ImageGlass added malware with this commit
github.com
github.com
>Very positively surprised by you listening to feedback and changing it, I was about to drop ImageGlass. I'm sure you'll figure out a better way to financially support the project.
>One thing you should definitely do is promote the Microsoft Store version more directly, I previously didn't know you could even buy ImageGlass. Now I'll do just that. It's hard to notice on the website, and you could also display something when launching the program the first time.
- https://github.com/d2phap/ImageGlass/issues/1252#issuecommen...
Financial support for a project is hard. Novel approach I've not seen before, not something I'd want.
https://github.com/d2phap/ImageGlass/issues/1252
The malware (at the very least) makes the user's machine the exit node of a commercial proxy service, without users' knowledge or consent.
In the repo maintainer's own words (in a "privacy" menu setting that was enabled by default):
>"Share devide IP with Spider.com customers to pass traffic through your device."
>"Learn more about privacy policy at {0}. To opt out an option, you can uncheck it, then click 'Save' or 'Apply' button below. It will be disabled immediately."
https://github.com/d2phap/ImageGlass/blob/51f9f5eaa17f6fc42e...
New version has been released.
On a semi-related note: Woof, issues like that make me want to never do open source again. Did that guy make a mistake? Obviously. Was it in good faith? It seemed so. Were people jerks even after he fixed it. Absolutely.
> ImageGlass Store version is not affected.
Most contributions are from drive by contributor's that may not even use the project.
Neither those nor the maintainer are entitled to compensation, but open source is a cruel environment where people want to use what you made but they wouldnt give you a dime unless they had to
I wish it was otherwise, people, but it's usually "build it and they WON'T come" ("they" being the funds needed to make a living.)
We need more martinlindhes in open source and fewer Yakabuffs.
It seems to me that it's up to the author to explain why the project can still be trusted, they can't just do this and expect that people will still trust them just because they reverted it.
everyone makes a mistake at some point and the fact that the dev used the ip hijacking service's name in the commit message to me signals that he wasn't aware of how shady it is
Even if he was, a comment like "I don't think this is acceptable and will fork" is a lot more appropriate than "don't talk shit"
Adding unwitting users' computers to a proxy network by default is so obviously and blatantly unethical, it beggars belief. I'm not angry at the creator, because they seem oblivious. I am, however, extremely saddened and frustrated by their obliviousness. Like in no universe is it ever OK to do this even if nobody responds to your discord poll. It takes a real failure in responsible, ethical upbringing to get here. It takes a lack of consideration and empathy for other people to believe that including this isn't an act of aggression towards everyone who encounters the software.
Or sadly, that commit log standards are nonexistent and don't have to describe the changes and be misleading, it's one of those.
As far as I can tell, they didn't even really make a Discord poll.
The first mention of "spider" (or "IP" or "proxy" or any related words) is from the release announcement of a version which already contains Spider, which got negative reactions: https://i.imgur.com/gLKce8W.png
It's very deceptive wording since "I made an announcement to poll people's reaction" is technically true, but it wasn't a poll or before the changes were made as is implied. Same with "There were very little comments", which leaves out the fact the comments they did get were negative and the low quantity is just from it being a small unknown Discord server.
On what planet could this be considered good faith?
How is this legal? And who even uses it?
I'd guess any such VPN can even put in their ToS "you grant $company the ability to send and receive traffic from your device" which wouldn't raise eyebrows in the same way such a clause in an image viewing binary would
I've seen this exact attitude before. It's always interesting to me when a developer like this announces huge changes exclusively through a channel that it turns out most of their users aren't even aware of.
-Hitchhiker's Guide to the Galaxy
As I see it the dev asked the void and got no negative feedback.
Afterwards the void grew legs and started running after him
The very first mention of "spider" on that Discord was already the release announcement of a version containing it and got negative reactions: https://i.imgur.com/gLKce8W.png
I skimmed through the dev's messages prior to that (not many) and couldn't find anything else related.
I believe "I made an announcement to poll people's reaction" is intentionally deceptive wording to imply they made a poll beforehand, but they're actually just referring to the release announcement. Same with "There were very little comments" which misses out the fact that all those comments were negative, and there were few comments primarily because it's a small unknown Discord server.
When I install a new software I am always a bit uncomfortable about the potential trojan.
The only thing that prevent it is if the software owner has more to gain by keeping it clean, and this is, unfortunately, not always obvious.
I used ImageGlass in the past, I'll think twice before installing it again, and that will probably never happen as there not a huge utility or value there.
One thing is adding a paid plan after you decide you want to monetise your software, it's unpopular but understandable, another is bundling malware or adding malicious logic to get some money or "protest" because companies aren't paying you. They knew this is how open source worked, and being a twat because they don't like those terms anymore just ruins their reputation and all the goodwill they've built.
/// <summary>
/// Checks if Blueswan service is running.
/// </summary>
/// <returns></returns>
What fresh hell is this?Fun fact: the DLL also has various "C:\Users\akabos" strings, that being the "CTO" of this enterprise: https://ru.linkedin.com/in/akabos
Russian malware writers don't care much for CI.
It's definitely on the list of "Must Install" after a fresh OS install, with VLC and a few others.
If you're already on windows (imageglass doesn't look cross-platform), why not use the built in photo viewer? It's pretty lightweight. It's not open source, but if it's already part of the operating system I don't think that's something to worry about.
https://www.tenforums.com/tutorials/14312-restore-windows-ph...
The underlying code is still there. You just have to reenable it with a registry tweak. https://www.tenforums.com/tutorials/14312-restore-windows-ph...
If I remember correctly, I still think Windows Photo Viewer was much better than ImageGlass. All I want to do is quickly browse through a couple of photos in a folder.
That argument wasn't convincing when it was made in support of the recent vulnerability added to the "colors" NPM package, but I can still imagine people claiming that hijacking users' IP addresses is not harmful enough to count as malware.
It's quite another thing to say "there is no warranty" under the idea that you shouldn't trust me, since I could suddenly decide to turn around and start taking advantage of you and your naïve trust in me.
I find the first kind of attitude acceptable and reasonable. The second is basically an anti-good-will, pro-aggressor view of the world, which I emphatically reject and hope becomes increasingly unpopular.
[1] S.W.A.G.
However, distributing GPL code along side proprietary libraries that are dynamically linked together on the user's machine is allowed.
> For example, Corresponding Source includes interface definition files associated with source files for the work, and the source code for shared libraries and dynamically linked subprograms that the work is specifically designed to require
The great news is we are not processor or memory heavy. In fact we don't compute anything local on machines and the bandwidth we use is the equivalent to downloading a few images. We sponsor projects to help developers and keep software free. We all know that software takes hundreds of hours to develop and maintain, so symbiotic relationships are good for the community.
We always require disclosure and being upfront with users. We require an informed decision on the part of the software's user. I am happy to answer questions about how Spider works. I can assure you we are GDPR compliant, we don't care about collecting user data we only gather data that is publicly available online about products and companies from public facing websites.
Wow, this thread is like 35 minutes old and people are already jumping to conclusions, bashing the developer, bringing out the torches to burn them at stake.
Really disappointed seeing this on HN...
Perhaps the title itself is insinuating, and people are not patient enough to dig any deeper. Perhaps someone can add [quickly reverted] or something to the title?
That being said, I really wonder why people 100% believe other people act in bad faith. Looking into that Github issue (https://github.com/d2phap/ImageGlass/issues/1252 ), it feels more like the dev was not aware of the issues with the bad actor in question, and was also very quick to revert the issue and pull the affected release from Github. This is the best someone can do under this situation, and I'm sure they must have felt quite stressful... Maybe they are, even now, feeling the stress if they stumble upon this thread.
If the dev reads this: You did a great job fixing the issue, congrats!
Toxicity like this kills many projects and dreams, by the way.
EDIT: My argument rests on the assumption that the dev was acting in good faith. If it is proven to be otherwise, I will gladly retract my statement and apologize.
That he reluctantly reverted the change only when people noticed and called him out on it is not particularly honourable or worthy of praise.
> Partner shall ensure that only Users who have expressly agreed to become nodes will actually be marked by Partner as such (…).
It's not uncommon for people to put obfuscated malware into open source code See: hackers putting cryptominers and wallet stealers [0] into compromised NPM packages, or UoM campus being banned from contributing to Linux for backdooring the Linux kernel [1].
[0] https://www.trendmicro.com/vinfo/dk/security/news/cybercrime...
[1] https://www.theverge.com/2021/4/30/22410164/linux-kernel-uni...
He's shown such a fundamental misunderstanding of the trust that was placed in him. He knowingly merged _malware_ into his software and then did the minimum amount of plausible deniability (a discord poll that 99.99% of his users don't access, and an opt-out buried in a menu).
I disagree. Let people learn from their mistakes.
> ... to contribute to software that isn't subject to someone else's review.
That's hard to do when it is the author's own software. This "someone else must be lord and master" solution often doesn't apply to reality. Also, I've seen entire companies full of bosses managing people who "are not to be trusted" to do the right thing eventually end up doing the worst possible evil. Let the author learn, and move on.
> He knowingly merged _malware_ into his software and then did the minimum amount of plausible deniability
Or he asked his most active users, and they said it was fine as long as I can turn it off. Who knows... To assign any intent other than to make some money would be assuming a lot of facts that are not in evidence. The good guys won on this. Let's move on to actual problems instead of punishing someone for learning.
I'm interested in finding out to what degree you hold this viewpoint. How severe do the negative consequences of an action have to be where you would switch from saying "let them learn from their mistakes" to "we can't trust them again".
(I'm honestly interested in knowing, this isn't just a rhetorical statement.)
Regarding crime, there a lot of behaviors that aren't legally defined as crimes, but are still objectionable (sometimes very). As such, there is no court to prosecute them with the legal system's presumably objective processes, so it's up to the general public to make our own assessments.
Finally, I'm curious as to your level of tolerance to questionable, unexpected behavior by software developers. Maybe not this one, but I wouldn't be surprised if there were certain actions by software developers where you wouldn't tolerate even a single offense. In any case, our differences regarding tolerance to questionable behavior is why we're all discussing this incident anyway.
Like, I dunno, but if someone decides to feed my dog a KitKat, I probably wouldn't trust them around my dog anymore, you know? Yeah, they've learned their lesson about dogs and chocolate, but what other stuff don't they realize?
If you feel like that is appropriate, you could do that. I'm just glad the author removed the malware, and hope he's able to find a way to make money that doesn't involve a commercial botnet.
Actions have consequences and this is a natural consequence, not a punishment. Trust was broken and users are not bound to prove the dev was in bad faith. The dev broke the trust and they can try and prove adding malware was done in good-faith if they wish. If the dev didn't care or _understand_ the severity of this change, then I have no problem if the project dies, gets forked, or whatever.
The idea that, at some point in the future, the developer will make a token effort to notify his user base before doing something against their interest is enough to make me not want to use this developers software.
They though they could be smart and slip in a malware quietly without anybody checking, which was pretty bad executed because literally anyone can see the commits.
You don't just accidentally type in a full line introducing a malware that IS of common knowledge ("Oh sorry my fingers moved on my own! I didn't it was a malware!!"), that doesn't exist, there is no sugarcoating, this was absolutely evil intended, stop painting as clean innocent what is visibly dirty
There is no way this was a good faith move, you don't expose your users to liability like this without informing them clearly and making it opt-in.