

#188
post #34

Do people think the people protesting like this don't know that this is damaging? They presumably feel that the issue at hand is more important than that damage. Every protest every has been met with "but this protest is being done the wrong way, don't inconvenience me", but that's the point: protest has to disrupt things to make people take notice and make changes. Would I do this? No. I don't think it's effective o…

This isn't so much of a protest as much as an nonviolent indiscriminate vigilante terrorist attack.

> The intent is to disrupt.

Presumably the intent is to help Ukraine. People need to stop and think about how their disruptive "protest" is actually going to help their cause rather than blindly chase awareness.

Re: Open source ‘protestware’ harms Open Source

#189

I'm in Texas. A LOT of Californians disagree with some of the laws that Texas has passed. How long will it be until my hard drive gets reformatted by some protestor in San Francisco who localizes my IP address?

What about Californians throwing Molotov at your house?

My point is analogy is not a valid tool of criticism when talking about policies, because their inputs and outcomes are not simple bool -> bool functions.

Would you be satisfied with 1000000 years on average as the answer?

Re: Open source ‘protestware’ harms Open Source

#190

Earlier quoted context omitted.

That would be a wonderful thing to able be do, if the woke brigade wasn't screaming "YOU'RE WITH US OR YOU'RE AGAINST US" a parent over. ;) Ignoring that isn't an option, unfortunately, believe me, that's been tried.

>yeah but so what Being silent about shitty behavior is the same as condoning it, don't you know? Just because you don't like the playbook doesn't mean it doesn't work. >Anybody who legitimately makes a "liberals only" stand in their license will get forked and their usage will drop off. Considering that the developer just pulled a "no russians" stand with their software...

> Being silent about shitty behavior is the same as condoning it, don't you know? Just because you don't like the playbook doesn't mean it doesn't work.

my point is that it doesn't matter. Condemn or not, regardless you can still fork earlier versions. Materially, it's not a threat to you.

> Considering that the developer just pulled a "no russians" stand with their software...

Yeah and look at how much shit they're catching for it. People are forking and freezing earlier versions, he's getting raked through the coals, etc. Is this really the outcome conservatives are afraid of?

Post reply on HN