Faker.js is now a community controlled project
fakerjs.dev
fakerjs.dev
I understand the decision for npm to take ownership of his packages, because npm is a community package repository owned by, and for, the community. All community package repositories have some sort of policy for package takeovers.
But GitHub claims to be your home for public hosting of your own personal code. What GitHub policy did he violate? The really outrageous thing is that the developer going "rogue" was actually him expressing his freedom of speech, again on his own personal GitHub account, in his own personal (not organization) repositories. He spoke about his thoughts about open source, businesses, and economics. Defending this type of political speech is especially important and GitHub banning his account and censoring this type of speech(whether you agree with it or not) is especially shameful.
He's not banned: https://github.com/Marak
You have to keep in mind that his changes were basically indistinguishable from a security breach of his account. Nobody really sabotages their own repos in a malicious manner like this. Suspending his account while they investigated doesn't seem like a stretch.
> This was his own corner of the internet for him to publish his own personal projects.
Which he's still free to do. But the actions in question had nothing to do with his "personal projects". It was specifically about his actions to intentionally break popular Node.js packages and do so with a version number that would disguise the change as a non-breaking update. It was a malicious act, and there's no way to paint it as anything else.
If DHH decided that Rails was contributing more harm to the world then good, and tried to remove it from GitHub, would GitHub lock his account and restore his repos "on behalf of the community", to side with the smooth operation of the open source ecosystem over a user's personal decisions? To what extent has GitHub decided that they "know best" for the open source community?
Github first responsibility comes to the community of users it supports, then to any individual user. Free speech/ personal choice / Freedom of expression come secondary to the welfare of its users.
Is it a slippery slope ? Yes, but Github does not have a choice if it cared about the interest its community
I'm not sure why it matters they are Github users. The packages were hosted on npm through Cloudflare - does that allow Cloudflare to take over the packages too? And NS1 since they host the fakerjs domain?
At no point down the road should that involve revoking someone's ownership of a software project, though. Software ownership is sacred, not just because of tradition but because understanding who owns your packages and libraries is paramount to auditing security. Some of the most valuable contributions to computer science have been ones that allow people to verify integrity, be it SHA, TLS or GPG. If Microsoft abuses their position of power to break that chain of integrity, how can we be sure that other repos belong to their respective authors?
I can understand if you, the individual don't find this interesting or consider it inconsequential to your workflow. But other people rely on it, and you can't pretend like an honest chain of custody is somehow valueless.
No one took away his ownership.
Marak:
https://github.com/marak/Faker.js/
https://www.npmjs.com/package/faker
Post:
https://github.com/faker-js/faker
https://www.npmjs.com/package/@faker-js/faker
Faker.js is not a trademarked term, so someone made a new Faker.js.
In fact multiple people did, and one emerged as the preferred fork: https://twitter.com/faker_js/status/1481918305669627905
-
And to be clear, even if NPM goes and replaces his package with this new fork, it wouldn't take away his ownership.
Github could do the same... doesn't take away his ownership.
His ownership of a Github page is not his ownership of the code.
I don't like this rules-lawyering stuff either, yet this is one time where even if you decide to be purposely inflexible with your understanding of laws/licensing/contracts etc... there's still no issue with how this has been handled.
actually, marak has github pro, so it is not a free account
There's a huge difference between displaying a message and going in an endless loop and backdooring as in providing an alternative access to control a system you're not supposed to have access to. Words have meaning. This wasn't a backdoor.
Everyone else should have been responsibly consuming the dependency. You don't get to call foul when you knowingly use something for something important and don't check to make sure it is okay.
Even if you're trying to keep things rolling forward and buy into taking in updates anyway; you don't do it in such a way as to cause it to leak to production until you are good and certain there is no potential for breakage. If you haven't learned this yet, give a monorepo a try. I assure you, you will be divested of any naivete in this regard.
If you do test and isolate testing environment then this kind of breaking update is just business as usual.
Fundamentally cloudflare can do that if they so chose. If your threat model doesn't account for that sort of action then you should reassess.
How was Github's community, specifically, harmed? A lot of developers were inconvenienced, but they would have been just as inconvenienced if he pushed the code to NPM from his local git repo, and never touched Github at all. Where does Github come into this?
Usually if I modify my car in my own backyard (aka my property) it is nobody's business to intervene, as long as it's on my property.
Legally speaking, fakerjs was Marak's property and GitHub has no right to intervene with a legitimate user action.
I can see that they "tried their best" but we also have to uphold the law here. If GitHub, say, called him on his phone whether or not his actions were intended...they would've had to restore the account and the "broken" repository as it was before the suspension immediately...which I assume they did.
My point is mostly that there is no legal contract between Marak and the "community", as he was never paid anything. Some might argue about mitigations in between disagreeing parties, but as I said there's nobody forcing you to use his library, just as there was nobody forcing you to update.
It cannot be malicious intent if the other party is free to decide to just ignore it and move on.
I see it like this. I can't buy a Harry Potter book, translate it to a different language, maybe change some of the character names and then claim ownership while not acknowledging the original work even if I publish it for free.
It's like you and your friends building a Mustang in your backyard, all of you put time, energy, and even money into the project only for you to turn around and claim you invented a new car model built entirely by yourself. No, it's a ford and most of the upgrades were done by others. People that helped you might feel that you are in fact being malicious.
Since we're using analogies, this wasn't his backyard, this is the GitHub's yard.
So I'd argue that it wasn't GitHubs backyard. They might be the landlord but they can't take ownership of the things that you build in your (rented?) flat.
Don't get me wrong, I also agree with you. For me this whole situation is kind of a paradox where there's no easy moral (or legal) answer on what to do, and on what society already has agreed upon.
Completely irrelevant to the issue at hand, though. The copied code was copied in accordance with an open source license. By this same token, the affected users/companies are free to start their own fork, but they didn't. The developer shouldn't be under any obligation to maintain anything, and GitHub shouldn't be intervening in these kinds of situations as that will simply serve to dull the positive effects these scenarios could have on the dependency landscape (people actually figuring out their shit). This is the package equivalent of a bail-out. At the end of the day it hurts more than it helps.
The people building infrastructure that depends on one guy's 3D model existing on his blog at all times were the ones who made a mistake. If one of your thousands of dependencies breaks, shame on you, make a fork. The dependency owner owes you nothing, and he can change his creation or remove it any time he likes. If you weren't fortunate enough to fork it while it was still up, then too bad.
Instead we as a corporate community are encouraging coddling and ensuring that if you make this mistake, GitHub, NPM, et al will take care of it for you. The downstream effects of this are much worse than the temporary damage of making people actually figure out their dependency chains.
You can't use GitHub to perform malicious acts, even if the victim isn't GitHub. GitHub isn't obligated to support anyone's malicious acts with their platform.
> If DHH decided that Rails was contributing more harm to the world then good, and tried to remove it from GitHub, would GitHub lock his account and restore his repos "on behalf of the community", to side with the smooth operation of the open source ecosystem over a user's personal decisions? To what extent has GitHub decided that they "know best" for the open source community?
GitHub hasn't done any of these things with faker.js.
Marak deleted the code and replaced it with a non-functional repo that has a README.md that just says "What really happened with Aaron Swartz?" (Reference to a conspiracy theory)
It's still here. You can still see it: https://github.com/Marak/faker.js
Github isn't obligated to support anyone's anything, your relationship with Github is entirely at-will. And yet, I believe that there are moral boundaries on how Github should act, and that different people can disagree on where those boundaries are. I do not believe that "updating a popularly used library to break it's core functionality" is harmful enough to the other users of Github-the-code-hosting-site that it necessitates intervention from the owner of the platform. I think specifically that the way in which Github came to the determination that this change was "malicious" is unclear, and that Github very clearly has a conflict of interest when it comes to determining which sorts of political speech are "malicious", and which sorts are allowed.
> GitHub hasn't done any of these things with faker.js.
Correct, that's why it's a hypothetical question. If Github is willing to intervene against "malicious behavior" on behalf of "the community", then the obvious question is "which behavior, and which community?"
As another hypothetical example, the https://996.icu/ website is hosted on Github. Chinese browser manufacturers have implemented a pop-up that calls it a "illegal and fraudulent site" if you navigate to the repo. Is this "malicious" behavior? Many in China would think so, and definitely the browser manufacturers seem to believe that it's malicious behavior targeted at Chinese tech companies. Should users be allowed to use Github to perform this "malicious" act, even if the victim isn't Github itself? If Microsoft was criticized for their Chinese offices' working conditions on the site, do you think this would change their viewpoint on whether the repo should stay up? Personally, I would hope that those within Github who are responsible for making such a decision wouldn't take such personal matters into consideration.
> Reference to a conspiracy theory
I'll be honest, I didn't know this was in reference to a conspiracy theory. Aaron Swartz was driven to suicide by the relentless and cruel prosecution of the United States government, and the inaction of the MIT administration. That incident is tragic and sad enough as is, and I hope it goes without saying that don't agree with anyone attempting to co-opt that tragedy for their own conspiracy theories about Qanon. But I don't think Github should be responsible for making the call on whether something is "good" enough political speech to be worth protecting.
> causes a minor temporary disruption in production
pick one
ETA: if someone created a virus that would just display the text "you've been hacked!" and then that virus infected thousands of computers around the world, that someone would have a visit from the FBI with very serious charges. I don't see how this is different.
I don’t understand. Industrial sabotage is an act of vandalism with the intended purpose of causing disruption in productivity. This incident in particular only caused a relatively minor disruption not much bigger then e.g. a partial github outage.
> I don't see how this is different.
The difference is in 1) the intended targets. This incident was targeted against particular industry. The worm you are describing would be indiscriminate and would have the potential to be 2) much larger scale and therefor you could deduce the 3) intention of your hypothetical attacker would not be to cause disruptions of productivity withing a particular industry, but rather to prank random strangers. The difference is rather obvious.
I'm disappointed to see this kind of comparison made.
A build will often reach out, download and install new and potentially breaking software components and it is part of its function to prevent breaking software components from reaching the application where it could cause material harm.
EDIT: I'm glad to hear from a sibling comment that GitHub has since unsuspended his account, since TFA and this comment made me think he was still suspended. Still, it feels like a misstep for GitHub not to have made some sort of comment here.
Not your domain/site, not your corner of the internet.
All cloud services do the similar things.
What isn’t yours is your “right” to use the service.
The only fault here is cutting the owner out of the repo, but given the security breach it’s strange that he isn’t permanently banned at all.
And yeah, adding an infinite loop is a DoS attack.
> not how cloud services work.
Try placing a virus on S3 and let me know how that works out.
You know, I hear that if you go around stabbing people, you lose the right to not spend a bunch of time in prison, too.
HN, at least, had a ton of discussion on this[1]. People advocated both ways.
> This was his own corner of the internet for him to publish his own personal projects.
No, it wasn't. It was Github's corner of the internet and then it was Microsoft's. If he just wanted a place to publish his personal projects, he could have put them on a personal, self-hosted website.
By putting them on a social network, like Github, he is submitting to their whims. He doesn't have any legal right to stay on that site if they want to kick him off of it.
He also wasn't the only author. Other people contributed to his repos. He was happy to receive the benefits of Github, and he should also realize that it comes with some loss of control.
Notably, he eventually used Github as a platform to deploy a Trojan to thousands of unsuspecting users. The other circumstances don't matter. Microsoft can and should remove Trojans from Github.
Of course, legally speaking, Github can do whatever they want with their website, but we're not talking about the legal aspect.
The developer community has put some trust on Github not to do whatever they want. It's an implicit, non-legal, non-enforceable, social agreement that Github is going to "respect" our user accounts on their platform as long as we don't break the TOS.
They could delete all existing repositories tomorrow, and replace them with pornographic images, and they would probably be in their legal right, but that doesn't mean that we can't critizice them for it.
They interpreted a developer's attempt to harm the community via abuse of the trust the community had placed in him as damage and mitigated it in the short run. That's a value-add.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
Also if we're expecting people to do the bare minimum specified in their license, github's license gives them all the leeway they needed for their actions too.
Either we're going by a legalistic interpretation of the terms in which case Marak was free to fuck up his project and github was free to kick him off npm for it, or we're agreeing that people can be held to moral standards apart from legal ones.
If we agree that moral standards about bad faith should prevent npm/github/microsoft from taking control of something that Marak has put work into, then we should also be able to agree that moral standards should prevent Marak from releasing a deliberately broken version of a package as a fuck you to corporate users. Even that action of Marak's I think is wrong, but the backlash also landed on many open source projects.
We can sit here and cluck our tongues and say "Should have known better than to trust someone else's code," but that's just victim-blaming. Marak broke trust. He took advantage of a system with a vulnerbility and he exploited it. And everybody uses a system that is vulnerable in some way.
Because he did this, the system interpreted his actions as damage and routed around them. The system may change to make this attack harder in the future. And the result will be more complex and have more failure modes, and everything will be slightly worse as a result because we have to replace with process what we were previously able to do with human-to-human trust. "Nice job breaking it, hero."
> Under New York law, a party can waive ordinary negligence, but not gross negligence, reckless conduct, willful/wanton conduct, or intentional acts. See Kalisch-Jarcho v. City of New York, 58 N.Y.2d 377 (1983); See also Restatement (Second) of Contracts § 195 (1981) (“A term exempting a party from tort liability for harm caused intentionally or recklessly is unenforceable on grounds of public policy.”).
Using your food pantry analogy, it sounds more like he should go to jail.
Then one day the food had laxatives because he felt not enough people put money in the tip jar.
I think that would still be actionable. Most people wouldn't bother, just like I don't think anyone is seriously thinking of taking Marak to court over what is mostly broken CI builds, but maybe the park staff won't let him offer food there anymore.
> What you're advocating for is that if an open source developer changes their code, even to say, prompt the user to confirm executing when before they didn't prompt and that somehow breaks automation that the user has built (not the developer) then they should be liable for harm.
We should probably divide the conversation into two threads: one on the tainted-food analogy, and one on the changing-code reality. Because they aren't the same, and one can reach weird conclusions trying to conflate them.
Liability for tainted food is pretty settled law. If someone eats your food and gets sick, it's a problem for you. If they eat it and get sick and can prove you poisoned it, it's a real problem with real legal consequences. Food handlers and preparers go out of their way to avoid both of those scenarios.
Intentionally modifying code knowing you'll break downstream consumers hasn't been tested (to my knowledge) in court, so we can set that aside. But is it immoral? That's going to depend on one's morality, but I have a hard time seeing my way to agreeing with the standpoint "Sure, it's moral. User beware." That principle, written large, creates a strictly worse world, where people are hiding in their digital caves, unable to trust anything outside. A lot of people (including GitHub and NPM's owners) are trying ot build something better than that.
Marak had a right to do what he did, but that doesn't mean it was right, we don't have to agree that "because he could, it was good" (that's just rule-by-power, and almost nobody thinks that's a good moral philosophy), and I applaud the open-source community who stepped in to minimize his harm.
Your can think what you want about whether that's good or bad, but it's unquestionably our current reality. Protecting JS projects from malicious updates, regardless of whether or not the project license technically permits this by the author, is clearly in the best interest of users of this ecosystem.
Fortunately, it appears the system has been stress tested now and we can see how that damage can be mitigated. If this kind of attack can be minimized by what is essentially moderation and curation, everything's good.
This is a divide that extends well beyond programming and this topic.
People that support GitHub actions believe in the concept of "greater good" and believe the actions of GitHub are ethical because it prevented harm to the community
People that oppose GitHub actions reject the idea of "the greater good" and believe this individual should have had the right to do with their property (i,e their code) anything they wanted and the responsibility was upon the people consuming / using that code to vet it before use.
If I'm leasing a part of my land to you (and others), and your use of your assets on my land has the potential to harm other users of my land - you'll be asked to leave. I have a business to run. You are still free to take your property to your own patch of land and do with it what you will. Your freedom has not been compromised. You just assumed a freedom you did not have - which is the use of my land in an unfettered way.
I am extremely individualistic. Github is also an "individual" that has its own private rights.
The author of this library absolutely had the right to write code, change it, etc. He does not have the right to use Github as a delivery mechanism for malware.
However that is not what github did.
I’m in the camp that if it was his repo then he can do whatever the eff he wants to it.
Expecting a company to have a moral framework is just setting yourself up for disappointment. They will always just do what they think will maximize their long term ROI. Possibilities lay between "enlightened self interest" and "barefaced self interest."
If you are going to insult people at least get the terminology correct, it is rolling coal, not goal.
Further most people rolling coal are not libertarian.
>>d "individuality" are simply self-centered anti-social assholes who haven't thought through the Libertarian ideologies they parrot deeply enough to realize how extremely dependent on and beneficial from collectivism they actually are
Incorrect, Libertarians / Individualists do not reject the concept of society or working in groups to accomplish a goal. However they believe said interactions should be VOLUNTARY, and not forced upon you by 3rd party actors.
>>against Obamacare for no better reason than the person THEY renamed the ACA after is black,
Ohh yes, the only possible reasons someone could oppose ACA is because of racism.
Do you support with the way your glorious Libertarian leader Rand Paul has attacked and endangered Anthony Fauci's family by lying about him, and reject the government's right to mandate vaccination, but support spreading lies about people and endangering their families for political purposes? What ever happened to personal responsibility?
https://www.washingtonpost.com/politics/2022/01/12/how-polit...
>How politically helpful have Rand Paul’s attacks on Anthony Fauci been?
>One of the more remarkable political disputes in recent history involves two doctors.
>One is Sen. Rand Paul (R-Ky.), an ophthalmologist by training. The other is Anthony S. Fauci, the federal government’s top infectious-disease expert. The genesis of their fight is the coronavirus pandemic and, specifically, government recommendations (for which Fauci is a figurehead) that Paul opposes. Over the course of more than a half-dozen hearings centered on the pandemic, the fight has become much more personal, with Paul accusing Fauci of having contributed to the creation of the virus and Fauci forcefully pushing back.
>On Tuesday, there was a new escalation. Obviously expecting Paul to challenge him, Fauci came prepared with an argument he hadn’t made previously: Paul was attacking him and putting his personal safety at risk for Paul’s own political benefit.
>Fauci pointed out that a man had been arrested while on his way to Washington to attack a number of public officials, including himself.
>“I ask myself, why would senator want to do this,” he continued, obviously flustered. “So, go to Rand Paul website, and you see ‘Fire Dr. Fauci,’ with a little box that says ‘Contribute here’ — you can do $5, $10, $20, $100 — so you are making a catastrophic epidemic for your political gain.”
And of course there are possible reasons to oppose the ACA, but most of them don't hold any water because they are based on lies ("It's SOCIALISM!!!", "DEATH PANELS!!!"), and are just cover stories and dog whistles for naked racism. You know that as well as I do, so don't play coy and deny it.
I see you have confused the Libertarian party with libertarianism they are pretty different
>>Do you support with the way your glorious Libertarian leader Rand Paul has attacked and endangered Anthony Fauci's
Aside from the complete falsehood of this statement entirly, I do support elected officials grilling non-elected bureaucrats in the manner used by Rand.
I also believe Fauci unfit to serve in his current role and there are serious questions around his tenure that need to be addressed including the funding of the Wuhan lab.
You are not pretty different yourself, since you believe and spread the same conspiracy theories, and support Rand Paul's attack of complete falsehoods against Fauci and his family. Rand Paul's statements were mendacious lies, yet you support him and his lies and threats against Fauci for the sole purpose of fundraising.
I'm glad you don't incorrectly disagree with the fact that most of the arguments proffered against ACA are just lies and racist dog whistles, but I certainly don't agree with you that it's a valid tactic, the ends justify the means, or that using racism and lies and threats and spreading misinformation against people's families to grab power and raise money is in any way ethical or justified, or a "great tactic" and that "misinformation works", as Rand Paul himself says.
https://www.insider.com/old-video-resurfaces-rand-paul-telli...
>An old video has surfaced of Sen. Rand Paul telling students that spreading misinformation is a 'great tactic'.
https://boingboing.net/2022/01/13/watch-rand-paul-tells-stud...
>Watch: Rand Paul tells students "misinformation works" in resurfaced 2013 video
Just because I choose not to respond to all of our unhinged conspiracy laced non-sense claims that everything you disagree with is a dog whistle to racism does not in anyway imply I support said statements. '
I choose not argue with crazy people on the internet, and clearly President Trump broke your mind and I hope for your sake you get professional help.
>> since you believe and spread the same conspiracy theories,
Sorry information released from government records pursuant to a FOIA request is not "conspiracy", I am sure you so biased in favor of your lord and savior (Dr Fauci) that you probably have one of those candles or figurines on your desk devoted to him so you will never believe anything negative however reality does not require your faith.
He is mid rate bureaucrat thrust in the lime light by circumstance and this hero worship of him is insane.
Further at no point did Rand threaten him or his family. The attempt to shift any real or imaged danger there is due to public backlash is a very dangerous game, tell me do you apply the same standard to Democrats who inflame AntiFa and other violent groups? Are these democrat politics to blame for all the violence, riots, etc they "cause" (and to be clear I do not believe they cause it, but you world view dictates we place this violence at their feet, i am judging you by your own standard)
Somehow I bet you will be hypocritical
https://www.urbandictionary.com/define.php?term=Popehat%27s%...
>Popehat's Law of Goats
>He who fucks goats, either as part of a performance or to troll those he deems has overly delicate sensibilities is simply, a goatfucker.
>He claimed he was just pretending to be racist to trigger the social justice warriors, but even if he is telling the truth, Popehat's Law of Goats still applies.
>>In no way do I "worship" Fauci.
Press X for doubt
>>You're projecting your own hero worship of Trump onto me.
Never voted for the man... I disagreed with him about 50% of the time, however I saw in real time the lies and misinformation the media was putting out.
>>It's you foaming-at-the-mouth Trump-worshiping Fauci-haters who are the deranged ones injecting disinfectants, popping horse dewormer pills, and drinking your own urine, instead of wearing masks and getting vaccinated.
Fully vaccinated, just do not support the mandates
//and for the record Trump also supports the Vaccines.. Much to the chagrin to part of his base
Also calling on of the most widely distributed human drugs, a drug that won accolades for saving peoples lives across the world a "horse dewormer" is unhinged conspiracy, and medical misinformation. Sure it may not be a treatment for COVID, that however does not change the reality that is a human drug, proscribed by doctors all over the world, and is infact on the WHO list of essential drugs...
>> disproven conspiracy theories that it was actually AntiFa who attacked the US Capitol
Where did I say that? There is clear evidence AntiFa violence all through out 2019, 2020, and 2021 with out having to talk about 1/6 protest turned riot.
>> So do you also believe the election was stolen from Trump, too, like MOST Republicans do?
Stolen in the sense you are talking about... No. However I do believe many states governors (on both sides) inappropriately (and IMO illegally) used their executive powers to change election laws under the guise of "emergency" to manipulate election turn out and other factors for their (or their parties) political advantage.
I also do not believe or support the narrative that voter ID is a threat to democracy, nor do I support or believe the narrative that the US has the most "secure" elections in the world.
>>Popehat's
Ahh yes... Ken White. another famous person broken by Trump. The one famed free speech advocate now fully supporting Censorship of all manner.
I agree wholeheartedly with this statement, but we're diametrically opposed on how these two groups are allocated. I.e., the people you're labelling as collectivists I are in the other group, and vice versa. People who think GitHub did right are a real me-first bunch, not collectivists.
It's a "the needs of the many outweigh the needs of the few" situation.
But Marak specifically is, and Microsoft being the good actor is indicative of how badly he messed up.
If his goal was to make a statement about big corporations taking more than they give to FOSS, arranging things so Microsoft gets to be the hero was a foolish way to go about it.
https://twitter.com/seldo/status/712417019686100992
https://blog.npmjs.org/post/141905368000/changes-to-npms-unp...
This is a straw man. No one made this generalization.
Marak, specifically, is a "selfish baddy", and it has nothing to do with FOSS. It has to do with his abuse of Github, npm, and Faker.js (which other people also contributed to) to distribute malware.
None of that can be generalized to a position about FOSS, Microsoft, or any other nonsense you're trying to extrapolate. It's specifically about a bad actor who was removed from a platform.
Sorry you were complaining about straw man arguments?
>> It's a "the needs of the many outweigh the needs of the few" situation.
> It's a bit mind-boggling that FOSS authors who give their work away for free are the selfish baddies, and Microsoft of all people, are the communistic heroes in your telling.
The discussion is about Github - microsoft - undoing the author's changes, the guy I replied to saying that this was good because he felt the author was "doing harm". So he definitely is saying that microsoft are the heroes there defeating "harm". And since he is supposed to be "doing harm" for his own benefit, the FOSS author being overridden by microsoft is the "selfish baddie".
For my edification, if you have a moment you can you help me understand where my comment failed to hew to a valid analysis of that part of the discussion and became some nasty straw manning activity?
Yes we are. I was responding to someone[1] who was alluding to the legal aspect using legal terms s/he clearly doesn't understand.
> > "What GitHub policy did he violate? The really outrageous thing is that the developer going "rogue" was actually him expressing his freedom of speech..."
Exactly. Marak's defenders are quick to argue that he had every right to do what he did based on the repo's license. It's inconsistent to then blame GitHub for suspending him from their platform.
Whatever his intentions were, acts like this threaten the open source community, but do not actually threaten the big companies at all.
This Tuesday is the 10-year anniversary of the SOPA/PIPA blackout [0,1]. Half of the tech internet crippled their own functionality for a day, in an act of political speech. (Was GitHub part of that?)
Tech culture has surely changed since then!
[0] https://en.wikipedia.org/wiki/Protests_against_SOPA_and_PIPA
1. Pulled down his repo, or replace his repo by whatever message he wanted to send.
2. Output his political message during the build.
3. Heck, all faker.js does is output fake data for things like names and addresses. I think he would have been well within his rights to make this data something like "123 Fascist Way, Fascistville, NY".
But he didn't. He replaced his code with an infinite loop that was a DoS attack. He deliberately released it as a patch version because he knew it would be pulled in by others that follow semver rules. The fact that his attack wasn't more severe (like, say, encrypting someone's hard drive) doesn't mean it wasn't an actual attack.
And for those quoting the "no express or implied warranty" section of the license, I guarantee no legal system is going to let an actual malicious act be defended by a license.
I can't create code with malware. I can't modify my code to make it malware. That's a crime. You're wrong
And the cybersecurity industry would like to have a word with you since you don't believe it's possible to create malware.
https://law.stackexchange.com/questions/966/can-one-be-liabl...
> I can't create code with malware. I can't modify my code to make it malware.
I guess I can appreciate your confusion but I still think I was clear in my previous comment. I'm willing to concede I would have been more clear if I had written:
I can't legally create code with malware to distribute without a warning. I can't legally modify my code to make it malware if I know people are using it.
PS I'm not discussing this further
What he just did is intentionally mess with the society for the heck of it and naturally the society will find ways to fix it and restrict him as necessary, right.
By putting it on Github, he surrendered a portion of his right to distribute to Microsoft, and Microsoft did the best course of action to protect their reputation and the interest of their stakeholders.
I see nothing wrong with this.
vs. an open source developer who’s work benefits companies like Microsoft who have no obligation to pay for that labor. And engages in a single industrial sabotage which causes minor disruptions, and harm which at most costs other developer some time and temporary frustrations.
I feel like we need some sense of relativity when we attribute nouns such as hazardous and dangerous here. Especially when we are talking about Microsoft.
then pay him? I'd admit that this person didn't really contribute anything really worthy. But please do not require someone to be "professional" when you did not pay him a dime.
So what you do mean is someone had to spend hundreds of hours maintaining some projects you've been using and also should have perfect personality and well behaved enough before you hire him?
You see a build fail, you pin the previous version of that dependency, run the build again and go on with your life.
Asshole move? Sure. Hazardous and dangerous? Don't be dramatic.
"1,2,3" Honestly, these ARE better things to do (and probably more effective) than what Marak has done.
"replaced his code with an infinite loop that was a DoS attack" So far I haven't seen anything about this actually causing harm and denying service.
"The fact that his attack wasn't more severe (like, say, encrypting someone's hard drive) doesn't mean it wasn't an actual attack." The fact that his attack wasn't more severe shows that he wanted something that would make an impact without hurting anyone.
" guarantee no legal system is going to let an actual malicious act be defended by a license. " That's the legal system's problem. The license is the license. Somebody's violation of an EULA (because they didn't read it) may be in all ways justified, but that argument probably won't hold up in court.
I wish he did something less controversial while still impactful, but it is incorrect to put it under the same term used to describe real cyberattacks that severely harm and kill innocents.
Just like BLM could protest in a remote location or do an online petition. Except that no one would give a fuck about that. The same about a message during the build.
You call it a DoS attack, I call it a brownout warning about unsustainable open source funding. After all old versions are unaffected. No hidden RCE there. Only ones who opted in for pulling a new version without due diligence (aka free shit lovers) experienced a minor inconvenience. He didn’t do anything a malware author would do with such distribution channel.
I would definitely do it some other way, but can’t blame him. If he had put a notice during the build, no one would see it. If he added an unskippable five minute timeout to that message it would a DoS attack as well.
I suffered a similar “DoS attack” myself. By Microsoft. They did one hour brownout of Devops pipelines still using windows server 2016 or something, to warn about unsustainably of supporting them (striking similarity). Right at the moment we had to deploy an urgent hot fix for our client. If there was a notice somewhere, I didn’t read it. No one does. Which is why they do brownouts. He didn’t put an early warning, but that might be a difference between a multibillion company and some random guy on the internet.
He is unprofessional, but well, don’t expect professional behavior from people you don’t have professional relation with. Who I would call unprofessional, are the developers who expect free working shit from some random internet guy and have audacity to complain when he intentionally releases a broken version to protest taking free stuff without giving back.
I’m mildly entertained by the uproar caused by his protest. Reverting to an older version of a library is not an end of the world. I think it is not caused by the minor inconvenience he caused to the lazy devs, but by the threat of the end of relying on free work from open source devs.
We will have to do it ourselves or pay for it. Like in any other industry.
I think this is the crux of it all. I (and many others it seems) disagree with the actions he took and think they're shitty, but also think he has a right to do this with his code that he provides and publishes for free.
But certainly not beyond repair (as injecting adware in your package).
Also it is certainly a reminder for everyone that GitHub should not be treated as an archive of your code, and more like a collaboration space.
Github claims to be a home for developers to publicly host code of public use. Any benefit to an individual developer is incident to that overriding purpose and they are clear about that in their use policies.
> What GitHub policy did he violate?
https://docs.github.com/en/github/site-policy/github-accepta... gives their acceptable use policies.
I think they could easily make claims on any or all of sections 2, 3, 4 and 10.
Section 10 in particular notes that Github is a service run for a mass of users and will favor users as a whole over individual privileges.
> expressing his freedom of speech, again on his own personal GitHub account, in his own personal (not organization) repositories.
Was he running his own Github server instance and I missed it somehow? The flipside to Github paying to run your git repo, issue tracker, etc. is that you agree to abide by their terms of use, and these terms are written for Github's benefit.
If a million Github users are impacted by this package breaking their code then why are you surprised that Github took action to protect their users?
Marak could have hosted his own git repo if he wanted to ensure his malicious code couldn't be intercepted by others. That's the tradeoff you have to choose.
> He spoke about his thoughts about open source, businesses, and economics. Defending this type of political speech [snip]
Inserting infinite loops into packages isn't "political speech" and trying to claim as such just waters down the entire argument...
He's not banned. It was most likely an initial response to a suspected compromised account situation. Once they determined the actions were carried out by the account holder, they reinstated it.
There are MANY reasons to be annoyed with GitHub but this isn't one of them. Github's actions here helped, not hurt. I would hope they'd suspend my account if they too thought it was compromised and pushing out malicious updates to packages.
The security of users is of the utmost importance.
Marak needs professional medical help. It is clear he's having a mental break and the people defending him and egging him on are only making things worse. He has a history of erratic behavior (dating back to almost a decade ago) and needs to find healing, not accolades.
Since this whole fiasco, Marak has garnered loads of followers and has increased his sponsor count dramatically. We should not be rewarding this behavior. If you at all dig into this, you'll find not a stable, perhaps loud individual, but a troubled, erratic, unpredictable, and hurting one. He is not martyr. He's not a patriot or a revolutionist. He's an abuser, potential "freedom fighter", malicious OSS maintainer and a beggar.
Please. Let's end this and not give any more attention to Marak. He needs help, and we're all collectively making things worse.
In the end, this thing spits out strings. Does it need eight maintainers, only a few of whom had commits, in low double digits? Does it need its own GitHub org, Twitter account, and Google .dev domain? Addressing open pull requests could be good, but the rest of the roadmap looks like packaging, doc, twiddling with test infra, and more "community" again. That is also work, I suppose, but API and function feel baked. Before he did "bad", Marak did good.
Overall, the vibe here is self-righteous hostile takeover. That's a pretty fraught concept I don't see a need to go near. Maybe it's not fair or accurate, for those better in the know. But from the outside looking in, seems to me a fork, a new name, and a quick tweak to package.json could fully address the issue of another 6.6.6-like release, cleanly. No special deals with the platforms. Name brainstorm, clone, fork, push, and publish of existing MIT code would have been intensely normal. Especially in JS land.
I get that "community" is supposed to make me happy and calm. But in the end, I don't see anything here addressing root causes of what happened, or even speculating on what they might have been. Marak isn't the only solo leading projects who's snapped, and he won't be the last. It's convenient, but ridiculous, to say that has nothing to do with the environment we've built up. Plus we've learned a new way to lose donors, it being no mean feat to get them in the first place.
"Hospitalized Queens man charged with reckless endangerment after cops find bomb-making materials in his home"
https://www.nydailynews.com/new-york/nyc-crime/ny-queens-bom...
I’m not surprised with Marak’s behavior given his mental state. What surprises me is the amount of support he’s garnered for his actions with a lot of people on HN.
Well, his motivations were somewhat understandable and his actions were still scratching the realm of acceptable (not cool, but no serious damage and nobody was hurt). It's actually hitting the pretty much perfect spot to generate lots of discussions, since it's very easy and understandable to argue for either side.
Declamations are fine; declarations about what is "acceptable" and what "they should have done" are more than mere criticism of poor judgement, etc., and are what the author of the comment I responded to actually wrote.
Then from the context, you can clearly read the comment you responded to did not mention that Makar needed to do anything for him specifically.
(This is my last response to you, since you were strawmanning from the beginning and this is obviously not going to go anywhere that doesn't involve intellectual dishonesty dressed up as a clever retort.)
He could have, and nobody would be talking about or remarking on it at all, which rather defeats the point.
It was a rebellious act against (what seems like) overbearing organizations, comparable to spraying a graffiti on their walls. As I said, there was no serious damage and nobody was hurt; it's not like he burned down buildings or shot at people. I'm of the opinion that this was not the right way as well, but in the end it really wasn't that bad.
I don't have a direct line on what happened to him, or where it took him, mentally or otherwise. But the hints so far aren't great. To one of us.
I think the responses from the platforms---GitHub, OpenCollective---get folks thinking, whether they feel it that way or not.
The vast majority of people on HN would never purposely harm strangers. Most of these strangers are fellow developers ie “Us”
I'm sure the people who got burned on builds had bad days. It's not fair to blame them entirely, for not locking deps. It is fair to point out this isn't the first time builds have broken, with npm or other repositories. Nor the most widespread in effect. Does this count as a crisis?
If anything, I suspect a crisis of faith. Seeing bad things can come of `npm install`, and those bad things might be intentional or just plain weird, instead of well intended but accidental, can make people anxious. Publishers to npm don't just disappear or malfunction. Their faults can be byzantine. But there are defenses against them.
On the maintainer side, like it or not, we all have an editor when it comes to publishing on GitHub. But it matters how invasively that power gets wielded, and how heavy-handed it's perceived. This episode suggests to me that the threshold for intervention in the name of user interest's pretty low.
That's based on the information I have. Perhaps GitHub will share more on the blog.
This is an open and shut case. GitHub did the right thing.
One of who, exactly? Marak needs professional help. This isn't a "personal army" situation.
It's like if a business delivered packages by asking some random homeless person on the street to walk it to its destination. And then one day the person just chucks your package in the river instead of delivering it. It's amazing that the company got so much value out of a free service for so long rather than shocking that it eventually didn't work.
Your analogy isn't even close. No one forced him to write faker.js. He chose to do it and he chose to make it open source under a license allowing people to use it. He also chose to maintain it and help people with issues. If he didn't want to maintain it anymore, It is his right to stop. No company could force him to continue. But he nor anyone is not entitled to add malicious code. Full stop that is where I draw the line. I can't believe anyone is defending that.
Yes, it is particularly shitty to intentionally screw it up. But the system that put so much value on something not happening without any safeguards or obligations is the real problem.
The move fast and break things attitude of web development is the cause. A single rogue dev is just an example of the worst happening. In the future I imagine we will have package managers which do not give random individuals so much power. And we will rely on packages from trusted names, Google for example has a very very low risk of sabotaging a package compared to a no name individual. If companies had paid for this package, they could take legal action against the author. But they paid nothing and had no assurances of anything other than a vague hope it would continue to work.
The code was open source. The code was published under a new major version number. The code had a descriptive change log that definitely didn't seem congruent with earlier versions. And he wasn't getting paid for it. What thing of value did Marak Squires defraud people of?
I get the sense that people are reacting with extreme hyperbole in their accusations, out of anger that he did something assholish.
Serious question: how is this different from 1Password publishing an upgrade that removes the ability to use standalone vaults in the iOS Safari extension?
At the end of the day, Marak published an update, knowing some people would update the software automatically due to their own workflows, and the update had negative effects on the users. Companies do this all the time and nobody accuses them of installing a "Trojan Horse" or committing a felony.
How did it come to this? Where HN, a place that is supposed to be genuine and curious, believes an act should be acquiesced to or branded a felony based on the individual's personality? Because that seems to be the consensus here and I find it disturbing.
If there was a bug in his logic that caused an infinite loop in some scenarios he was under no obligation to fix it. While I think he should in that scenario, I would defend his right to leave it. Another maintainer could fix it, someone could fork the package, whatever.
I am not arguing he owed anything to anyone. I am arguing that he is not entitled to maliciously break things on people. He committed it knowing full way most packages would grab it automatically, most people are okay with that as if it breaks things they can go back a version no big deal. His package is so popular some people might not even realize that one of their dependencies relies on it.
We can argue about how much time you should invest in knowing your dependencies and checking every commit for them, until we are blue in the face. The reality is he knew most people just can't or won't especially in npm world.
There is no defending a malicious act. He is not entitled to commit code maliciously. OS works because we trust maintainers to do their best to have the best interests of the users at heart. The flip side of that is they are under no obligation to work on it. They can walk away at anytime.
If peoples idea of OS software starts to include that someone could do something malicious at any moment, that's the beginning of the end of OS.
That analogy makes little sense.
In my county, what you described is malicious mischief, and is a crime. A homeless person is not entitled to act in such a manner.
Utter nonsense.
You don't put out code under open-source MIT and then want to take it back when you realize other people are using it exactly as you instructed them to use it, which in this case is "anyway they please".
You have to think about this stuff before hand if you want to be compensated if it "takes off", there are other licenses you could use.
A saboteur is more often then not mostly frustrated at their employer, or the industry, and try to maximize harm to those entities, not innocent bystanders. However given that saboteurs are often quite angry and have often been in a prolonged state of stress, and most often act alone—keeping their plans secret until they are executed—they are often not in the best position to correctly estimate who will receive the most harm.
In our industry there are plenty of frustrated workers, some are underpaid, others are overworked, some work for entities they morally object to, etc. When a colleague engages in this kind of sabotage which causes disruption on some scale we might see it as an act of solidarity from a shared frustration. This is certainly the case in other industries, and I don’t think tech is any different. In fact this incident reviles that our industry might even be more vulnerable to industrial sabotage then other industries.
I'm pretty sure the org and multiple people are to avoid a single point of (mental) failure - quite reasonable given the project history.
Also, if we really want to go that way, Google Search is also just a product that spits out strings. And a few orders of magnitude more over-engineered ;)
> But in the end, I don't see anything here addressing root causes of what happened, or even speculating on what they might have been.
Well, they have a larger team now, which can reasonably prevent a single person from doing that kind of damage when set up correctly. What other root cause are you looking for? Mental checkups for open-source maintainers? Redefining the "free" in free software?
In any event, the median count of contributors to an open source project remains one. This team-up doesn't help projects != faker.js.
As for scope, I haven't looked at this source in a while. But it seems the strings are still static, in the package: <https://github.com/faker-js/faker/tree/29234378807c414158886...>.
That's not really a critism. 90% of web dev is string manipulation.
I'm sorry but this feels wrong. The existing sponsors should have their subscriptions cancelled, instead of going to a new organization automatically.
Any sponsorships tied to marak's personal GitHub account were not changed, of course.
This is also consistent with the original terms:
> During the conversation with Ben, he went over the terms and conditions of the Open Collective with me.
> Ben said that simply, "The funding is attached to the project, not the current maintainer."
Full details: https://github.com/faker-js/faker/discussions/56#discussionc...
Yeah, but the project is not actually the same anymore. The new project taking over the name and URL of the old project doesn't make it "the same" project.
Do you really think the sponsors and the people using this code actually care that one person (of many contributors to the project) who wanted to break the project is no longer part of the project?
It's a technicality, but in practice nobody actually cares. If they wanted to sponsor Marak they would have done it through his Github sponsorships. If they wanted to sponsor Fakerjs, in whatever form it takes, they would choose the Open Collective and their associated terms that allow for exactly this scenario.
Some of them probably do. And some probably don't like the way in which the takeover was done, or don't like the new guys, even if they don't really like what the old guy did either.
> During the conversation with Ben, he went over the terms and conditions of the Open Collective with me.
> Ben said that simply, "The funding is attached to the project, not the current maintainer."
None of Marak's personal GitHub sponsors were changed (obviously).
To be clear: Marak deleted the original project as part of his protest. The sponsors in question are donating money to sponsor the project, not a single person. It wouldn't make sense to send their money to someone who deleted the project.
This new fakerjs isn't the old project, technically or practically speaking (technically being the important part here).
So funding attached to the old project should be still attached to that now-abandoned fakerjs, or straightly up canceled if Open Collective considers it violates their terms, instead of transferring.
The fact they can't do it themselves and asked Open Collective's exclusive director to do it "manually" basically self-confirmed it shouldn't be done.
No, it's definitely a continuation of the old project.
Marak deleted the old project. It's now just a non-functional GitHub repo with a Readme that says "What really happened with Aaron Swartz?". Nobody would consider that to be more like the original fakerjs than this active fork that, literally, retains the original fakerjs.
> So funding attached to the old project should be still attached to that now-abandoned fakerjs
Not just abandoned. It's deleted. Or at least rendered useless, devoid of history, and non-functional.
Why would they continue funneling money to that? Why would they not give money to the actual project as it continues?
What I don't agree is to transfer its sponsors to an account that has zero relationship with original account.
Marak's GitHub sponsors aren't changed. If people wanted to specifically sponsor Marak, they would have chosen to do it there. The Open Collective is very specifically about the project, not a specific person.
> What I don't agree is to transfer its sponsors to an account that has zero relationship with original account.
The current fakerjs has more of a relationships with the original code than what's in Marak's repo.
I don't see the issue. The Open Collective is specifically about sponsoring the project, which Marak clearly and publicly washed his hands of.
Again, they weren't sponsoring Marak. They were sponsoring the project. The project is still going.
> We came to the determination that users unfamiliar with the whole Faker situation wouldn't know that the repository's sponsorship links aren't funding the continued development of the project.
If the intent of the supporters was to support the project, then you can ask them to continue funding the new fork. But you don’t just move funding by default. Cancelling the ongoing support would be fine, but you are relying on people (who were never aware of the switch and the new fork) being okay with this, without their consent.
This is a messy situation, but you can’t make these decisions unilaterally. Inform the supporters and let them decide.
Open Collective makes it clear that the sponsorship is for the project, not for a specific person.
It's not "without their consent". It's literally the terms of the Open Collective.
To me, this is like the left-pad incident and npm. There was a vocal minority who denounced npm for looking after the greater good, maintaining continuity and transferring the project to someone else.
In this case, since the author also deleted the project, the proper way to maintain continuity for the sponsors seems to transfer it to the new community of folks who are interested in maintaining the project. Sponsoring the old deleted project does nobody any good.
Personally, I don't see anything wrong with what OC did.
You can make that decision easy, you can automate a lot of it, you can inform, but you can’t change which project the funding is going to without explicit consent.
And yes, for these purposes, the new fork should be considered a new project. It is a completely different situation than if the project itself decided to change maintainers, etc.
This is really a crazy situation where the original maintainer blows up the project. The best scenario would be for the original authors to hand over the project in some capacity. But that seems pretty unlikely.
To put it in different terms… this was not a SQL UPDATE. The was a DELETE. You don’t just change foreign keys to a different project_id when you delete a record.
I would also argue that the author was completely irresponsible, and made life difficult for everyone that used and supported the project. But that’s a separate issue and doesn’t make what the open collective decided right.
Does the open collective have the ability to decide who is in charge of a project? Can they remove maintainers?
Let’s say there is a fork of a different popular project. Are you suggesting that they could they unilaterally decide to support the fork over the original project? However unlikely that is, I don’t think they have that power. Decertifying a project? Sure. Redirecting funding to a new project (even a fork), just isn’t right.
The project no longer exists. It was deleted. These people forking it does not give them the ownership of the project. The problem in the supply chain was solved by NPM rolling back the version. Github temporarily suspending his account could be attributed to suspicious behavior. These guys commandeering someone else's open collective and general community identity (hn handle, twitter handle, library name) does not solve any actual problem, and is clearly just an opportunistic way to boost their own standing in the community and financially gain off someone else possibly having a breakdown. Shameless and very unethical.
If I make a donation to a charity which I trust, and some third party simply takes the money and hands it over to some other charity instead, claiming that it doesn't matter because the goal is the same, I'd be rightfully outraged. How is this different?
Also, kudos for emphasizing the real originator of the package:
> Faker was first implemented in Perl in 2004 by Jason Kohles
Thanks everyone.
`npm install --save faker` and boom you have access to a huge variety of random test data, across different locales. Doesn't stretch my imagination to see the appeal.
I wonder if those who say "2 days?! Just npm install!" answered those questions, or if they googled "nodejs fake data generator" and installed it onto their businesses main product in the next 5 minutes.
`npm install @faker-js/faker --save-dev`
1) Is the project built correctly
2) Is it the correct project for your issue
3) Is the project maintained
4) Is the project going to be maintained for the lifetime of your project
5) Is the project secure, and how risky is including it to your project?
And if these are all good then sure, it makes sense to include it in your project. And this is good engineering. But what people seem to do is go "Oh hey, I need to get a random name from a dictionary of names. Let's google that. Oooh faker!" without even thinking these questions through.
So...just you, in your career, have spent between 1 and 2 total weeks of developer time building the exact same functionality, and you're curious why an open source project that cuts that time down to like an hour is popular?
I'm also a little suspicious of the claim that it's the exact same, because Faker has a lot of functionality under the hood, but you've more or less demonstrated why it's useful in this comment.
And of course the reason this new version exists is because the previous version was deliberately broken.
Why add significant dependencies for the sake of a few hours (maybe a day or two in the long run if you need to add functionality)?
A) most of the dependencies that Faker has are common with lots of JS projects that I work/have worked on in the last few years. Looking at that dep list[0], I'm familiar with most of them. They're mostly common packages. To some degree, I'm relying on the thousand eyes here.
B) In terms of security risk, Faker runs in test suites to generate data and locally on dev machines, sometimes, to populate sample DBs. It lives and runs in managed environments and doesn't get packaged into prod anywhere. The risk profile isn't nonexistent, but it's also not a massive risk.
C) I really think we're underrating the amount of work that would required to recreate this project (not uncommon here). Faker can spit out 205 different types of random data in 46 different languages/dialects. Building that is not a two day project (evidenced in the fact that people have been working on this for years now); making sure you can generate all that data correctly in all those different languages is a non-trivial task; building and maintaining it internally will take dev time and energy and will continue to require that time and energy on an ongoing basis.
You're talking about this choice here and in other comments with an air of "silly JS devs, just build this easy thing!". I don't know if it's your intention, but you're coming off dismissive and ignorant. People think about these tradeoffs all the time, and sometimes decide to use packages like this. I think it might behoove you, if you find someone's decision confusing, to start from the position that they are also reasonably competent professionals and see if you can understand why a competent professional might make a different decision than the one that seems obvious to you, rather than assuming that if someone makes a different decision they're stupid and/or incompetent.
[0]: https://github.com/faker-js/faker/blob/main/package.json
Could I/anyone else build this? Of course. Could I do it so thoroughly, provide support for it, and still do my day job? Not easily, not as easily as I could install this project and use it.
Also keep in mind it's not like those 8 contributors are throwing a full 40 at this project every week.
I don't think it's a bad philosophy, just different perhaps from yours (and mine).
Working for companies we are taking big bucks for writing some glorified invoicing systems (let be honest 90% or 99% of business logic is "move from screen to DB, move from DB to screen"), but code which is often important part of whole process is created for free by some folks. Strange.
If he just wanted corporations to pay, there are plenty of other alternatives like changing the license for future versions like SugarCRM did. It's been years since they've done that and they have plenty of customers.
https://sugarclub.sugarcrm.com/engage/b/sugar-news/posts/sug...
Since the developer in question has been acquired in the past (https://en.wikipedia.org/wiki/Nodejitsu), he could also make it into a SAAS play. He has the connections, skill and experience.
Otherwise, he can just walk away like everyone else. Maliciously changing code to break people's stuff is uncalled for. If he wanted to charge people from the start, then maybe he shouldn't have used the free for all MIT license for his code? If you want more restrictions on usage, choose a more restrictive license. Here's one of many restrictive licenses that changes depending on who's using the software
https://writing.kemitchell.com/2021/06/15/Big-Time-1.0.0.htm...
Fakerjs is also not completely original work. It's a port of a Ruby library which is also named Faker. That Ruby library is also likely a port of a Perl library that is also named Faker. I haven't read anything about Marak even mentioning to support those projects financially.
On a related note, Marak is not well mentally which helps rationalize what he did
https://www.qgazette.com/articles/more-charges-possible-for-...
"A team of NYPD investigators and FBI agents found potassium nitrate, which is used in fertilizer, metal containers, fuses and other bomb-making materials in the crate, along with printed bomb-making and survivalist materials and a book on how to make a bomb scattered throughout the home, the source said."
“'The chemicals separately are what they are, but taken together they can assemble an explosive device,' NYPD Dep. Commissioner of Intelligence and Counterterrorism, John Miller, said. 'There were books about military explosives, booby traps and other things.'"
I could be wrong, but Marak purposely trying to sabotage other people's projects was a precursor to him attempting to hurt people in real life. This was not reasonable behavior from a sane person. He should not be getting this much support from so many people on HN.
how about you do it for him? like forking and maintaining your own copy of faker.js and all the nodejs packages you are actively using in the first place?
ad hominem does not help your argument.
Please read the comment before accusing its author of ad hominem attacks.
I only wrote the other stuff to show that there are other better alternatives to getting paid as a response to people who supported the terrible thing that Marak did to open source.
However he also distributed the software under the MIT license - that is "as-is" and "without warranty of any kind". So I'm having some trouble understanding why would you point out his personal life, psychological state, or his past projects as justification for anything related to Faker?
I haven't checked earlier versions of Faker but 5.5.3 does credit both the Ruby and the Perl libraries.
Problem is in this that default behavior is "we are not paying for tools", people are looking for free tools to avoid fighting with procurement and everyone seems happy. Only really big companies are giving something back, most is simply leeching from OpenSource community. You are mentioning several ways how this guy was able to collect money, yep, but again changing license would mean that somebody else will fork previous version and thats all.
I'm not saying that this action was super, but for me it is result of problem deep in whole idea of "free libraries" and "free tools", often this all base on some poor guy or gal spending weekends on some project, which at the start was cool and funny, but later becomes burden.
The problem is if the person wants to get paid, then they need to use licensing that is more restrictive and sets the expectations for eventual payment. The MIT license is a "do whatever you want with my code as long as you don't sue for inadvertent mistakes" license. No one else is at fault for that license except for Marak. The expectation of doing what you want based on the license is inline with behavior. If he wanted to change behavior, he just has to change the license or don't go open source. You can't have your cake and eat it too ie. you can't have open source's viralness and expect everyone to pay. If you want a near guarantee that people will pay for your work when they use it, don't go open source. Open source is not about getting paid.
> You are mentioning several ways how this guy was able to collect money, yep, but again changing license would mean that somebody else will fork previous version and thats all.
Since we're on this subject, I'm going to remind you that Marak didn't come up with faker on his own. He ported it and maybe even the data from a ruby project that was also called faker. To my knowledge, he hasn't shared any of the monetary contributions to his project with the people maintaining the ruby version of faker.
If his software is so simple that someone can just fork it and gain an audience, then maybe it's too simple to replicate and too much of a commodity; but as I've already pointed out SugarCRM successfully transitioned to closed source and I believe redis has successfully transition to a more restrictive license. Neither of them messed with other people's projects. There's no excuse for the bullshit that Marak pulled. Zero. Changing the license is more simple than adding an infinite loop to waste CPU cycles.
> which at the start was cool and funny, but later becomes burden.
I've already written this, but most people just walk away instead of doing something malicious.
I wish everyone to read the above about 5 times and try to let it sink in.
“He can do whatever he wants. Users should just not download it.” Well, Microsoft can do whatever they want. And they did.
On the other hand, this further proofs exactly how replaceable one can be... especially those who want to `sacrifice` themselves for opensource work.
Get a job to sustain yourself and your family; then contribute to open source when you are bored or for fun...
The copyright to the original code still belongs to the original author, of course, but the author has chosen to license his code in such a way that this is a perfectly fine thing to do. This is the power (and, for some, the weakness) of open source.
[0]: I can only find one live registration by the name "Faker" here, and it's not in the same segment as computer software https://tmsearch.uspto.gov/bin/showfield?f=toc&state=4801%3A...
> Faker was first implemented in Perl in 2004 by Jason Kohles
It’s not like he is mining crypto on your machine. It’s a (however misguided) act of protest and demand for attention.
Fine GitHub put the breaks on in case it was an account takeover but they should allow him to do whatever he wants with his repos once it confirms it’s really him.
Also npm just removes his access…? If I was the author of a popular npm package and decided I wanted to remove it I’d hope npm and the “community” wouldn’t appropriate it and decide I don’t have an opinion about it.
Wanna clone it and upload your own? Fine. As the original author I should have the final say?
edit: undoing autocorrect
Ouch. Has it diverted too far from common sense?
0: https://abc7ny.com/suspicious-package-queens-astoria-fire/64...
Anybody who continues using this new fork should therefore never again complain about evil corporations making money from FOSS and not giving back just because they're legally allowed to. This is the exact same thing.
This would be an exceptionally hard problem to solve, with-or-without blockchain.
Could you develop a system where any new releases are required to be reviewed and "signed off" by a random assortment of users before becoming "active"? Sure.
Is "blockchain" necessary for that? No.
In this situation, you are downloading code from a central authority, and have placed your trust there already. What benefit does a distributed solution give here?
As you note, this doesn't require a blockchain. crev uses a web-of-trust model which is pretty well suited to the task.
In contrast, Powershell on Windows won't even let you use scriipts you've written yourself on your local hard drive unless you call them in a way the lets PS know you approve them. Scripts off the net have to be signed.
Methods of signing scripts https://docs.microsoft.com/en-us/powershell/module/microsoft...
Signatures from the author doesn't solve much unfortunately. You would still need a mechanism to build trust (or review the script manually) and once you put that trust in the author, all that a cryptographic signature gets you is automatic trust in the next version... so the Faker attack slips through.
A lot easier to pretend NFTs are more important than collecting stamps.
Ethereum provides trust in the results given trust in the code, nothing more.