Live data from Hacker News

Open source ‘protestware’ harms Open Source

opensource.org

541–550 of 575 posts

Re: Open source ‘protestware’ harms Open Source

#541
post #197

But on the other hand, these people are not promising anything, do they? Check the MIT/BSD/GPL etc, all of them explicitly state that the software does _not_ come with any kind of guarantee. Harsh reality is: It's user's responsibility to test for those. Noone is forcing you to use this piece of code which is given as-is without any guarantees. Noone is forcing you to update. It might be a dependency, but still it's…

They are not. And there would be absolutely nothing wrong with them no longer maintaining the package, deleting it, or with the package not working.

The issue here is spreading actual malware. A developer doesn't owe anything to anyone.

But actually and actively harming others trough actual malware is unethical even if someone didn't promise they wouldn't do so.

If I give someone a piece of food that I expressly don't guarantee anything about, the worse one would assume is that it might be spoiled and I didn't check, or that the ingredients may be of very law quality. Not that I actually purposefully poisoned it.

Re: Open source ‘protestware’ harms Open Source

#543
post #495

Earlier quoted context omitted.

You’re at war. Maybe you don’t realize it because you can still go on with your life as if nothing was happening. It’s not a trendy thing, it won’t go away because of some random trendy thing. HNers annoyance couldn’t be more irrelevant. And people are still getting killed because the world has decided that this war , as bad as it is, shouldn’t interfere with business too much. People are still getting killed because…

So will plastering banners all over the internet end the war? How is it raising awareness exactly? And why aren't we raising awareness about thousands of other political, social and economic issues around the world that actually need awareness, rather than pretending to do so about the most popular issue of the day? Politics doesn't belong in software. Some software can be political, sure, but the only purpose of the…

> why aren't we raising awareness about thousands of other political, social and economic issues around the world that actually need awareness

Our lives are going to change. Depending on how concerned and committed western people will be, we'll have to face a major energy crisis, or give up our democracies for cheap oil & gas. If trump is re elected, I see nothing good coming for the west. We are living crucial times, fascism is back in full force, our medias and politicians are being bought one by one with dirty russian money. And fascists don't feel the need to hide anymore.

But people fail to see why this war isn't yet another political, social or economical "issue". I looks like we're in for a very dark age...

Re: Open source ‘protestware’ harms Open Source

#544
post #450

Earlier quoted context omitted.

What next? Is refusing doing business with Russia a war crime, too? After all, some civilians might lose their livelihoods and starve to death, right?

There's an obvious difference between trying to hurt people and not trading with them yourself. If the distinction is difficult, there are laws to define this 'war crime' thing, you may wish to consult them. Also, Russia is relatively self-sufficient foodwise. There'll be shortages but no starvation. I'm sure though that if starvation was serious possiblity the West would exclude food imports.

You might wish to consult those laws yourself before you call random shit a war crime...

Re: Open source ‘protestware’ harms Open Source

#545

Earlier quoted context omitted.

You’re at war. Maybe you don’t realize it because you can still go on with your life as if nothing was happening. It’s not a trendy thing, it won’t go away because of some random trendy thing. HNers annoyance couldn’t be more irrelevant. And people are still getting killed because the world has decided that this war , as bad as it is, shouldn’t interfere with business too much. People are still getting killed because…

Are we still talking about BLM? Because I regret to inform you it has already gone away. The city where I lived published their provisional crimes stats for 2021 and it looks like murder rates have gone up. Most of that is gang related and black on black. Not only has the city not “defunded” the police department they’re looking to purchase what can only be described as a tank from a Homeland Security grant. There ar…

Maybe it didn't help much, and so what? Are you saying we shouldn't even try?

Re: Open source ‘protestware’ harms Open Source

#546

Earlier quoted context omitted.

From the point of view of American isolationists, there is no difference. There is a difference for Europeans, in that Ukraine being engulfed by a full scale war will result in around 40M refugees in the EU, almost 10% of EU population. That's an order of magnitude bigger than the previous migration wave. It's also an order of magnitude faster. Over 10M people have been displaced already. Some numbers: https://en.wik…

I think you are reversing causality here. No doubt the EU could have seen similar numbers of refugees from Syria and Iraq and Afghanistan, had they allowed them in.

Before the current crisis, there were >1M Ukrainian workers in Poland, hundreds of thousands in Slovakia, Czechia, etc. The world where Polish, Slovak or Baltic people watch dying Ukrainians through their border fences was never going to exist. The possibility only ever existed in the minds of some confused Americans and maybe western Europeans. German policy in the previous refugee crisis (especially with regard to non-Syrian migrants) literally made the present course the only possible one -- something along the lines of "If we are letting random Africans in, how can we not let the Ukrainians in." is hard to argue with.

On the other hand, accepting even less refugees in the previous crisis is something that was definitely (politically) possible at the time.

Re: Open source ‘protestware’ harms Open Source

#547

Earlier quoted context omitted.

you can't really escape politics and ideology. What you can do, is to not be petty with your public contributions. As the parent example states, while somebody /could/ embed malware into their software that targets Texans, this falls under the pre-existing social doctrine of a "dick move". These things exist on a scale from "exclude government/corporate entities from your software license" to "try to fuck up random p…

I think the main problem is that we are increasingly operating with different definitions of "dick move." To many people, the idea that a small business owner would have their store burned to the ground because someone else in their town (or on the other side of their country) did something bad, is a massive dick move. Yet, this happened numerous times during the summer of BLM in 2020 and it was widely defended with…

If anybody is defending burning down small businesses as part of BLM, I can promise you they're in the vast minority.

Re: Open source ‘protestware’ harms Open Source

#548

Earlier quoted context omitted.

> It harms all of technology and by extension anyone who participates in the modern world. Just like any malware or other antisocial behaviour. Sure but the problems are in order of significance are: Putin invading Ukraine Trusting things from NPM This author adding malware to his package I'm disappointed by the chorus of "keep politics out of tech" that seems so prevalent on HN, though not surprised. In general I'm…

> but when things are this completely broken I think anything goes Why? If something doesn't help in any way, it shouldn't "go". Putin's invasion of Urkaine doesn't justify doing other bad things, just because those bad things aren't quite as evil. Something can be wrong without it beying literally invading another country. Putting malware in software is an example of that. > but often times the vibe of that one poem…

> Putin's invasion of Urkaine doesn't justify doing other bad things

Yes it absolutely does. Killing is bad, killing invaders in defense of your country is justified. Collapsing Russia's economy is bad, but in light of Putin's actions it's justified. Putting malware in your packages is an extension of that concept.

It's unclear to me whether putting malware in your packages is effective, but it's certainly worth trying, and I absolutely can't condemn someone for that. If you wield power you are responsible for it's effects, and to some lesser extent you are responsible for the effects of your inaction.

Re: Open source ‘protestware’ harms Open Source

#549
post #197

But on the other hand, these people are not promising anything, do they? Check the MIT/BSD/GPL etc, all of them explicitly state that the software does _not_ come with any kind of guarantee. Harsh reality is: It's user's responsibility to test for those. Noone is forcing you to use this piece of code which is given as-is without any guarantees. Noone is forcing you to update. It might be a dependency, but still it's…

They are not. And there would be absolutely nothing wrong with them no longer maintaining the package, deleting it, or with the package not working. The issue here is spreading actual malware. A developer doesn't owe anything to anyone. But actually and actively harming others trough actual malware is unethical even if someone didn't promise they wouldn't do so. If I give someone a piece of food that I expressly don'…

I don't know. Going from same example, if you give me food with a note on it saying "I don't be liable for anything, I am not giving any guarantees. And if you'd like to give this food to someone else, you must give a copy of this note too.", poison possibility is not off the table.

Anyway, I understand the frustration of people who got broken tests, but just noting the different angle.

Re: Open source ‘protestware’ harms Open Source

#550
post #197

But on the other hand, these people are not promising anything, do they? Check the MIT/BSD/GPL etc, all of them explicitly state that the software does _not_ come with any kind of guarantee. Harsh reality is: It's user's responsibility to test for those. Noone is forcing you to use this piece of code which is given as-is without any guarantees. Noone is forcing you to update. It might be a dependency, but still it's…

I think what you're missing is that this discussion is not about the legal consequences of these individuals, but about ethical decisions that will have a negative impact on the ecosystem as a whole.

Tbh I don't see an ecosystem here, there are some dots which are connected but seems like people are thinking there is a liable vendor polishing npm packages..

Also I'm not sure which one is more unethical: Malware from a random developer or profiting over his/her "free code" * by not giving any care about open source or sustainability of it at all.

* (in the view of big corp)

Post reply on HN