BountySource have turned evil – alternatives?
diziet.dreamwidth.org
diziet.dreamwidth.org
Sounds like a quick money grab while destroying your brand. Were they recently bought by a hedge fund or something?
https://www.crunchbase.com/organization/canya#section-overvi...
Maybe it's time for a browser extension that just tracks a list of crypto companies and warns you anytime their name appears on a page.
Your own bank has clauses like this btw. I had to fight for my funds in a bank account I hadn't touched in seven years. And I once used a pay-as-you-go phone service that would consume your balance if you went 6 months without depositing.
But two years seems way too aggressive for this sort of project.
There's a pretty simple answer here: return it to the person who posted the bounty. Other options could be letting them donate it (minus standard fees) to the maintainer(s) of the project that their bounty applied to or to an OSS organization.
The choices aren't just "Hold on to it forever" and "Take it for Bountysource." It's on the books as a liability for a reason, namely, it's not Bountysource's money.
(There's also an entire ecosystem for unclaimed property, which is where banks distribute money from customers they can't locate: https://unclaimed.org/)
You can't just steal people's money because it's inconvenient to return it to them.
I'm not saying that what BountySource is doing is justified. In my case I need to just wind down the company because I think it would be unethical to pull this shit.
Thanks, guys, for bringing this to my attention.
An entire legal framework already exists for just this scenario, and it doesn't involve pocketing the money.
Money and other assets are supposed to be relinquished to the state so that owner or intended recipient can collect it.
There is no such recourse in this case so the idea makes perfect sense to me. Two years is the only bit I have an issue with - 5 would be a bit more reasonable.
What they're doing here is just a scummy cash-grab, and I am not sure how legal it is considering it applies retroactively.
https://coscout.com/organization/canya.io
Seems a bit shady if you ask me. Looks like the founder has also moved on (as per linkedin). So yeah, this just looks like a cash grab.
The plot thickens.
Literally just any repercussions at all for being like this would be a nice change of pace.
What we have instead of terrible ideas like this, are laws. Unfortunately these are often designed by the same nonsensemongers mentioned above, but they are the only reasonable recourse.
Good ideas don't start off fully formed. I'm talking about the desire to have a bottom up justice system. The fact that anger is the impetus means there is a lot of potential for a slippery slope, and I cede that.
But the point stands: there are many people who've reaped nothing but benefits from being horrible, and I would gladly pitch a couple bucks to make their life miserable for a while.
Also known as "lynch mob".
Laws are the only reasonable recourse. They may have better access to laws and legal maneuverings, of course.
But you're measuring things incorrectly, I think. You write:
> there are many people who've reaped nothing but benefits from being horrible
Nope. They've reaped what they've sown, and they are horrible people. They might be rich or powerful, but who really cares?
You think they were having a bad time on Epstien's island? You really think they're so unhappy about being horrible?
Your state AG's Web site will have a form for filing a consumer complaint. Here are example links if you live in California or in Washington State:
https://oag.ca.gov/contact/consumer-complaint-against-busine...
https://www.atg.wa.gov/consumer-issues
Save and include a copy of the changed https://www.bountysource.com/terms, which says this: "2.13 Bounty Time-Out. If no Solution is accepted within two years after a Bounty is posted, then the Bounty will be withdrawn and the amount posted for the Bounty will be retained by Bountysource. For Bounties posted before June 30, 2018, the Backer may redeploy their Bounty to a new Issue by contacting support@bountysource.com before July 1, 2020. If the Backer does not redeploy their Bounty by the deadline, the Bounty will be withdrawn and the amount posted for the Bounty will be retained by Bountysource."
What? Do they really want to keep the award money if nobody solves the problem?
Think of Amazon's search: Finding the correct thing you want, sold by your preferred/official merchant is kind of impossible. They can pull the same thing, so the bounties stay unsolved.
I think some central authority not tied down to any single issue tracker or source code repository for bug bounties is still a good idea, but it will never work if the controlling entity is a single for profit organization. Let bountysource die.
If anyone is interested, the campaigns concern GCC and LLVM:
> https://www.bountysource.com/issues/84630749-avr-convert-the...
> https://www.bountysource.com/issues/91495157-vax-convert-the...
> https://www.bountysource.com/issues/90829856-llvm-complete-t...
> https://www.bountysource.com/issues/86138921-rfe-add-a-front...
Is there any actively-maintained FOSS bounty platform without the GitHub dependency?
Reasons such as?
our bounties platform is coupled to github, but grants/tips/other tools are not.
we plan to decouple from github eventually. until then, the workaround is to post a gitlab repo into a github issue and bounty that.
any other questions lmk
But plain fraud where you steal money (or tips) or impersonate other businesses? I don't think anyone is going to be happy with that.
Hi You're receiving this because we updated our Terms of Service.
Withdrawal of new Terms of Service Yesterday, we communicated a change to the Bountysource Terms of Service (ToS) agreement. These changes have been withdrawn and the ToS reverted to its prior state. The ToS will be revised and clarified in the future.
Thankyou
Bountysource Team support@bountysource.com
more on us: https://gitcoin.co/mission https://gitcoin.co/results
[1] https://github.com/jollheef/donate
[2] https://opencollective.com/
[3] https://github.com/opencollective
[4] https://docs.opencollective.com/help/collectives/github-spon...
https://github.com/fossjobs/fossjobs/wiki/resources#bounties
I guess FreedomSponsors still works (didn't try it in years), but active development stopped in 2017/2018 and communication stopped in 2015. I liked it and used it to fund some small fixes back in the day.
Thanks in advance.
Not sure what the motive would be though.
I would imagine that it is the money.
A non-evil motive would be that for accounting reasons that has to be kept on the books as a liability, and it's not nice to keep liabilities around indefinitely. There are lots of situations where this is the case, but where "just keep the money" is actually accepted practice. Gift cards, for instance. Also, I've seen IT support contracts where you purchase a certain number of "hours" that you spend on logged work; and those hours expire if you don't use them within 2 years.
But obviously this is completely different, since in the above two cases, you as the consumer have control over when the spend happens; you have no way of knowing if or when anyone is going to fulfill your bounty.
I have to imagine the amount of money they're looking at collecting here in the >2 year old bucket is large enough that they're willing to take the PR hit. There's probably a good chunk of change there held by now-inactive users who they're hoping won't actually do anything about the change like redirecting their funds.
It's also really sad because the open source project I contribute to is six years old, and had a couple year quiet period, but is often tackling multi-year old issues now. In our case, we don't use BountySource, but had we, we'd be looking at losing funding that we were still very much intending to earn.
Or it could be exactly the opposite bucket: any bounties less than 2 years old are still subject to expiration, but they're not allowing you to redirect them when they expire.