GIMP-Win project wasn’t hijacked, just abandoned
sourceforge.net
sourceforge.net
Once again reposting what I said in the other thread (which seems to have been modded off the frontpage, sad).
I'm one of the lead devs of LXQt and an LXDE sysadmin. We use Sourceforge for our mailing lists and some LXDE legacy stuff.
I'm absolutely sick of them. It's not the first time this has happened. I've been pushing for us to move off SF for a while and this is a good occasion to push for it harder.
I've sent an email [1] detailing plans to move. I am urging everyone who still has projects on Sourceforge to do the same.
If you have similar migration problems to solve as the ones I've highlighted in the email, please contact me directly and we can share the workload. My email is available on my Github profile [2].
[1] http://sourceforge.net/p/lxde/mailman/message/34148903/ [2] https://github.com/jleclanche
> I have read and agree to the above terms , and agree that if I ask FreeLists for email addresses or send SPAM using their resources, they have permission to inflict severe pain on me with large, blunt objects.
[emphasis mine]
In fact, I wish anyone would do that. I've had detailed plans of what a service like that would look like for over two years, and no time to take a stab at it myself. If someone here is actually interested, feel free to contact me.
Everyone wants to jump in on the blog-engine space and invent their own blog engine (I'm guilty of this myself).
We need more people to jump in on the mailing-list/forum type products.
But like a lot of successful people will tell you, if you want to be successful too, solve the dirty problems.
Voting isn't generally a feature you want for discussions - voting provides visibility over a short period of time, and then the topic dies off, which is a very big issue with reddit-likes being used for discussion. Newcomers to a highly popular topic are on equal footing with the rest of the participants, while on Reddit/HN the topic is overwhelmed and only the highly popular, old comments get visibility.
This is very suitable if you don't want everyone to have equal footing. For example, discussions centered around video games, politics, social issues, etc. For open source it tends to be bad. This is an off-topic meta-discussion I'd love to take further, in private, if only it'd take me a click to do so. :)
If I remember correctly, that's actually one of the continuously rotating suggestions on below the button on their home page.
It was originally built for sizable coworking communities but is pretty decent. Mail integrated, daily digests, etc.
Still a WIP but pretty mature at this point.
Those prices are really high too for what it presents itself doing. And I don't care about all the people talking about how awesome it is, really I don't. Show me the sausage.
If this project wants to go anywhere it's going to have to severely review its strategy.
150 members before you're in the "if you have to ask you can't afford it" bracket -- even small, niche projects would have more people than that subscribed to the announce list -- and that's $129/month. You could run a majordomo list with no member limits on a VPS for less than $10/month.
[1] http://gna.org/
Then there is the spam. Once targeted the spam can get really bad. Meteor JS suffered this and moved to the open source forum software http://www.discourse.org.
One option is to migrate away from mailing lists and towards something like a forum; but forums, while they provide very low barrier-to-entry, produce a fundamentally terrible user experience. (Yes, including HN. This text box I'm typing into is an embarrassment.)
What I'd really like, I suppose, is a service which provides an easy-to-use web forum with an SMTP gateway for those people who hate forums. And then have it all hosted via my project website so that I don't have to redirect people to some dubious third pary site. Bet I'm not going to find one, though...
Where is that other great free service which hosts large binary assets, web sites, wikis, forums, and trackers i.e. everything you need for a project.
Github is only a solution for software without meaningful binary assets where the user is expected to build the software himself and no community interaction beyond pull requests and issue reports is desired.
There is no free alternative to SF for many users, that is the problem. And well, "free", that is the key word here, at the end of the day SF has to make money somehow. As a non-paying SF user I cannot really complain about ads.
I have no experience with them, but I've seen some projects using Bintray:
Apparently, they have some integration with GitHub as well.
So this is a broken model that Sourceforge entered itself into. You absolutely can and should complain that a service has a broken business model resulting in a horrible user experience.
I'm not sure if that model would make people happier.
GitHub Releases addresses this (i.e you can release compiled binary assets as your "release", rather than just an archive of the repository). Also, GitHub Pages is pretty useful if you want to build a user-facing site for your project.
edit: typo
Throw up an nginx install to forward part of the site to github, and downloads direct from disk, and you have a nice - and fully customizable - project setup.
Edit: doh, I didn't realize they had been sold off already. Never mind. :)
1) There is nothing clear and open about the project being abandoned by the author
2) The author left SourceForge due to their business practices and this allows SourceForge to take over the repos and continue making money?
3) Is SourceForge just going to maintain any project that leaves them and makes a mirror?
The sad state of Download.com and SourceForge keeps getting grimmer and grimmer.
The search hijacker that came with my copy of FileZilla Server was the first such infection I've had in a decade.
Ninite.com is a great resource for getting tools like this (and things like Chrome, Firefox, etc) without all of the packaged adware.
I use it almost exclusively to get all of my dev tools on a Windows machine.
I typically use the Ninite installer on a clean, freshly installed Windows machine because the installer can be ran again in the future to update those same apps. Chrome/Firefox/etc. will auto-update themselves but for those apps that don't, they will be updated to the latest version if/when you re-run the same installer that you originally downloaded.
It makes it handy to keep the 'installer' that you download, as it will go through and update all of the listed apps later on.
Disclaimer and full disclosure: I am not affiliated with them, just a happy user for many years
Doesn't GPL have to say something about this? Wouldn't this mean that the adware would need to be open sourced?
Edit: The difference between murder and manslaughter has now been explained, multiple, multiple times. Manslaughter is still a crime and in that way it is still the same. The comparison was used as a device to elaborate why the reasoning was unimportant, the difference between murder and manslaughter isn't important within that context. Suffice to say, now that I have been corrected repeatedly over this nonsense, this would have been a better anecdote:
> "I killed him because he slept with my wife" doesn't change the fact that you killed someone.
[1]: https://en.wikipedia.org/wiki/Murder_(United_States_law)#Deg...
No. The adware is part of the installer, and is considered separate by the GPL:
http://www.gnu.org/licenses/gpl-faq.en.html#GPLCompatInstall...
"By sending or transmitting to us Content, or by posting such Content to any area of the Sites, you grant us and our designees a worldwide, non-exclusive, sub-licensable (through multiple tiers), assignable, royalty-free, perpetual, irrevocable right to link to, reproduce, distribute (through multiple tiers), adapt, create derivative works of, publicly perform, publicly display, digitally perform or otherwise use such Content in any media now known or hereafter developed. You hereby grant the Company permission to display your logo, trademarks and company name on the Sites and in press and other public releases or filings. Further, by submitting Content to the Company, you acknowledge that you have the authority to grant such rights to the Company. PLEASE NOTE THAT YOU RETAIN OWNERSHIP OF ANY COPYRIGHTS, TRADEMARKS AND SERVICE MARKS IN ANY CONTENT YOU SUBMIT."
This does not appear to include the right to use the trademark in installers, as an installer is neither a site nor press release, etc.
I assume the name GIMP is trademarked and it is creating user confusion that the actual GIMP organization is backing that installer.
As far as I can tell, there's no formal "GIMP organization".
By the way, the trademark you mention was Caughron, Mathew K. INDIVIDUAL UNITED STATES, who seems to have been responsible for the old WinGIMP and MacGIMP distributions that cost money.
Hate, well, love to be pedantic, but it actually it does matter.
Courts and society alike take the reason for a murder (e.g. self-defense, revenge because of having been abused, being crazy or intoxicated etc.) into consideration for less harsh sentences or even acquital.
Intent and reason is quite important. It is the difference between receiving no punishment and receiving the death penalty (in places that still have it).
I get it. The anecdote had technical issues. Not-with-standing that being technically correct is not what anecdotes are about in the first place.
One way this happens is.... people open HN, click on a few links to open them up in tabs, then get distracted by work or other things.
An hour or two later, they don't refresh the page and just make comments based on what they see.
I'm guilty of it too sometimes.
Honestly. I respond as I read. I tend not to keep reading and then go back to respond.
>Not-with-standing that being technically correct is not what anecdotes are about in the first place.
This is more than a mere technicality. The whole issue of mens rea is that one's state of mind is a factor is how someone is judged for their actions.
Your point, even without the analogy issue, is that the reason is irrelevant. That is simply not the case. Putting a security flaw in place to give the FBI a backdoor is vastly different than putting a security flaw in place due to poor coding. You may say they are both the same in that they both compromised security, but only one of these is backdooring and the damage to one's reputation is going to be different.
Now, in this particular case, the reason isn't sufficient to warrant a different judgment. But that is because of the details of this case.
That it is open source does generally allow anyone to do this, right?
But yeah, Sourceforge sucks.
Their malware is open source?
That's why the typical workflow is to say in the header of your GPL license "Foo is copyright John Doe... Permission to modify is provided ..."
Sourceforge may be allowed to redistribute software with malware but as far as I can tell, copyright law should stop them from calling the software by the same name, right?
Does the author have a copyright on the gimp-win name? Maybe I don't understand the law correctly though, IANAL, etc.
That's trademark, not copyright. Though I believe some free/copyleft licenses allow you to require a name change if they make changes.
Copyright doesn't apply to names. That's trademark laws. Contrary to copyright, trademarks have to be registered and cost money. There is no registered trademark for Gimp or gimp-win in the US or Europe.
Trademarking the name of your project is considered incompatible with Free Software by a number of people. It's one of the issues that lead to the creation of Iceweasel, after Mozilla Corporation told Debian to stop distributing their builds of Firefox[1]. The issue also resulted in RMS telling people not to use Firefox.
But if we go back to the _point_ of open source, especially the GPL: It's to let users keep using and modifying and distributing modifications to the software, without needing the permission of the original authors. That's the whole point, for users to have that freedom, that the authors can not take away from you. That sourceforge can keep distributing the software without the permission of the original authors is the entire point.
To the extent that trying to prevent third parties from using the name makes it harder to distribute the software (for instance, would it require changing the source to take the name out? Would it make it harder for users to find software that the authors are _trying_ to suppress?), I think we could argue that it would be against the spirit of the GPL, regardless of what trademark law says.
Well, why not?
YCombinator also invested in a company that did this.
http://www.istartedsomething.com/20130115/y-combinator-is-fu...
Here's pg's response:
>2. The apps that get installed are "crapware."
>This one seems a matter of opinion. A lot of the world's most popular apps and sites seem like junk to us. But the users are choosing to install these things.
What systems are in place to prevent this from happening with package manager systems like apt-get, yum, or even npm? How often do we just blindly "sudo apt-get install blah-blah blah"? I know I don't read the dependencies.
I wonder if we will see more of it as distros move to Snappy or similar schemes. I guess it will come down to how "frameworks" gets handled etc.
Distributions don't typically package and distribute malware. And everything packaged in a distribution should be removable via the same package manager that installed it. So, while you might get a package you don't want, that package won't start showing you ads or harming your system, and you can always trivially remove it.
There aren't any technical measures in place to prevent this. Imagine the backlash, however, if any Linux distribution decided to do this.
https://threatpost.com/microsoft-to-detect-search-protection...
Then you say:
> 2) The author left SourceForge...
Pretty sure if you left SF with the project still up on SF, any reasonable person could consider that abandoning the project. A more responsible thing would have been to remove the project entirely and shut it down.
> 3) Is SourceForge just going to maintain any project that leaves them and makes a mirror?
I assume you mean the only obvious option is to remove the project entirely (or disable from view) for those that leave. Leaving up old code at the scale of GIMP has the potential for leaving up unpatched code that is still downloaded and used. If your opinion is that nothing should have been done at all, I think that's far worse than what anything SF did.
https://sourceforge.net/u/sf-editor1/profile/
It is part of their "mirror directory" project, which seems designed merely to get traffic from popular Open Source software, and occasionally inject malware into downloads that they can dupe people into getting from SF.net rather than the authoritative source.
And, of course, in this case, the author of Gimp-Win has plainly stated they did not abandon the SF project. They were locked out by SourceForge staff.
I'm all for caution before reaching for the pitchforks and the torches, but there's an awful lot of very large, very credible, projects saying, "Yes, SourceForge did this to our project."
I sent them an email yesterday asking for clarification, but have not received a reply.
Here is the list, http://sourceforge.net/u/sf-editor1/profile/ http://sourceforge.net/u/sf-editor2/profile/ http://sourceforge.net/u/sf-editor3/profile/
https://mail.gnome.org/archives/gimp-developer-list/2015-May...
I'm thinking something along the lines of, "Don't like the way services like SourceForge are handling your project nowadays? There are better services to use; here's a list. Obviously, we'd like you to use ours. We've already set up a home for you on our service in anticipation of your stay with us, which we think you'd enjoy. You'll find that it's already fully furnished, even. Here are the keys. Give us the go-ahead and we'll aggressively pursue the takedown of badware distributors."
The benefits to any of the three who go for this plan would be the host's association with such high-profile projects. GitHub may look at this and decide that at this point in their trajectory, there's just not enough in it for them, but it seems like either GitLab or Atlassian could benefit from it.
This is about aggressively courting existing projects that may still be on SourceForge out of nothing more than inertia. Migrating away is a process, even with importers. My original comment was about surveying the landscape for potential candidates that you'd like to see using GitLab, and then go ahead and set up a home for select projects before approaching them. This could include reserving accounts for the core developers, pre-seeding the project with whatever importing would be required, and just generally making it stupid-easy to migrate--as easy as just saying, "yeah, okay; we'll do that", and then setting up their password.
If you're worried about doing anything with their blessing, this could all happen in such a way as to not be publicly accessible until the project actually gives the go-ahead and confirms they would like to make the switch.
For desktop software, I'm more concerned after hearing of projects being wrapped in Adware/malware. This is a particular problem on sites like http://download.cnet.com. I've been online since at least 1996, and those sites used to be great to be able to find useful software. Now, I prefer to not install much new software, in order to keep a stable desktop (and it does work - I've only had to wipe my desktop and install Windows from scratch once or twice in my entire online career, I get new PCs more often).
I've even seen jobs posted on some sites to work on open-source code - but then the project is hosted on sourceforge.net, and so it is using Subversion for version control. While I may be expert on the underlying technologies that particular project used (and the language) - its not something that would ever convince me to help them - not even while being well paid (and working remotely, which is what I'm aiming to do from now on).
Let's put this in context: SourceForge was once (this was many, many years ago) a deeply trustworthy entity. They were excellent stewards of Open Source projects. They consistently took guidance from the community, and wouldn't have chosen profits over users or projects (though, certainly, they've profited).
Markets change, leadership changes, acquisitions happen. One day, we may not recognize github as the entity we know today, just as we don't recognize the entity that SourceForge has become.
I'm not saying don't move to github. Obviously, nobody should be starting new projects on SourceForge and github is one of the better third party alternatives. But, it may be worth thinking about what happens when we as an Open Source community build up another SF.net like entity. A central repository for all the most popular Open Source software, controlled by one profit-driven corporation.
Maybe it was worth the tradeoff. Maybe SourceForge provided enough value over the years to where it's not worth belly-aching about having to rebuild our communities around new tools (maybe even another third party tool), and to educate users that SourceForge is now an untrustworthy provider that should be avoided. Maybe we have to just mourn the loss of a once great supporter of Open Source software and move on to another that will likely, someday, also turn its back on Open Source values in pursuit of profits.
I hate trash-talking SourceForge so harshly, as projects I've been involved in have been well-served by SF.net in the past (and even now, we're pushing out terabytes of downloads through their mirrors, even though we've moved our revision control to github long ago). But, the company as it exists today is nothing like what it once was. I must assume none of the original founders remain given how far this strays from the original vision of the thing, and certainly it's been through multiple acquisitions and leadership changes. Maybe I shouldn't feel so bad about it...maybe the SourceForge I knew has been dead for years, and I just didn't notice as it's taken a while to start to smell.
In the age of cheap bandwidth and cheap servers, how is this not massively profitable?
Makes me pretty sad since I still remember the days when SourceForge was one of the good guys.
https://en.wikipedia.org/wiki/Geeknet#Initial_public_offerin...
http://www.nytimes.com/1999/12/10/business/a-tiny-company-wi...
If they just mirrored the project, no one would be complaining. Having another place to download copies of the official releases is a good idea.
The issue is they changed the release. They advertised it as "mirror of Gimp-Win version X". And it wasn't. It was Gimp-Win version X with a boatload of adware / crapware. This made the Gimp-Win people upset that the crapware was being falsely associated with their product.
If SF had advertised it as "SF Version of Gimp-Win with magic crapware", people would be less upset. And fewer people would download it, of course. Which isn't what SF wants.
Their self-serving statement about "mirror" is a lie. The people who wrote it should be ashamed of themselves.
How this was done was wrong.
SF writes: "Mirrored projects are sometimes used to deliver easy-to-decline third-party offers, and the original downloads are always available."
It's wrong because it's disingenuous - an insincere representation of the GIMP maintainers package, to include adware in the package.
SF insufficiently differentiates this "gimp-win" project with the small, coded byline: "Brought to you by: sf-editor1" (http://sourceforge.net/projects/gimp-win/files/)
Let's be blatant and honest: this is "SF-GIMP" not GIMP. It's being operated here under the guise of the authors and currently not sufficiently identified as a fork.
SF skirts "adoption responsibility" by simply writing a post to some unrelated blog article after the fact and create a collection of unrelated "deceptive ad blocking" website tools.
RECOMMENDATIONS TO SF:
* Be up front and bold about "adopting"!
* Free software or not this adoption stinks!
We welcome further discussion about how SourceForge can best serve the GIMP-Win author.
Just stop. How disingenuous can you be? What a disgrace.
Do we really need to go there? Ok, how about: "completely suspend and remove the project, and don't let the name be reclaimed."
Source Forge is trying to convince us they never thought of that. Really? Give me a break. You knew. You just don't care. Fine, you don't. But don't try to play that off as ignorance. "Oh, yeah, please enlighten us with further discussion!" Get out of here, stop wasting our time.
They could just as well have done away with the blog post and put up an image of a giant middle finger, instead. At least that would have been honest.
RubyForge folded and the world was better off.
My employer runs a sourceforge mirror – i am going to start some discussion if we can turn it off.
Also, old HN post on "what happened to Sourceforge": https://news.ycombinator.com/item?id=6700115
Please do. IIRC, most (all?) of their mirrors are provided by third-parties who are graciously offering their resources and SourceForge is taking advantage of them to serve up and profit from adware/malware installers.
"Hey, this isn't a SourceForge project! Check out the SourceForge Open Source Mirror Directory for more information. " -> this links to a page that explains in detail what you are getting.
I don't have a windows installation handy so I can't 'test' the SF installer to see if the adware or add-on programs are easy to identify and accept or refuse -- has anybody tried that?
[1] https://deals.slashdot.org/?utm_source=slashdot&utm_medium=n...
Would be interesting to see if Slashdot posts this story.
This has to be some prank, they can't be serious about that.
You'd think that if they really cared, they would back pedal on what they did, but no, instead, they double down by trying to justify what they did and "welcoming further discussions".
Also, this:
> deliver easy-to-decline third-party offers
How about delivering third-party offers that users need to opt in instead?
Terrible, terrible company and organization.
It's as if they know the majority of experienced users would decline those "enticing" offers.
The newish anti-spam measures in the Netherlands actually forbid the 'Yes I would like to receive spam' checkboxes to be pre-checked - has to be opt-in instead of opt-out.
[research ensues!]
http://europa.eu/rapid/press-release_MEMO-11-675_en.htm see (3) "Banning pre-ticked boxes on websites". I'm sure Oracle - or whoever - would argue that as the consumer isn't paying they don't have to abide by the regulation but Oracle are being paid to do it so I don't see how that's any better (in fact it's worse really).
> It appears that +SourceForge took over the control of the 'GIMP for Windows' account and is now distributing an ads-enabled installer of GIMP. They also locked out original owner of the account, Jernej Simončič, who has been building the Windows versions of GIMP for our project for years.
> We also got outed of our +VLC project on sourceforge...
> But it does not matter, we moved to our infrastructure a long time ago to our own, which is better and more powerful!
No.
> ... or was did the project just stop using Sourceforge?
Yes.
Good job SourceForge. A++ would never download anything from again.
So in other words, GIMP-Win was hijacked, just not by a 3rd party.
Please report the entire website, not just some project. They had distributed enough malware already.
Well, there's your problem.
What assholes.
Pretty sure I downloaded Synergy and it deceivingly downloaded a common installer which was small and installed adware as it downloaded the proper executable which you desired to download in the first place
1) wrapping the software in the sourceforge installer which includes adware. (That's what you mention).
2) having a page that looks like an official project page and distributing the software. This is bad for bla bunch of reasons, including 1) above.
However, recently, I cringe if I somehow end up at an SF link. Feels like I'm on the wrong side of the Internet and that I can't trust any downloads from them.
right.
I wonder... Is bundling adware installers with GPL software a violation of the GPL? (If not, should it be? v2?/v3?) Where's the installer's source? It wraps it in one linked executable file and presents itself as an installer for it, so I am not clear that any "mere aggregation" defence would hold?
There's also a reasonable argument that this brings the official project into disrepute: The GIMP may not be trademarked, but would it have to be?
Firefox, of course, is trademarked. I dearly hope they've never wrapped Firefox installers with adware, because Mozilla would not like that.
What is very possible is that if they integrated their installer into GIMP's installer (Since GIMP already has it's own installer), GIMP's installer is GPL so their modification would be a GPL violation unless they make the code available. If all their installer does is run GIMP's installer though, then there's no violation AFAIK.
It's not as if an installer is software worth protecting via copyright in 2015.
I would assume that adding in stipulations like this would actually be more of a hinderance. Who decides what is "crapware" vs legit software? I can see use cases where you would want an installer to install more than just 1 GPL app (ninite?) and I'm sure it has further implications...
It's a shame. Sourceforge used to be really good.
This is why popular open source projects should seek trademark protection on their names.
Sure, people get angry about Mozilla's protection of the Firefox trademark, but this demonstrates that there are legitimate reasons to trademark a name so you can protect it from malicious operators.
See: "The Non-Revocable GPL" http://www.groklaw.net/article.php?story=2006062204552163
Unfortunately this is not a reality or an option but it would be a good alternative.
Msys2 project gives a few of these apps as binaries. But it would be more user friendly if we could just download from a source repository and compile locally on windows.
Yeah, hijacked.
Sorry I must be missing something, what's wrong with "Upload a release asset" [1].
[1] https://developer.github.com/v3/repos/releases/#upload-a-rel...
I only recently found out release assets.
If you want something with more security guarantees, then use the walled-garden app stores. It reduces your chances of getting malware, but also reduces the choices available to you.
Whether or not people like what SF is doing does not change the fact that it is legal under the GPL. I hate adware myself, but if someone chooses to distribute it legally, then I respect their freedom to... and the only thing I would do is tell the users so they can make an informed decision. The official GIMP site has made a notice about this already.
As long as computing platforms exist which allow users to install any software, from anywhere they choose, they will eventually install something they don't want (and even in walled-garden app store environments they still manage to.)
Something to think about: "Freedom is not worth having if it does not include the freedom to make mistakes."