- Cross-Internet reputation system for accounts
- Small fee on submission
- Cross-Internet reputation system for accounts
- Small fee on submission
This will immediately bias the submissions only coming in from the west. Remember you can make the fee small but sometimes a person can't even pay even if they have the money. I remember having the 1000 or so rupees required for some VPS stuff when I was a teenager and not being able to pay since I didn't have a credit card. I hope we don't ever make money a barrier to open source.
I doubt it.
It's easy to get a Visa/Mastercard in the US. It gets a bit trickier in some EU countries. Then the further from the west you go, the more complicated it gets, all the way down to impossible if you live in a place that the US isn't on friendly terms with (like Iran or Russia).
If you auto-assume everyone can pay any amount online (even if it's a refundable $1 for verification purposes), you're gonna cut off access to a lot of people unintentionally, while only raising the bar a little bit for spammers.
Then make some other very cumbersome proof. But it's still better to cut off half the world from open source than pollute the few large software repositories with spam, which would dissuade everyone everywhere from contributing eventually. There's no problem contributing to a library from anywhere it's just that you collaborate with someone who in turn can pay the reg/anti-spam fee.
The reason money is natural is because there is a cost associated with manually vetting all packages.
Gets rid of anonymous spam.
> - Small fee on submission
Gets rid of amateur spam.
I guess that's 98% of the problem. I think this is a good start.
What to do about bogus projects sponsored by wealthy companies? What about abandonware? And how do we remain open and inclusive to newbees?
Does this happen in the real world, rather than as a theoretical concern?
As a thought, when a problem is pressing then sometimes it's best to start with a reasonable action then course correct over time. Rather than doing nothing waiting for a perfect solution.
Heck yes. 99% of the stuff advertised to me in big money advertising campaigns is stuff that I will never want. If that doesn't count as "bogus projects sponsored by wealthy companies" then I don't know what does.
So, similar to Twitter's blue check mark - Yes, asking a "small fee" adds friction, but it's not an obstacle to the wealthy.
Unfortunately, that last one deserves a special Fuck You to the main developers of FileZilla, who have knowingly bundled malware for years. :(
For anyone that doesn't know about it, here's a forum thread about it they haven't deleted:
> I guess that's 98% of the problem.
No, that's 99.99% of the problem. I've never even seen "bogus projects sponsored by wealthy companies" in volumes where it would be considered "spam".
> What about abandonware?
Grandfather in old projects.
> And how do we remain open and inclusive to newbees?
Everything is still open and inclusive - anyone can publish a repo on GitHub for free. Using a reputation system or a small fee for submission is a very reasonable means of controlling access to a centralized online repository.
Real fee will scare away almost all amateur developers and almost all professional developers who don’t already have a business account available.
What happens to the international developers who cannot easily get a payment method setup?
Does a $10/m "identity verification" stop a nation state from using the platform to influence?
Micropayments on internet have always proven difficult to implement. No silver bullets.
It also attaches an identity to the posting.
Anyway, involving humans (funded by NPM's commercial revenue) doesn't reduce the options to "letting the spam happen and dealing it after the fact" or "holding all submissions until a human reviews [them]".
If I was trying to solve this problem, I'd be open to a solution that tried to automatically classify submissions as either legitimate or spammy, with an associated confidence level. If the confidence level fell below a given threshold then I'd involve a human.
Every paper should be reviewed manually. Of course that costs some money (although the reviewers aren’t paid).
https://www.google.com/search?q=stackoverflow+review+queue&t...
(The overall lack of quality control on npm is a separate question)
Wait, I may have been overdoing it with root cause analysis again.