Live data from Hacker News

A cautionary tale about software dependencies during major geopolitical events

blog.benjaminvr.net

1–10 of 41 posts

Re: A cautionary tale about software dependencies during major geopolitical events

#2
>> The founder & lead developer is Russian and does not accept donations, perhaps noble, perhaps to avoid a financial trail.

In modern Russia, if one receives money transfer from any other country, they may receive "Foreign Agent" (иностранный агент) status

https://en.wikipedia.org/wiki/Foreign_agent

"prohibited from receiving state funding, teaching at state universities, or working with children"

Re: A cautionary tale about software dependencies during major geopolitical events

#3
I don't really see how this has anything to do with major geopolitical events, other than the fact that the developer of the library is Russian. The author's complaints could have happened with any open source library and don't seem to relate to the war in Ukraine in any way.

Re: A cautionary tale about software dependencies during major geopolitical events

#4
post #3

I don't really see how this has anything to do with major geopolitical events, other than the fact that the developer of the library is Russian. The author's complaints could have happened with any open source library and don't seem to relate to the war in Ukraine in any way.

I read the article and got the same impression. It had no conclusion on global event affecting dependencies. More speculations rather than facts.

Re: A cautionary tale about software dependencies during major geopolitical events

#5
Is the author's implication that the developer took the project in a different direction because of the war? I don't understand what the connection is between "major geopolitical events" and the library. It's just a graph that shows that a year after the war started, the developer removed a feature the author liked.

Re: A cautionary tale about software dependencies during major geopolitical events

#6
I've had to reread, I was certain I missed something. But no, this is entirely conspiratorial speculation without any basis _or_ even without any point?

If at least they explicitly put forward a theory like "it's russian influence to slow down western digital development" it would have some internal consistency, but no. They suppose it's russian influence (again, without basis) without any theory of _why_ Russia would care about an inconsequential CSS-related lib. Shrug.

Re: A cautionary tale about software dependencies during major geopolitical events

#7
post #4
post #3

I don't really see how this has anything to do with major geopolitical events, other than the fact that the developer of the library is Russian. The author's complaints could have happened with any open source library and don't seem to relate to the war in Ukraine in any way.

I read the article and got the same impression. It had no conclusion on global event affecting dependencies. More speculations rather than facts.

Thanks for your comments. I have to admit that it is shallow - going in more detail would risk identification of the people involved and paint a target on my back.

I do realize that he may have simply changed his opinion - yet it is the most controversial one and he stood by it ideologically as expressed numerous times through a variety of mediums.

It's a bit tinfoil hat, but I am disappointed and there's no harm in informing others about these observations and this experience. Mind you - and that's about all I'll add - that the repository stagnated in development for some time, increasing my senses about something being off considerably (browser extension ownership for example get bought frequently by criminals to convert a user base into a cash cow, or worse)

Disclaimer at the end of the article: If I am totally misinterpreting my observations and the Discord hostility without even an attempt at producing counter-arguments or productive and professional openness and communication, at least it serves as a cautionary tale of what could be. In any case, no disrespect or attempt to taint anyone's (opensource) software development ventures and/or their personality is intended. The name of the project or its developers will not be shared, if you can find it, be discrete or this article will be removed. Thank you.

Thanks for your time. Have a great weekend.

Re: A cautionary tale about software dependencies during major geopolitical events

#8
post #5

Is the author's implication that the developer took the project in a different direction because of the war? I don't understand what the connection is between "major geopolitical events" and the library. It's just a graph that shows that a year after the war started, the developer removed a feature the author liked.

It's more than just this - I wouldn't write a "conspiratorial article" out of nothing, but alas I can not provide depth without risking identification of the people involved and painting a target on my back.

I am watching the advisories for the dependencies closely. Please check my other comment as well.

Thank you, have a great weekend.

Re: A cautionary tale about software dependencies during major geopolitical events

#9
I'm not sure the article really makes the point, but in my experience the war has complicated remote work.

I'm tangentially aware of at least one US company that was outsourcing work to Russian and Ukrainian coders. Apart from the obvious "team" dynamics collapsing, it's not even possible (legal) to pay Russians at this point if you are a US company.

I'm also aware that the narrative inside Russia as to the cause of the war is very different to the narrative I hear. Naturally I believe the narrative I hear as do they.

In this global work-space, who you hire and where they live can become material quickly.

Re: A cautionary tale about software dependencies during major geopolitical events

#10
post #3

I don't really see how this has anything to do with major geopolitical events, other than the fact that the developer of the library is Russian. The author's complaints could have happened with any open source library and don't seem to relate to the war in Ukraine in any way.

To give a more realistic answer to this question, when I was writing an article about npm dependencies[1], I incidentally came upon a case where the developer of node-ipc released a malicious version of the package that affected computers in Russian and Belarusian IPs specifically in response to the Ukraine war[2].

[1]: https://www.preethamrn.com/posts/who-actually-uses-is-odd

[2]: https://www.bleepingcomputer.com/news/security/big-sabotage-...

Post reply on HN