Not everyone has an email address associated with their account, or want one.
Anyway, since such requests are apparently ignored here, my password is "bluewave".
Have fun.
HN user
Not everyone has an email address associated with their account, or want one.
Anyway, since such requests are apparently ignored here, my password is "bluewave".
Have fun.
Indeed, it's common nowadays to label things (ideas, people, etc.) in order to frame them in a way that's convenient to the labeler and helps him advance his agenda. I think given the global situation, some people become more sensitive to this kind of tactic (which is often used), while others have shown just how susceptible they are to it.
The author of the software didn't attack anything. He just pushed some code into a place he had legitimate control of.
Some irresponsible (see what I did?) developers downloaded and executed this code without checking, and as a result their stuff broke.
So you're saying he also had to document his code? Maybe make a pull request.
Every developer is responsible for what goes into his project, including dependencies. When a developer wants to update a dependency, he is responsible for the appropriateness of the update. In order to get an idea, he should audit the changes. For personal code, such an audit may constitute of a quick skim to determine that nothing breaks. For production code, it may also include a security audit.
When a dependency that used to do X now does Y and therefore breaks your stuff, you are the one responsible for dealing with it. The author disclaimed any warranty and any fitness of purpose for his project, and whether his intentions make sense or not is of no consequence.
My point was that there is no such thing as "malicious code". Code is code, and it's your responsibility to determine whether it fits the context. That someone put it out there with an MIT license means the responsibility is yours.
P.S. Ata nishma bachur magniv, lama macharta et ha'autobus? OK, ro'e she'ata gar be-Sverige achshav (Scandinavia ze ha'chalom sheli) az mevin.
Intent doesn't matter. The only person who cares about intent is the agent who acts.
The repository contains the console.log code, but you, as a user, would have to knowingly download it and run it. It's not like pushing code into a repository tricks you into running the code.
Trying to "win" by labeling something as "whataboutism" is just idiotism.
Yeah, I was a GitHub user in 2008. Though it obviously had a social aspect, it wasn't considered a "social network" type of site. Its ongoing transformation into one is a result of the acquisition by Microsoft.
I take it you've never read a virus magazine like, say, 40Hex or 29A?
What is "malicious code" anyway? Maybe Microsoft Windows is malicious. It does contain code to format your disk.
You are saying "scary", but I think "alarming" is more appropriate.
It's an alarm that should be buzzing through sleepy programmer skulls. It should alert them to the fact that it's no longer the small company that respected programmers, where you felt your account was yours, and your repositories were yours.
The rules have changed with that acquisition, and Microsoft exploited the good reputation of that small company and the inertia of its users. Step by step, the site became more "social", and started suffering from the usual issues. Step by step, we see the same bigco policies that treat users as worker ants. When an ant starts making up a mind of its own, queen ant sends some soldier ants to cannibalize it.
Now, I realize here on HN the tired old rants of Moxie are considered gold. But if you want to skip being treated like an ant, run your own server, maybe support upcoming federation protocols to kill this centralization and bring down the nest, or at least migrate to some place that respects its users in the meantime.
This sounds good, but what about discoverability?
There should probably be a way to merge project lists on various forges into a potentially huge index that can be browsed and searched, independently of each particular forge. Maybe it already exists?
1. thaumasiotes is __________.
2. everyone likes being __________, but...
3. ... not everyone likes criticism, even when it's __________.
4. therefore, often HN comments are downvoted despite being __________.
ICANN is a fat American corporate body.
At some point ISLANNDs (Internet Small Local Authority for Name and Number Designations) could override it. That way, you could link to http://google.lol/posts/39-put-google-in-the-can and your cohort will enjoy this and the rest of those posts making fun of google, while the rest of the world is disappointed over dead links.
It doesn't mean everyone is making a request to a website every minute. I use http://gwene.org/ for example. To me RSS or Atom are a major success, as the blogs I want to read almost always seem to have them. Those that don't, well, I used to scrape, but after a while stopped and forgotten about them.
If gwene goes under, it'll suck but I'll have a gwene like on my own server. If RSS goes under, it'll go under here and there, and not wholesale. Good technology is resilient like that.
Solutions involving companies paying directly to the people whose code they use miss the point.
The reason is that software shared with the world is often shared out of passion and idealism. If only code that's useful to some companies is paid for, the world of free (as in beer or otherwise) software as we know and love is still unsustainable, and not just because fledgling projects tend to be inferior in many ways to everything that came before.
Some software is written simply for the fun of it. Future Crew were kids writing demos and putting them out (by the way, an executable for a program that's written in assembly is not so far removed from its source code; so whether they put out the source code or not is immaterial, here the point is "free as in beer"). These demos were unlikely to be directly useful to companies, but we were still amazed by them and some of us got into programming because of them. Do you want to live in a world where only people who produce software that's useful to some company can sustain themselves?
Their parents provided them with food and shelter, so they didn't have to think too hard about writing and releasing it. People in this thread claim that they don't feel exploited, probably for similar reasons. They probably have an income or enough money to make them feel comfortable giving something away. What happens when circumstances don't go your way, though? Then, while you live off your savings, see them shrink day by day, you realize that society doesn't give you the basic stuff that's needed for living, so why the hell should you give anything away? If you already gave stuff away while you were fat and healthy, and this stuff is being used profitably by others, the resentment can only grow.
I could've predicted that. Maybe because I am living in the future (without manipulation).
I clicked "Yes" and it does nothing. Maybe because I have JavaScript disabled.
Maybe businesses should pay a tax that goes into paying a respectable universal basic income.
That would make it easier to develop and maintain such software, and it would make it easier for people doing other things besides software development (yes, they exist) to open up their artware without starving.
Then there wouldn't be a need for the insane "professional" formalism described in this blog post.
You can also write useful software without getting paid. Simply don't share it. Indeed, that's one way to spend your time when you're not seeking employment.
This is very cool stuff, thanks!
Yes, I know. I thought about it after I posted. I wanted to emphasize that "web" can be a small part of Internet use, so a browser's importance is placed in a wider perspective. The rest of my comment talks about its importance within that niche, though.
The article says that if you care about the web, you should care about Firefox. I disagree, because my "web" is probably not Batsov's "web". What is "the web" for me? Well, I'd say it's IRC, torrents, mailing lists, git repositories, oh and mostly-textual websites. I use Firefox for the latter, but for most of them I wouldn't mind using emacs-w3m instead. Unfortunately GitHub turned into a shitty JavaScript Web App, and many people still use it so I need to interact with it at times. So yeah, I care about having a Firefox version that can work with it. It doesn't need to be updated every week with the latest user-hostile interface changes. It doesn't need endless security updates, because JavaScript is disabled by default. I don't care about Firefox qua product anymore, because it too turned into a piece of trash long ago. I definitely don't care about the Mozillas. The only reason I still use it is that some mostly-textual websites are too shitty to run in a basic browser like emacs-w3m.
Sounds like a new Soviet Union.
You told sushsjsuauahab that he/she is a small minority of people. I'm sure that makes sushsjsuauahab and others who have their own (gasp) reasons not to get the vaccine feel better... See, it's this one-size-fits-all dictum backed by sanctions that's the problem. The vaccines help prevent sickness, but government policies hurt healthy people.
You can't outlaw math, but you can make outlaws of people learning, using, or teaching math. You are saying the Clipper chip "didn't work", and that's true, but it wasn't "last time". Since then, many attempts were made and many did succeed, and we have Snowden and other whistleblowers to remind us of that fact. So you can downplay this current attempt all you want, but some people don't want their chocolate cookie recipes exposed to everyone just yet (maybe just in the Netherlands).
https://en.wikipedia.org/wiki/Erik_Erikson#Erikson's_theory_...
Welcome to stage 7. (Don't mind the age ranges, which shift with time and place.)
It's not just science, but also technology and other areas of research. Bigco throws money at some technological choices (think programming languages, or methods of machine learning, or fields like distributed computing, cryptography), and academia follows to dance at that pole. As a result, research becomes synonymous with advancing current industry choices, and all alternatives become obscure, even undignified.
Right, though I'm not sure it's easy to infer an ordinary function's return type from this kind of declaration.
Speaking of return types, do you have any idea if any implementation takes a generic function's return type declaration seriously? I believe SBCL currently doesn't, which is unfortunate (defmethods keep clobbering the ftype declaration).
If you want to declare that the function takes a fixnum and returns a fixnum, you can use a function type declaration:
(declaim (ftype (function (fixnum) (values fixnum &optional)) foo))
Of course, if you pass a fixnum and the result cannot actually be stored in a fixnum, that's no good. So you need to either handle that case or not make such a declaration.Thanks.
Since then, the npm security team has removed all the compromised coa and rc versions to prevent developers from accidentally infecting themselves.
Removing all trace of evidence is not something "security teams" should do. Instead of sweeping security incidents under the rug (where twitterverse resides), they should at least mention the existence of these versions and that they contain malware on the package page.
Is the advisory genuine?
It links to the github repo, where the latest commit is from 2018 for version 1.2.8.
It links to npmjs page, that shows 48 versions, where the latest version is 1.2.8 from "3 years ago".
Yet it has 1.2.9/1.3.9/2.3.9 for "Affected versions".
Did npmjs "revert" these versions and any clue of their existence? The npmjs page links to dominictarr's repository. The npmjs site doesn't seem to have a "who owns this package name" besides the repository/homepage links. Very confusing.
I remember some years ago there was some story involving the original author's handing maintainership rights to some shady dude. Is it about that time, or is it about something more current?
BitTorrent existed since 2001. Get on with the times.