Live data from Hacker News

Sourceforge Hijacks the Nmap Sourceforge Account

seclists.org

21–30 of 201 posts

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#21

If you didn't know sourceforge have back-pedalled 2 days ago and said they'll stop bundling the crapware in the mirrored projects: http://sourceforge.net/blog/third-party-offers-will-be-prese... The author, and a lot of the commentators here, don't seem to have seen that announcement.

Because they said it it must be true!

Fool me twice...

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#22

If your old account is listed here, you getting fuxxored: http://sourceforge.net/u/sf-editor1/profile/ http://sourceforge.net/u/sf-editor2/profile/ http://sourceforge.net/u/sf-editor3/profile/ Edit: added http://sourceforge.net/u/sf-editor/profile/ which includes MySQL and a few other high profile projects.

I didn't know they did this at this scale. I'm suprised by all the big names in the projects they've highjacked: I see apache, drupal, firefox, libreoffice, mysql, postgresql, redmine, sqlite, thunderbird, vlc, virtualbox and many, many others.

They're really going all in with that.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#23

If you didn't know sourceforge have back-pedalled 2 days ago and said they'll stop bundling the crapware in the mirrored projects: http://sourceforge.net/blog/third-party-offers-will-be-prese... The author, and a lot of the commentators here, don't seem to have seen that announcement.

We saw it, but why does it matter? They also claimed to never add adware without consent before. Even considering to bundle up malware with FOSS projects is offensive to me. They lost my trust and a simple blog post won't win it back.

The policy of taking over "abandoned" projects is super shady as well. That's what this mailing list post is about, isn't it?

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#24
post #6

I'm surprised the nmap.mirror site doesn't have hundreds of reviews telling people to not use it, and pointing them to the official site. I'd be interested to see how sourceforge respond to DMCA requests.

MOZILLA: http://sourceforge.net/projects/firefox points to "personal builds of Firefox"; http://sourceforge.net/projects/firefox.mirror/ seems to describe legit Firefox. I haven't tried to download it to see what I get.

FEDORA: http://sourceforge.net/projects/fedora/ points to some random software. http://sourceforge.net/projects/fedora.mirror describes Fedora the OS.

Not only scummy, but semi-competant too.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#25
Just submitted the story to Slashdot [1].

Sharing the same owner as Sourceforge let's see if it gets "buried" [2] (or "late released due to an editor vacation" [3] as it was their explanation) or if they publish it in a timely manner and within the spirit of the submission.

[1] http://slashdot.org/submission/4487045/sourceforge-hijacks-t...

[2] http://www.reddit.com/r/linux/comments/381q6r/slashdot_buryi...

[3] http://tech.slashdot.org/story/15/06/01/1241231/sourceforge-...

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#28

One should sue for trademark violation. I'll chip in if anyone is fundraising.

This is definitely a possibility, and when sourceforge bundles nmap with malware I would deem it nessesary. nmap is protected in the US by trademark #78342532.

Re: Sourceforge Hijacks the Nmap Sourceforge Account

#30

This is the sort of behavior you get from a company that's lost, and is now trying to extract every penny they can from whatever shenanigans they can get away with. If they have no future brand value to be concerned about, then, from a game-theoretic approach, it's actually a pretty rational profit seeking move. (As long as they don't incur any downstream liabilities from outright illegal activity for which they migh…

The problem now is raising the alarm all the way out to the endest of end users, that this formerly trusted site cannot be trusted anymore.

Perhaps Google could step up and de-list them, but that is a pretty slippery slope.

Post reply on HN