Live data from Hacker News

Gem.coop

gem.coop

261–270 of 331 posts

Re: Gem.coop

#261

Earlier quoted context omitted.

Again, link? It's no good just talking about what heinous things someone has done. That kind of talk is always incredibly unreliable.

Evidence for thee, but not for me? You write with such authority on this topic, yet you insist on demanding evidence for even the most basic knowledge surrounding it. https://www.bbc.com/news/articles/cm2njjm4e2po https://xcancel.com/jk_rowling/status/1819007216214573268 https://xcancel.com/jk_rowling/status/1931144695771435140 Also, on another note, here's one of her many posts from JKR literally equating trans wome…

[deleted]

Re: Gem.coop

#262

Earlier quoted context omitted.

Again, link? It's no good just talking about what heinous things someone has done. That kind of talk is always incredibly unreliable.

Evidence for thee, but not for me? You write with such authority on this topic, yet you insist on demanding evidence for even the most basic knowledge surrounding it. https://www.bbc.com/news/articles/cm2njjm4e2po https://xcancel.com/jk_rowling/status/1819007216214573268 https://xcancel.com/jk_rowling/status/1931144695771435140 Also, on another note, here's one of her many posts from JKR literally equating trans wome…

> Also, here's one of her many posts from JKR literally equating trans women with sexual predators.

> https://xcancel.com/jk_rowling/status/1972054407148695732

Consider what this conversation was actually about - a male sexual predator, caught pleasuring himself in the showers attached to a girls' changing room, who claimed, when caught, to have a female gender identity:

https://xcancel.com/KatieDR96/status/1972050074227429663

Re: Gem.coop

#263

Earlier quoted context omitted.

Evidence for thee, but not for me? You write with such authority on this topic, yet you insist on demanding evidence for even the most basic knowledge surrounding it. https://www.bbc.com/news/articles/cm2njjm4e2po https://xcancel.com/jk_rowling/status/1819007216214573268 https://xcancel.com/jk_rowling/status/1931144695771435140 Also, on another note, here's one of her many posts from JKR literally equating trans wome…

> Also, here's one of her many posts from JKR literally equating trans women with sexual predators. > https://xcancel.com/jk_rowling/status/1972054407148695732 Consider what this conversation was actually about - a male sexual predator, caught pleasuring himself in the showers attached to a girls' changing room, who claimed, when caught, to have a female gender identity: https://xcancel.com/KatieDR96/status/197205007…

Setting aside that you're passing claims from a far-right troll as facts, that still doesn’t make it acceptable to equate trans women with sexual predators, both morally and logically. Or are you suggesting that if you can find one male sexual predator, it justifies equating all males with predators? I have a feeling you’d be up in arms about that.

Anyways, it's clear that you're intent on dehumanizing others, even creating a new account for the sole purpose of saying the most vile things, so I'll stop replying here.

Re: Gem.coop

#264
post #94

Earlier quoted context omitted.

>It kind of feels like this fork is the better-maintained piece of software now. Maybe, but I feel the value of the index is the storage and bandwidth and not the software itself, isn't it? Could an index work by just being a search engine for gems, storing the hashes, but pointing to external resources, like GitHub repos, for the download itself?

Trustworthiness is far more important for a package manager. No amount of storage or bandwidth can compensate for an untrustworthy package manager.

Is it? Anybody could publish to Rubygems. Baring obviously malicious packages that happened to get noticed by a researcher, what trust were folks placing in Rubygems?

Re: Gem.coop

#265

Earlier quoted context omitted.

> Also, here's one of her many posts from JKR literally equating trans women with sexual predators. > https://xcancel.com/jk_rowling/status/1972054407148695732 Consider what this conversation was actually about - a male sexual predator, caught pleasuring himself in the showers attached to a girls' changing room, who claimed, when caught, to have a female gender identity: https://xcancel.com/KatieDR96/status/197205007…

Setting aside that you're passing claims from a far-right troll as facts, that still doesn’t make it acceptable to equate trans women with sexual predators, both morally and logically. Or are you suggesting that if you can find one male sexual predator, it justifies equating all males with predators? I have a feeling you’d be up in arms about that. Anyways, it's clear that you're intent on dehumanizing others, even c…

The reason that this male sexual predator was allowed to use the female changing room and showers is because he claimed to have a female gender identity.

This illustrates the safeguarding risk in allowing males to use female spaces on the basis of simply saying that they identify as female. It ends up with situations like this: a registered sex offender pleasuring his erect penis in a shower area that young girls are using, and a reluctance of the authorities to stop him and file charges because they're in the thrall of policy that deems self-declared gender identity to be unquestionable.

> are you suggesting that if you can find one male sexual predator, it justifies equating all males with predators

For the purposes of safeguarding, yes. This is much of the reason why we have female-only spaces in the first place, as a preventative against male predation.

Not all males are predatory, but one can be quite sure that the subset of males who disregard and ignore women's and girls' boundaries are. Including the sex offender being discussed in that Twitter conversation. And any other male who demands access to female spaces.

Re: Gem.coop

#266
post #264

Earlier quoted context omitted.

Trustworthiness is far more important for a package manager. No amount of storage or bandwidth can compensate for an untrustworthy package manager.

Is it? Anybody could publish to Rubygems. Baring obviously malicious packages that happened to get noticed by a researcher, what trust were folks placing in Rubygems?

The package repository going rogue is a significant escalation compared to merely having individual malicious packages that go undetected. You can't possibly argue that those two are the same.

Re: Gem.coop

#267

Earlier quoted context omitted.

It's a package repository. A link to an Ansible repository or whatever doesn't need to be in the first announcement. > This leads me to think this project is not about the code but about the people. Trust is of utmost importance to a package repository. Even more so than code. A hostile takeover, like the one that occurred with RubyGems, fundamentally undermines that trust. In contrast, an alternative run by the orig…

I think the issue that you overlook is that you assume this group of individuals is trustworthy. I'm not saying they aren't, but there are a LOT of conflicting opinions about what happened, why it happened, and who was right/wrong. This it what tends to happen when money gets involved in a project without a clear structure/business plan/guarantees put in place. People just did whatever and made assumptions, and now s…

> I think the issue that you overlook is that you assume this group of individuals is trustworthy.

Of course I do, because the original maintainers earned that trust over the course of years. That's not an issue.

Re: Gem.coop

#268
post #264

Earlier quoted context omitted.

Is it? Anybody could publish to Rubygems. Baring obviously malicious packages that happened to get noticed by a researcher, what trust were folks placing in Rubygems?

The package repository going rogue is a significant escalation compared to merely having individual malicious packages that go undetected. You can't possibly argue that those two are the same.

To put my cards on the table: RubyGems.org seems plenty trustworthy to me. They seem to be shitty at communication, but locking down production access to systems in light of the state of supply chain attacks in 2025 is the kind of thing that reduces the risk of rogue repo-level activity.

But to your comment: I'm not arguing the same, I'm arguing that the results are the same. If I'm consuming packages from a repo, and I care about the security of the thing I'm running, I need to think about how I know I'm getting legitimate code that does what I expect it to do. One of the risks to that is malicious developers at the package level (either outright malicious or stolen publish credentials). Another is malicious substitution by the package repo. The detection strategies and next steps are different but as a consumer of code, bad code is a risk regardless of who injects it.

Re: Gem.coop

#269

Earlier quoted context omitted.

I think a lot of people don't know why being Danish is relevant. Is there some reason why controversial views on immigration might be less suprising coming from a Dane?

Denmark is the rare case of a European nation where its center-left listened to feedback from the electorate early on and earnestly adopted policies restricting immigration and refugee admission. As a result they had no populist backlash, and that policy position is uncontroversial to hold publicly.

Denmark also has significantly lower rates of violence, crime, rapes and more. Sweden sees ~10 times more rapes than Denmark.

As a Norwegian I respect Denmark for putting its people first.

Re: Gem.coop

#270

Earlier quoted context omitted.

What does “fash problem” mean?

That's the part where the term "fascist" is misused to smear somebody they disagree with. It can be safely ignored.

I thought so but didn’t want to assume.

People really like to misuse terms like fascism these days, huh…

Post reply on HN