Firefox download on SourceForge
sourceforge.net
sourceforge.net
https://www.mozilla.org/en-US/foundation/trademarks/policy/
It specifically precludes distributing modified versions of the software or installer and still calling it "Firefox" (with which they seem to be complying for the moment), and also specifies the manner in which the name and branding are to be used in website copy, like putting a "TM" symbol after the first mention (with which SF seems not to be complying at the moment). In other words: Mozilla has power here and could force them to take it down if they wanted. And they should, in my view, if for no other reason than because SF have been jerks about this whole thing and this is finally a situation where someone can actually do something about it.
"By sending or transmitting to us Content, or by posting such Content to any area of the Sites, you grant us and our designees a worldwide, non-exclusive, sub-licensable (through multiple tiers), assignable, royalty-free, perpetual, irrevocable right to link to, reproduce, distribute (through multiple tiers), adapt, create derivative works of, publicly perform, publicly display, digitally perform or otherwise use such Content in any media now known or hereafter developed. You hereby grant the Company permission to display your logo, trademarks and company name on the Sites and in press and other public releases or filings. Further, by submitting Content to the Company, you acknowledge that you have the authority to grant such rights to the Company. PLEASE NOTE THAT YOU RETAIN OWNERSHIP OF ANY COPYRIGHTS, TRADEMARKS AND SERVICE MARKS IN ANY CONTENT YOU SUBMIT."
I admit I missed that.
Apparently this is done by the uBlock Origin's own "uBlock Filters"[1][2] with this reason:
# http://libregraphicsworld.org/blog/entry/anatomy-of-sourceforge-gimp-controversy
# https://blog.l0cal.com/2015/06/02/what-happened-to-sourceforge/
# Using `other` will cause the whole site to be blocked through strict blocking,
# yet the site will render properly if a user still decide to go ahead.
||sourceforge.net^$other
I'm a little bit unsure whether this is a good thing or not. But personally, given SourceForge's recent behavior, I'm kinda happy that uBlock Origin did this (as SourceForge have clearly stepped into the ranks of malware-spreading sites).[1]: https://github.com/gorhill/uBlock/blob/ed130afc6f3a70e2c2a68...
[2]: https://github.com/gorhill/uBlock/commit/c4e82357efaf18bac3f...
But this action made me install ubo. Two minutes ago.
EDIT: Just tested strict blocking on my install and nothing prevents the link from displaying. I wonder what is different in my version.
I have today installed uBlock and it didn't block the whole page by default.
Hyperbole.
This merely acts as a warning. Notice the buttons at the bottom to disable the blocking temporarily or permanently.
Disabling it was easy enough so I'm not too mad about it, but I still don't like it.
The thing is, there isn't really anything that easy to move to. No, no github, because we don't like git. We have a bunch of Mercurial repos. We could try moving them to bitbucket, but this also leaves the question of what to to do with our webpage hosting, which is currently on SF.
And no matter what we decide doing, it's all a bunch of work that nobody really wants to do.
At least when SF first approached us with their "revenue sharing" bullshit we refused. I think this means our downloads are clean so far.
I think it means they just get to keep more money...?
http://sourceforge.net/projects/octave/files/Octave%20Forge%...
The most prominent element of this page, centered just below the header, is a large bright green "Start Download" button. That button is part of an advertisement, but is blatantly designed to get the majority of its clicks from users who intended to download software from the project hosted on SF. I see it as a malicious download.
I realize you may have been referring specifically to the recent SF malware bundling, but I want to stress that this ad came up for me on my first try clicking one of those links. Ad's like that have been regular on SF for years; it's impossible to believe that they have made it a priority to prevent them. The opposite seems more likely: the page design minimizes the legitimate controls and emphasizes the scam link.
Even if I know the installer is free of opt out malware I would hesitate to send a SF link to a friend or family member. The clearest call to action they are likely to see is a malicious download impersonating the software they want.
A lot of people don't want to do things they have to do. It's a question of if you're going to wait for SF to hyjack your downloads or move preemptivly.
Also, apperently bitbucket will host static pages, I don't know if that works for you.
Any particular reason?
> We could try moving them to bitbucket, but this also leaves the question of what to to do with our webpage hosting, which is currently on SF.
You could move your repositories to bitbucket but mirror the single repository for your webpage content to GitHub to use their hosting. (And if that repository is currently Mercurial, see git-cinnabar by Mike Hommey: https://github.com/glandium/git-cinnabar/ )
Or, it looks like bitbucket may have a similar feature: http://pages.bitbucket.org/
Lots of reasons. I'd rather not go into an argument about it. It's not something that can be fixed: git is a no-go for us.
> but mirror the single repository for your webpage content to GitHub to use their hosting.
I'd rather break free, not change masters.
Unless you have the volunteer army necessary to run the hosting yourself, you're going to be changing to a new master anyway. You just need to make sure it's a master you can leave at any moment.
So get a domain name and point it at GitHub Pages, and deal with git for the timebeing. At any point (either if GitHub goes bad, or someone's enthusiastic about setting up something else), you can repoint that domain name to another host, far more easily than you can change octave.sf.net to point somewhere else.
I agree that switching to octave.github.io would not actually help anything other than the immediate problem.
You don't need an army (depending on the solution). But setting up gitlab/rhodecode/indefero/srchub/Gitolite/custom scripts for a single project is kind of overkill. I've used rhodecode and whenever they released an update it would take me hours to update it. I've never been happier to fork indefero and get off of google code.
This seems to be a continuous problem in the open source community. As tools, maintainers, and support platforms age, how do you deal with the tech debt of keeping them supported? It's an easier calculation for a business; I'm just curious how various open source projects make these kinds of choices absent a corporate benefactor that sets direction.
I'm not interested in getting into an argument, but I'm genuinely curious what reasons remain for people preferring mercurial. At the moment, apart from "got used to the UI", the main one I know of is more "native" Windows support (without needing a Cygwin-like environment to work in). I don't know if that's an issue for your project.
> I'd rather break free, not change masters.
Fair enough. In terms of repository hosting, moving to Savannah seems like the obvious choice there then. And assuming you have people available to do the work, you could always move to gnu.org or nongnu.org, depending on your tastes and the nature of the software your directory links to.
Top-level answers here:
https://news.ycombinator.com/item?id=9467096
> moving to Savannah seems like the obvious choice there then.
The only issue is that Savannah is static hosting. We have a bit of PHP that generates one page. We might be able to replace that with Jekyll, though.
Does it do so from dynamic server-side data, or could you run it on each new commit and serve the result as a static page?
Because that's about the only way to genuinely "break free".
https://lists.debian.org/debian-devel-announce/2003/03/msg00...
"We'll approve ... free software/documentation where a Debian developer is heavily involved (part of the core team for example). The project request should ideally be done by a Debian developer."
Alternatively, can you get your webpage hosting onto gnu.org?
As for GNU, the problem is that we only have static sites there. It's not a huge problem, but it might be a good solution.
https://confluence.atlassian.com/display/BITBUCKET/Publishin...
Would that work for Octave-forge?
So you can move to github and keep hg.
>Hey, this isn't a SourceForge project! Check out the SourceForge Open Source Mirror Directory for more information.
which links to: http://sourceforge.net/mirror/
>The Open Source Mirror Directory is an extension to our existing software directory, where we'll be mirroring projects that are not hosted on SourceForge, and SourceForge projects that have been abandoned.
Perhaps its time for Google to "adjust" their host rank?
Another channel would be donations for hosting FOSS projects or something like that.
Very hard question indeed.
Kind of what? I'm genuinely not aware of this. People seem to be hating Quora but I've never received a concrete answer; their having to select 'preference' at the beginning annoys the hell out of me, though.
Forced sign-in for one. They used to show different versions of the the Q&A to crawlers vs people who click the search result. And then blur the answer. Also they didn't have an option to delete an account. You need to email them about that.
Some previous discussion
https://news.ycombinator.com/item?id=4377181
https://news.ycombinator.com/item?id=4332978
They also make money off of their job board ($450 a listing) and could probably monetize a lot more here without angering too many users. https://jobs.github.com/
Now, if you click the 'read more' link, you'll find that the Firefox download available on sourceforge was actually last updated 10th June 2014. 53 weeks ago. 10 major version numbers ago.
:(
Their past indicates they will and what they have done so far fits the pattern nearly perfectly. I'd put money down that malware will be in this by the end of the year if not sooner.
From a company with a history of stuffing adware down our throats.
Edit:
% md5 firefox-*
MD5 (firefox-genuine.dmg) = 71c3d44cd5a612489a70e0f2ef825ba9
MD5 (firefox-sourceforge.dmg) = 71c3d44cd5a612489a70e0f2ef825ba9
So they are the same binary. All we need to do is create a Chrome extension that downloads the binary from both places and checks the hash then tells you if it's safe to download the SF one. Simple!Note that it took 8 times as long to download the binary from Sourceforge compared to Firefox's own site.
Just yesterday VLC was on HN about moving away from SF "The story between VLC and Sourceforge": https://news.ycombinator.com/item?id=9714250
The mirrors (HEAnet & co) should refuse to add any new binaries from Sourceforge and we need a community driven website that coordinates open source download binary mirrors (based on what SF uses at the moment), and Archive.org/ArchiveTeam/etc should backup all SVN/CVS/etc repositories on Sorceforge, and Google then should remove them from their index or flag them as adware/scam.
If you look at Fedora the new sourceforge hijack page links to Fedora, but the original sourceforge page was just some random software.
Mirror hijack: http://sourceforge.net/projects/fedora.mirror/
Original: http://sourceforge.net/projects/fedora/
Hey, this isn't a SourceForge project! Check out the
SourceForge Open Source Mirror Directory for more
information.
plus the url also clearly says ".mirror", so they're not pretending to be the authoritative page on the product. It's no more creepy than Tucows or C-Net at this point. Just a regular spam laden download site.You can try to draw a line between 'optional highly integrated offers that are hard to remove', 'crapware', 'bloatware' and 'malware' if you like, but .. it's really just one bucket. Bad → Malware.
You dilute the meaning of the word by using it here.
They say the road to Hell is paved with good intentions. Does that mean we should just ignore the fact that it goes to Hell?
However, what's clear right now is that if you download an installer from Sourceforge, it could install software that is totally unrelated, that you didn't request. Yes, they might disclose that it's going to happen and give you the option not to install the unwanted software, but it's still clearly their intent that some people end up with unrequested software on their machines. That's pretty questionable behaviour in my book.
They've put out press releases explicitly admitting to such intent: that they hijacked "inactive" projects (which includes projects who intentionally left), and that they bundled "offers" (malware) with them.
And if you think there's a useful distinction between malware and what they're distributing, note that one of the bits of software they "offer" to install captures all network traffic and routes it via a third-party service without making that clear to the user.
That's not what malware is, though. The term isn't a scientific one, but the intent to harm is a pretty key component, and I am quite certain Sourceforge isn't trying to hurt its users.
Does it really bother no one else that the phrase "malware" is being thrown around antagonistically?
So one could argue that their installer is a trojan since it's actual behaviour isn't the same as it's presented behavior. Thus even if the software they install isn't malware, their method of deployment is.
You don't get to play that card.
By that logic I can run a botnet and distribute whatever I want over it and it can't be called malware as long as I say I have no ill intent and I keep myself blissfully unaware of what's being installed. NO. SF can and SHOULD be held responsible for bundling crap and malware to unsuspecting users. They don't get a pass just because you THINK there is no "ill intent". Ignorance of the law is not an excuse and neither is ignorance of the shit you are deploy. They don't get to stand back and shirk responsibility, it's on their site it's their problem, plain and simple. It doesn't matter AT ALL what there intent was it matters what they are doing and they are distributing malware. END OF STORY.
It just seems to me that the term "malware" is being used here intentionally to antagonize, rather than to accurately classify the software being installed by Sourceforge.
Please understand that I am casting no judgement or assessment whatsoever of what Sourceforge is doing -- personally I think they're a dying website that's trying to do whatever they can to make money and stay relevant.
It just intuitively feels wrong to classify China in the same category as Sourceforge.
There is, however, a meaningful difference between the kinds of things my antivirus picks up and the software Sourceforge was bundling.
Calling the Sourceforge bundles "malware" masks that difference, and I think that's harmful, and maybe a little childish.
Scrambling to stay in business, or being under new management, is not an excuse to suddenly become user-hostile or otherwise turn to shady activities.
Similarly, many companies start throwing around litigation when they begin to fail, since that's the only way the purchasers of the various patents/etc owned by the company into money.
Finally, the only "harm" it could do to classify all such software as "malware" is to make it more difficult for vendors of software who would prefer not to be classified in the same bucket as people who maliciously break into computer systems. And I have zero sympathy for any such companies; the sooner they go out of business, and the more they're viewed as universally unacceptable, the better off both users and the computing industry will be.
> admit it and slither away
Totally not ok. Please comment civilly and substantively or not at all. [2]
1. https://hn.algolia.com/?sort=byDate&prefix=true&page=0&dateR...
Oh, and don't bother trying to spam my email account. I set up a filter to automatically delete any email from hn@ycombinator.com long, long ago.
And attempting to trick users into installing software that you know they don't want is definitely ill intent and attempting to hurt users.
Sure, some security professionals make distinctions between a variety of different subtypes of bad software, with varying definitions, including adware, malware, badware, ransomware, backdoors, viruses, trojans, and any number of other terms. But outside of the security industry, people trying to make fine-grained distinctions or introduce different terms are often malware vendors themselves, hence why you've "touched a nerve".
For instance, when Lenovo started pre-installing the Superfish malware on their systems, they persistently called it "Potentially Unwanted Programs", to obfuscate what they were actually doing.
On top of that, as the Superfish case indicates, even software that "just" serves ads tends to escalate, such as by MITMing and utterly breaking HTTPS. And any such software has the potential to introduce bugs.
We have quite enough bugs in software that does what its users want it to do, without introducing more software that nobody wants and that can only further reduce user security and privacy.
I think you and I are on the same page here. My only additional point I'd like to make is that there is value in differentiating between what Sourceforge did and what will happen if you download a bad torrent from TPB, or click the wrong ad on a porn website. Lumping them all together means my grandfather goes and buys identity protection services because the Ask toolbar on IE is "malware".
Also, the Ask toolbar is not the only thing SF is installing; they're also installing much worse software. And sure, it's less harmful to change a user's search engine or waste a few dozen vertical pixels on a distracting toolbar than it is to turn a user's system into a botnet node, but "less harmful" is still harmful.
For the record, I also think there are some bad actors in the "identity protection" and similar security spaces; not only is it ridiculous to need software or services to protect you from other software and services, but many such services are scamming novice computer users who know enough to be afraid. And the entire consumer antivirus industry is a bit ridiculous as well, not least of which in the sheer amount of resources such software tends to take up. I much prefer the portion of the security industry that's pushing for a sandboxed-by-default, principle-of-least-privilege world.
But at the same time, adware, malware, or whatever you want to call it (including the vast majority of IE toolbars and such) are good examples of software that needs to go away and never come back. I'm not interested in shady ways to scam and "monetize" users; as has been said many times elsewhere, "your failing business model is not our problem". And the existence of even worse software doesn't excuse slightly-less-awful-but-still-awful software. The only question is how much damage such companies will do in their death throes before they finally die.
I get what you're saying regarding "if we just call it all malware, people will get upset when companies install it", but I see that as a dishonesty to the public. In the computer security industry, it's very tempting to sell fear -- it's immensely effective as a sales pitch, but it's not honest. We can do better, I think.
https://sourceforge.net/blog/advertising-bundling-community-...
Therefore, we evaluated a few Installer Partners to help us address end-users’ complaints related to one or more of the following reasons:
a) opaque installation flows providing little or no choice about secondary offering installations;
b) undocumented and difficult to uninstall procedures for those secondary offerings;
c) secondary offerings that are not always safe, trusted and secure applications.
We addressed points a) to c), and our approach was highly appreciated by eminent members of different open source communities.
Then they figured out that they had made a mistake and started bundling less user hostile software.
If they had not bundled stuff people didn't want, they would say that there instead of back peddling.
Considering the incidents involving Sourceforge in the last few weeks, I would be rather surprised if they just did this, considering how hilariously tone-deaf it would look.
I can't honestly say I don't agree with it's behaviour
all the malware we try and install without you noticing
I could be wrong but there are signs and absurd behavior like umpteen number of resignations at the top, Firefox Apps been published with strange love from private players like telefonica/others etc.
Isn't there a smell somewhere here?
The moment anyone decides to add bundleware to the official release would be a golden age for tech recruiters since most of the engineering staff would be already packed.
Source: Mozillian
echo "127.0.0.1 sourceforge.net" |sudo tee -a /etc/hosts