Yes, a forum of people interested in software development might care that most new repositories created on the most popular website for sharing open source code will end up spoofed and sharing malware?
HN user
joshdotsmith
I like to make things
As I wrote in this issue, I am exhausted. Microsoft has plenty of money to handle issues like this and chooses not to do so. I have spent hours now reaching out to GitHub in vain, tracking down people affected, and trying to figure out how to get someone to give one single flying fuck.
So what the hell. Let’s make the CISO’s slideshow intro to GitHub popular.
Thanks, I just find it wild that Microsoft appears wholly uninterested in policing what seems like a huge legal liability to their business. I’ll start reaching out to as many journalists as I can with what I’ve got. They seem a little overwhelmed from the two I’ve already reached out to.
Edited to add: I’ve also been hoping that I could avoid giving the attackers too much of a heads up, but at this point the risk is higher that nothing gets done about it at all.
SEEKING WORK | REMOTE | Baltimore, MD, US
Product-focused full stack developer with 14 years of experience. Hired on "Seeking freelancer" before – happy to provide the reference!
Work with early stage startups, often seed or pre-Series A. Recent experience in enterprise on various teams at Credit Karma.
Recent work: https://keyhero.io - designed / built everything
--
Skills:
- Ruby / Rails, Elixir / Phoenix, Node.js
- React, Next.js, some Vue + Elm
- React Native / Expo, Swift
- CSS, HTML, Tailwind
- Design, UI, UX, Figma
- Postgres, MySQL, Redis
- AWS, DO, Fly.io, Render
- TDD / BDD
- SaaS + consumer metrics and conversion rate optimization
--
Email: josh@coderly.com
GitHub: https://github.com/joshsmith
Thank you for sharing this! Shared it with my wife over breakfast.
I'm also curious about this. We were accepted into Stripe Atlas but too late – we ended up forming our company while on the waiting list and couldn't partake.
Watsi only funds its operations via tips. 100% of your non-tip donations go to funding treatments.
If your non-profit needs any help with any of the software side (that can be made open source) let me know and I'd be happy to see how I can help.
Looks fantastic. Do you have plans to support additional languages?
This would be particularly useful in open source.
I don't think he understood the question. "For 30" sounds like he meant "$30 per hour" and not "on net 30 terms."
Okay, so I got downvoted for clarifying why the now flagged post said the parent "had the ethics of a soldier." Maybe at least explain why?
I'm sorry, what?
Does this mean you're also hoping to expand into Delaware PBCs, too? Lots of open source projects are considering this approach due to a combination of poor response to open source nonprofits from the IRS and flexibility in figuring out their funding sources. There's only trivial differences to a C Corp in terms of filing.
I'd been planning to reach out to Stripe about this when it made sense; I probably should've just emailed you! We're advising folks we're bringing onto our Stripe Connect platform as managed accounts to go use Stripe Atlas where possible, but plenty have voiced support for having B Corps be part of that happy path.
Honestly, I might even just pay a lawyer at some point to open up some standardized set of docs for this.
Do you hope to have any way for Connect platforms with managed accounts to more directly refer people into Atlas? Having an API for the application process would be amazing.
You can definitely browse projects without signing up.
Code Corps is intended to be a place to find and volunteer for open source projects you think are worth whatever free time you have. For maintainers, we'd like to make scaling your community trivial: acquire and retain volunteers, onboard newcomers, recommend the right tasks to the right people, and fund your operations.
As an aside, I'm kind of curious how others feel they fare on building new projects. Do you feel slow? I worry constantly about how quickly I'm moving relative to peers.
Do you have anything you can share about this? I'm very interested to see and am happy to provide feedback.
Stripe did introduce Stripe Atlas. Although this doesn't solve the situation totally, it's at least one of a number of helpful steps in the right direction.
Does anyone have resources on how one should design their changes to run side-by-side? I have not been at large companies and don't have the advantage of institutional knowledge to help here. Book, articles, and practical examples would be fantastic.
And since it's often hard to generalize, I work today with Elixir and Postgres. Anything specific around this stack would be exceptional.
Do you have anything you can share at all?
Do you mind sending me an email sometime? You can find one in my HN profile. I'm really curious to hear about what you've done to find maintainers and how you've thought about tackling the fundraising issue.
If anyone from LaunchDarkly is reading: any plans to add Elixir?
When doing design work I usually now start with Ryan Singer's shorthand for UI flows: https://signalvnoise.com/posts/1926-a-shorthand-for-designin...
From there I'll dive into hand drawings, perhaps a wireframe (although Balsamiq is a pain to use), and maybe some specific visual designs if needed in Sketch, which may then go into Invision. Basically every step is optional along the way to a fully implemented design, but the general flow can be adapted at length.
This is especially nice when doing client work because clients' needs and budgets are highly variable. If I can get away with just a UI flow and drawings and feel confident that we're on the same page in terms of how they describe the UX back to me, then we're good to go.
The biggest thing is to just get over your own insecurities about scribbling and drawing. I'm awful at it. But when my anxiety or my attention-deficit keeps me from going through the earlier (cheaper) motions, then invariably I suffer in terms of time lost later.
National Voter File (http://www.nationalvoterfile.org)
We’re building the first open source, publicly available national voter database in the United States to power grassroots campaigns, monitor voter suppression, and make door-to-door advocacy possible for anyone.
Monthly Goals:
- Create loaders for new states
- Enhance reliability of existing loaders
- Create Python geocoder to tag households with lat/long
- Develop queries to explore data quality
- Begin work on flash API
Skills needed: PostgreSQL, GIS, Python, Pentaho Data Integration (we can help you learn)
Slack Signup: http://goo.gl/forms/8SJRDlo7Lx2rUsan1
GitHub: https://github.com/getmovement/national-voter-file
Dimensional Data Model: https://docs.google.com/document/d/169mIkiIdl4OetbGvnbVCzq9S...
Information on state voter files to load: http://voterlist.electproject.org/home
Pentaho Data Integration: http://community.pentaho.com/projects/data-integration/
License: MIT
Code Corps (https://www.codecorps.org)
We're helping volunteers and donors contribute to software projects for social good.
Monthly Goals:
- Polish edge cases in Stripe integration for monthly donations
- Redesign task UI
- CSS work to move towards BEM, flex box, greater responsiveness
- Minor features in blog
Skills needed: Elixir, Phoenix, PostgreSQL, JavaScript, Ember.js, HTML, CSS, Sass, WordPress, UI and graphic design (Sketch a plus), dev ops (Docker, AWS)
Slack: http://slack.codecorps.org/
Elixir Phoenix API: https://github.com/code-corps/code-corps-api
Ember front-end: https://github.com/code-corps/code-corps-ember
WordPress blog: https://github.com/code-corps/blog.codecorps.org-site
License: MIT
If you're reading the above comment and nodding your head or even feel the argument is wanting, I highly encourage you to read Postcapitalism by Paul Mason. There's even a chapter entitled "Was Marx Right?" Well worth the read.
https://www.amazon.com/Postcapitalism-Guide-Future-Paul-Maso...
I would also really like to hear stories like this. Was so enthralled by Leo's post I ended up making a template for derisking: https://blog.codecorps.org/lower-your-startup-risk-with-this...
These are learnings that doesn't just flit by me. They're not filler. They profoundly change the way I work precisely because of the depth and detail, along with their actionability. Applied learning is by far what I want to hear.
Also curious about this. For reasons that our team was personally against, we had to devote some serious upfront development work to building an integration with a WordPress backend and the rest of our Ember front-end (which consumed, thankfully, a JSON-API spec backend). We wrote custom adapter and serialization layers for this, which was trivial; the only exceptions to the ease of writing such code was when the WordPress developers would return bizarre status codes or missed root objects or some other such nonsense.
You can check out Code Corps' Ember app as well, and it's MIT licensed: https://github.com/code-corps/code-corps-ember
We also have a Slack where you can ask a large group of us questions about it at any time, or just reach out to me using contact info in my profile.
Those reasons, which surely place some non-negligible burden on the teams involved, do not seem to be so overwhelming as to ultimately dictate that 80% of projects are not made open source.
I'm definitely aware of the difficulties involved in open sourcing significant amounts of your work. The bigger burden is less, in my opinion, about cleaning up your code base. If you're committing potential security vulnerabilities into your code that are then tracked by your version control system – and you're a Federal agency – that's already a problem that's just going to be exacerbated by making it public; making that code private doesn't make the problem disappear.
The real meaty problems that all open source projects share is people: people like me who come in and overwhelm the project with support requests. I just opened four issues tonight just for this website, in the span of several minutes. (Sorry team!) If you already have poor project management practices in place, or your team is too small, this can quickly overload you.
Of course, with a vibrant community around your project, even the social and management problems could become trivial with time. Look at especially great examples like Hoodie. Given the number of technical people who have left cushy, high-paying jobs to serve in 18F, USDS, and the other alphabet agencies of late, I have to imagine the rallying cry to support truly useful code by compassionate people will be significant enough to justify the upfront expense here.
Not only is 20% not perfect, I don't think it's enough. I want 100%, and I think it's a fair request as a taxpayer, even if there is some burden. This country has fought two world wars and gone to the moon. We can always do better.