At work (Pootle), we're also moving our mailing lists away from Sourceforge. They were the last bit of SF we still used.
[2] https://onlinegroups.net/, https://onlinegroups.net/l/groupserver
We moved revision control to github several years ago.
We just haven't had time lately to figure out what to do about the SF.net malware situation, but I can't imagine we'll stay there for too much longer, given the circumstances. We don't provide a Windows installer, so we're probably not at any immediate risk from SourceForge practices, but it doesn't seem like a smart place to be, given their behavior.
I just don't see how this is a trick. There's not even a "default" option here, except for the Accept button being on the right. How can anyone possibly click the word "Accept" without even glancing at the text surrounding it - even a glance shows you the giant icon with the slogan "Mac Cleaner Clean Up Junk Files on Your Mac"? If you look at the bullet points, the first one clearly identifies what it does. So it's an opt-in screen. There's no default. The action word is "Accept" and the top bullet is about the additional software you would be installing, with a giant picture and caption showing the same thing. Or you can click "skip."
This is above-board if you're going to do this sort of thing. Hell, given how above-board it is I might just click "Accept" in this case! (knowing that the devs opted into it as well.)
It is very, very hard to read this as anything other than an opt-in screen. How can you be any less ambiguous??
EDIT: I didn't even notice, there is even grey small text that spells this out in completely unambiguous words! (Thank you for considering this offer from our advertiser...your choice does not affect installation of FileZilla.)
I honestly don't even know that I would ask FileZilla to change anything whatsoever about this screen. It's great!
> EDIT: I didn't even notice, there is even grey small text that spells this out in completely unambiguous words! (Thank you for considering this offer from our advertiser...your choice does not affect installation of FileZilla.)
Doesn't the fact that you didn't notice it make you at least pause?
I am ad tolerant. I do not run an ad blocker. If an ad is relevant to my interests I will click it. (I click maybe one ad every six months. I've never bought anything as the result of an ad.) And I loathe this kind of bundling.
We know that users are unable to read dialog boxes. Ask anyone who's worked in support about their experiences of getting people to read back an error message that's displayed on their screen. Every support channel on the Internet will ask people to post screenshots or to copy and paste the output.
IMO there should be an industry standard for how the screens should be worded, what they should look like, what buttons they can or can't include. Yes, we'd see many fewer people installing the malware but that's the point: no-one wants it. I tolerte ads but I see no reason to switch from Google supplied ads to some random adnetwork.
I should clarify that I was only referring to this screenshot - https://i.imgur.com/hNDdz4P.png - the other one is worse but I didn't notice ggp had an album of two (unless they changed it.) without the picture it would be a lot worse.
To be clear, I personally wouldn't mind advertising and installing software from an installer if some minimum criteria were met:
1. The software being advertised was actually checked by someone to confirm it had some use, and was not in fact detrimental to the users.
2. The accept/install button was not put in place of the button that moves the install process along normally.
3. A separate installer window was launched to make it obvious what was happening. No quiet background installs allowed.
What would be less ambiguous would be when you download an installer for an app then the installer installs that app and doesn't attempt to trick you in to "accept"ing what you think is the initial app install but is in fact an entirely different app.
If you really wanted to let them add apps people don't want then at the point of download an unchecked box could have an offer for unrelated software and that offer would state something like "software we're getting paid to have installed on your computer". That too would be unambiguous.
It's like someone offers you a bag of sweets and as you take them they say "you're fine with cryptosporidium" under their breath; you think they muttered some marketing slogan and instead you get ill from the sweets. Perfectly acceptable, you even had chance to find out what was in the sweets /s.
Aside: What's your startup?
Extremely distasteful.
When you ask someone about an irrelevant detail related to their status in the community while you are discussing something unrelated, it implies (quite strongly) that you are trying to change the topic from what is at hand to a comparison of credentials, and it also implies that you believe your credentials to be better in some way, somehow giving you an upper hand.
If you are truly independently curious about their startup, ask them separately.
But you were not (you admitted as much). So it's distasteful.
If you do google the specific thing being advertised (as I would if I wanted to know exactly what I was accepting) you would find something quite mixed. It has nothing to do with the format of the offer though (or with me.) It's like an ad. In the specific screenshot I linked, which is this one: https://i.imgur.com/hNDdz4P.png
Yes, I have no problem seeing offers in that specific format in my personal case as a consumer. No, I have nothing to do with any of these companies.
If one wants to ask a related question, ask a related question: "Do you bundle adware with any software that you distribute? If so, which software is that?"
An alternative I would consider "honest"? Hmm... "Support us by installing this bundled software" maybe.
And the fact that it is so unexpected is what makes this misleading. You're installing open-source software, on a mac, no less. You're expecting the bottom-right button to continue the installation. I don't know how you can't see how easily it is for a user to accidentally install this malware.
The only objective measure is "is this software required for what I'm installing"; clearly, in this case, MacKeeper fails. There is a degree of trickery, sure, but they are unequivocally trying to trick people into installing something other than what they intended.
I actually installed the malware because I'd become so used to not dealing with this sort of stuff on my non-windows machines. The install process hijacks your browser by adding extensions, changing the search engines, blows away your prefs and cookies, installs some crap in the OS, etc. Huge pain in the butt. Totally my fault for just blindly bashing on the next button in the installer. I can assure you, the malware in Filezilla is quite real.
"Getting the Latest Stable OpenCV Version
Go to our page on Sourceforge;"
It is one of the oldest software in the world.
If projects need to host binaries what are the best alternative to sourceforge?
I maintain a ffmpeg build and two of codec code destinations are SF. lame and opencore-amr.
I tried to find a mirror but couldn't. They link to Sourceforge from their official site.
Do you know if there's any plans to move away from SourceForge? If I was in charge of the project, I'm not sure what I'd do. Maybe move all active development to github, but not abandon the SF repo to malware injection?
It was never on sourceforge as far as I know. It was in Google Code and then later github
The downloads are still on SF, though. That's unfortunate.