Popular open source project Moq criticized for quietly collecting data
bleepingcomputer.com
bleepingcomputer.com
I simply cannot understand why someone, especially the author, would think this is a good idea. How can you not predict this will create a backlash and push users away?
> I discussed this approach with fellow developers and it sounded unanimously reasonable.
Who would think that entering a GDPR/CCPA hellhole of PII collection is "reasonable"?
Because it earns money. Money talks and bs walks.
The guy's got a valid point, especially as many Big Tech companies are using it, but this is a massively fucked up way to go about it. If you're going to do this, what else are you going to exfiltrate under the guise of open source sponsorship?
Pin to 4.18 until you've got a migration plan.
Trust has been completely destroyed. What if the next malware attempt isn’t discovered immediately? Anyone continuing to use Moq is opening their company up to possible litigation.
Anyone know of a good drop in replacement? Internally we’ve gotten the ok for our next release to continue with this software pegged to a pre 4.20 release, but we’ve also been given the directive to “dump this guy” as soon as possible.
I've favored Moq in the past because I think there are a couple of things it makes a bit easier or is a bit less opinionated about, but NSub is perfectly cromulent as well.
Someone posted a quick guide to migrating a bunch of it easily in one of the issues in the Moq repo discussing this whole mess: https://github.com/moq/moq/issues/1374#issuecomment-16712411...
...because it completely broke builds on macOS and Linux [0]
https://github.com/devlooped/SponsorLink/issues/9
https://github.com/devlooped/SponsorLink/issues/13
https://github.com/devlooped/SponsorLink/issues/16
And the original blog post.
https://www.cazzulino.com/sponsorlink.html
His opinions make me feel a bit worse that I went for Moq for work-related projects.
That's really assholish