Goodbye, Sourceforge
helb.github.io
helb.github.io
These "mirror" (MITM) pages outrank the authoritative sites for many projects because Sourceforge has been around for 10+ years and has superior trust/backlink profiles compared to the newer author-blessed sites which presently host the software. Gimp is actually fortunate in this regard -- gimp.org is stickied to the top spot when searching [gimp] and Sourceforge floats around #8 or so.
Sourceforge should get hit with Google's standard penalty, which is "we smite your rankings with the hammer of an avenging god." Minimally, Google should at least tighten up their enforcement of AdWords policies. Their "installers" are per-se violations of the Unwanted Software Policy (http://www.google.com/about/company/unwanted-software-policy...).
How about it, resident Googlers?
The Usenet group alt.comp.freeware converted several people to the idea of open source by having links to sourceforge posted there.
It should just die.
https://web.archive.org/web/20010418143406/http://sourceforg...
On a side note, looking now at their Wikipedia page, I'm shocked to see that they only started in 1999. I would have place them a year or two earlier in '97 or '98. Anyone else feel this way?
I can't wait for the new package manager in Windows 10, though.
From what I understand, it's more of a "package manager-manager" so it manages other systems (like Chocolatey) rather than running the repos itself.
In the meantime, I'd drop $5 on Hitman Go: http://apps.microsoft.com/windows/en-us/app/hitman-go/5fa3bb...
and a donate button at the bottom of the front page. I wonder how much money that can generate though.
Pretty similar to npm.
I tried to make a package for a simple binary last year (I believe it was premake4 or something). It was annoying to use, and other software I installed with it didn't have an uninstall option.
Package managers make me happy (love Homebrew on OSX), but I don't see a point if I can't also uninstall. I rarely install things from sources that need vetting.
Yes, GitHub can use the domain attribute on a cookie to prevent this, but then you have designed a system that will fail open if you mess up. (i.e. potentially malicious user content would always be able to access a cookie, unless GitHub does something).
Better to just stick it on a separate domain entirely, and this is a commonly used practice. For example, Google does this with their googleusercontent.com domain
// GitHub, Inc.
// Submitted by Ben Toews <…@github.com> 2014-02-06
github.io
githubusercontent.com
Apple/Google/Microsoft/Mozilla use this list to restrict cookies -- foo.github.io can't set a cookie for github.io, even though it normally would be permitted. This list is also used to highlight the address bar, so "foo" would be emphasized, rather than "foo.github".You either die a hero or live long enough to become the villain.
See there: https://forum.filezilla-project.org/viewtopic.php?t=31127
"This is by design. In any case, nothing is forced upon you, all offers are entirely optional and are only being displayed during setup."
It's just a fact of life that open source software won't make you rich. Either they are ok with it, or they create a commercial product from the start. But adding crapware afterwards is not a proper solution.
Bad people do bad things. Paying or not paying has nothing to do with it.
Would these companies change if their only source of funds was the malware? I don't think so.
Proprietary software can do whatever it feels like on your computer and you would be hard pressed to know until it was too late.
A few large companies have been implicated in root-kits / backdoors / random horrible deliberate security practices. These are probably just as destructive as replacing your browser search bar or installing some fake AV software.
Free isn't the problem. Bundling crap-ware with otherwise audit-able open source software is the problem.
"Whether passwords are stored encrypted or in plaintext
makes no difference in security."
Just... wow.For the same reason, Pidgin and many other IM programs also do not encrypt the password.
It doesn't stop every attack, but it's not useless.
Outside of enterprise environments, most windows installations are single user. Even if it's a multi-user system, the data would already be protected by NTFS permissions if it was stored in the user's profile folder.
>as well as protect against offline reading of the files
no, it doesn't[1][2]
[1] http://passcape.com/windows_password_recovery_dpapi_decoder
Still should go with the browser/password manager approach of using a master password to decrypt the password database.
Software that encrypts passwords without a master password are just selling you sneak-oil.
Strange, almost every comment on this page say the crapware was added by SourceForge, e.g.
> The offers are added by SourceForge, they are borderline crapware to put it nicely.
The FileZilla developers have never been very vocal about this so most of their comments is a generic "Nothing unwanted is being installed without your consent", but they are the ones who have accepted to add the adware. And even though they also have clean installers, they put the ad-enabled link first.
I remember signing up for an account years ago and having to use Putty and SSH keys to upload data which was revolutionary to FTP-aware me. There was an awful lot of software on there (who remembers visiting freshmeat.net to look for daily updates or search for software too????) but I think it would be sad to not realise how great it was that they offered free hosting and tools. They used to have a compile-farm that you could use to build software on different platforms and architectures but this got retired a long time ago.
For the free tools you got, it wasn't bad! I think "nerds" are quick to forget that. It was FREE
I wonder if it would be possible (and legal) for somebody who isn't the project owner to copy some of these unmaintained projects into another system?
(I remember they had a dozen Java MVC frameworks 10 years ago tho)
Each Contributor hereby grants You a world-wide, royalty-free, non-exclusive license ... to use, reproduce, make available, modify, display, perform, distribute, and otherwise exploit its Contributions, either on an unmodified basis, with Modifications, or as part of a Larger Work;
So the answer (at least for Saxon) is yes! Just make sure you conform to the licence requirements and you're good to go.
Why? Because SF have proven if I were to do so they'd take my work under my name and bundle their crap into it. The only way to stop that is to keep it active.
That feeling of being trapped into a terrible system because it'll screw over people even worse if you leave.
Oh, is that a thing? I was surprised when the Lobo project's admin rights were handed over to some relatively unknown developer. I had a long and confusing discussion with the new project admin here: https://github.com/UprootLabs/gngr/issues/87#issuecomment-86...
These are two popular mirrors in the UK & Ireland (both academic institutions):
http://www.mirrorservice.org/ (University of Kent)
http://ftp.heanet.ie/ (Ireland’s National Education and Research Network)
I remember the "BerliOS" from a Germany's Fraunhofer institute that was a kind of clone of Sourceforge, a open source project hosting service. It was closed in 2013 and some valuable code and binaries are lost forever.
About Releases: https://github.com/blog/1547-release-your-software
An example: https://github.com/adobe/brackets/releases/
As for mailing lists, I guess their excuse is that they already provide possibilities for discussion in the issue tracker (which can be also interacted with entirely by mail). This is appropriate as a forum for developers - but not a forum for users, which would be out of Github's scope, IMO.
Help if you can, it's fun! #archiveteam on EFNet.
Unfortunately, short of registering a trademark with the PTO, it'd be difficult to get a lot of this crapware removed from SF.
About that help/helb confusion mentioned here – sorry about that, it's not intentional, it's just my nickname since 2nd grade or so.
I'd thought Collab.net ended up with them. Need to review the history.
May be important to some legacy projects trying to get off of SF.
It's sad that with Google Code going away, a lot of projects that chose Google Code for Mercurial are being pushed to switch to git (e.g. vim) because Google is pushing so hard for projects to be migrated to GitHub,
They haven't injected their own installer on downloads so for the time being I leave it there because I'm too lazy to move it off.
A while back I did move the main project page to its own domain, so I'm only really using Sourceforge for downloads and source control (although the project is stable and hasn't had commits for a long time so not even that really).
Hopefully, this will hit a chord with enough projects that they will altogether stop using sourceforge.
Two nights ago I went to a "bleeding edge web" meetup. I was really struck by how universal, unspoken, and simply taken as a given it was that modern web development is done on a Unix box. Thus there was no room for any discussion about Windows alternatives, or even explanation for us third-worlders about what role certain tools - that at least I had never heard of - play in the ecosystem. I was completely alienated.
Unless you're coding for Windows only (eg C#, .Net, etc), Windows is the red-headed stepchild of development environments. I'm somewhat hopeful that this will start to change with the release of Windows 10.
Does anyone have any recommendations?
No, SourceForge was always sleazy.