Live data from Hacker News

We will ban you and ridicule you in public if you waste our time on crap reports

curl.se

451–460 of 653 posts

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#451

Long time ago Sourceforge and then GitHub promoted into the current default the model of open source distribution which is not sustainable and I doubt it is something that the founding fathers of Free Software/Open Source had in mind. Open source licenses are about freedom of using and modifying software. The movement grew out of frustration that commercial software cannot be freely improved and fixed by the user to…

> has nothing to do with open source I partially disagree. It does have to do with open source: Github (et al) are about creating a community around an open source project. It's hard to get adoption without a community; it gives you valid bug reports, use cases you didn't think of, and patches. You can, if you want, turn off PRs, issues, and literally any feedback from the outside world. But most people don't want th…

> You can, if you want, turn off PRs, issues, and literally any feedback from the outside world. But most people don't want that.

Just a note, you actually can't turn off PR's on Github repos. At least not permanently.

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#452

Earlier quoted context omitted.

> Which of course is a lot less polite and causes a lot of friction. Most cultures have this, but it goes mostly unnoticed from the inside because one can read between the lines. "How are you?" can be asked just to be polite, and can cause friction when answered truthfully (rather than just politely, as the cultural dance requires). An Eastern European may not appreciate the insincerity of such a question.

Great example. I work in a radiology practice and greet patients regularly. 99% of them say the are good/great etc. It’s quite a striking response when they are limping, bandaged and on crutches.

These days I do a 'eh' and shrug when someone asks a random 'how are you'?

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#453
post #364

I wonder if there is a way to blanket prevent these types of problems. Possible solutions I can think of: - Require an account with a paid service. Fix = require money - Require an account verified with real ID/passport etc. Fix = link to real person - Automated reply system to "waste tokens" if it is an AI that is responding. Fix is increased cost of spammer. - Have some kind of "vetting system" where you get on an…

I've thought about this some and there are benefits and detractions in the processes.

First requiring a deposit system. This might work in the sense that someone dedicated can put down $5 and report a bug, and even if it's not a bug but their work is legitimate they get refunded at the end of the process.

- This doesn't scale well globally as $5 is nothing to me, but significant to someone that lives in a place almost no one in the US can pronounce correctly.

- Once you become trusted you no longer need a deposit.

- Most people what would submit a single, real, bug won't do this and you lose this information.

- How is management of this deposit system paid for? How is fraud dealt with?

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#454
post #415

Earlier quoted context omitted.

> Good Indian devs out of college make atleast 30k USD. Good senior devs make atleast 50k. 1. How can you be a good dev if you've never developed professionally in your life? 2. I know Indian numbers and this is complete bs. Like complete. Maybe there are extremely rare exceptions to it, but this is like claiming that good US devs out of college make 350k. That's beyond rare, may happen, but it's beyond rare.

1. "out of college". I'm sure you can figure out how to interview new grads and identify good devs. 2. They are not. FAANG in India pays higher than what I quoted. My senior numbers are especially on the lower end of the spectrum. If your numbers are lower then you aren't working with good devs. These are the numbers for good devs. The ones who get into great startups/companies. 95% make less and it shows in the qual…

No you can't. Because the real difficulty is not bullshit leetcode questions, but professionalism, ability to handle pressure, requirements collection and research, soft skills, design, etc. you can't interview for those.

You build these skills by writing good software under constraints not by building personal pet projects and farming leetcode.

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#455

Earlier quoted context omitted.

> Which of course is a lot less polite and causes a lot of friction. Most cultures have this, but it goes mostly unnoticed from the inside because one can read between the lines. "How are you?" can be asked just to be polite, and can cause friction when answered truthfully (rather than just politely, as the cultural dance requires). An Eastern European may not appreciate the insincerity of such a question.

Great example. I work in a radiology practice and greet patients regularly. 99% of them say the are good/great etc. It’s quite a striking response when they are limping, bandaged and on crutches.

I’ve always interpreted that question to mean emotionally. Yes, clearly I’m physically injured, but I still have a positive outlook.

When I do hear people respond in the negative it tends to be an opening up about stress.

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#456

Earlier quoted context omitted.

Indian here (~15+ years in tech). I've seen this behavior a lot, and unfortunately, I did some of this myself earlier in my career. Based on my own experience, here are a few reasons (could be a lot more): 1. Unlike most developed countries, in India (and many other develping countries), people in authority are expected to be respected unconditinally(almost). Questioning a manager, teacher, or senior is often seen as…

Alternatively you could hire people from cultures where this crap doesn’t fly.

But that might cost more money! Trust me they'll be able to continue the work while you sleep!

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#457

Earlier quoted context omitted.

[flagged]

> (...) that's a you thing. You have to be tougher than that. They really don't, lol If a community is full of assholes, unwilling to change, walk away! Don't contribute to what you don't want to support. It's just like voting with your wallet. All contingent on whether you can actually afford to do so though, as usual, but I have a hard time believing that interacting on Reddit would be so essential, especially thes…

Yes! Walk away. You don't have to delete your entire reddit account.

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#458
post #33

Earlier quoted context omitted.

Money for a report and a patch, with convincing test cases, might be worthwhile. Even if a machine generates them.

I've read this idea that we could make people pay for security reports a few times here on HN (and you get back the money if the report is deemed good). That feels very wrong. If I find a security issue, I'm willing to responsibly disclose it, but if you make me pay, I don't think I will bother. Punishing bad behavior to disincentivize it seems more sensible.

I get what you're saying, but I don't think punishing bad behavior is practical here. It's like a "enumerating badness" problem - there's way more bad actors with nothing to lose and not much practical way to punish them. There's too many of them and they all have no reputation to damage.

Not saying I have a better solution, just that it's a hard problem. Maybe dissuading some good people who have genuine security issues but don't feel like paying just has to be a cost of doing business.

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#459

Earlier quoted context omitted.

That is sad, sorry to hear it. But at the same time, sometimes you have to really persevere to get a bug fixed. Consider the perspective of the maintainer of a popular project: to them, you're one person in a big queue of people all reporting problems. Most issues turn out to be "I need free technical support, which you don't offer, so I'll phrase it in the form of a bug", and it saps their time to look into the deta…

[flagged]

You're also free to not use their free software.

You're paying exactly $0 for support for this software. So any support (eg: bug fixes) you get are a gift. That means that if you (1) use their software, (2) don't provide a good bug reports to help them fix their bugs, and (3) complain about how it's not your job to fix them then... you, my dear person, are acting like an entitled ass.

It's not hand-holding to provide a good bug report, it's essential to make the bug report actionable. curl is so widely-used that bugs often come from a combination of the software and the environment (OS, libraries, etc). Without enough details to reproduce a bug, then the bug is often impossible to track down. This means: recreate the environment, the actions that led to the bug, and create the bug itself.

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#460

Nice. But it deters people like me who aren't totally confident in sending reports, trading false positives for false negatives

> it deters people like me who aren't totally confident in sending reports This is by design, you shouldn't be submitting reports on anything less than certainty. It's not the maintainers responsibility to prove out your idea. It's yours, and when you're sure, reproduceable, and documented it, then you can submit it.

The real problem here is that this is now the only way the maintainer/reporter can reasonably work.

Proving out a security vulnerability from beginning to end is often very difficult for someone who isn't a domain expert or hasn't seen the code. Many times I've been reasonably confident that an issue was exploitable but unable to prove it, and a 10s interaction with the maintainer was enough to uncover something serious.

Exhausting these report channels is making this unfeasible. But the number of issues that will go undetected, that would have been detected with minimal collaboration between the reporter and the maintainer, is going to be high.

Post reply on HN