Google Is Now Listing SourceForge as a Malicious Site
i.imgur.com
i.imgur.com
Edit: Thread: http://www.reddit.com/r/technology/comments/3a9h9x/soureforg...
Response from one user that sourceforge is actually whitelisted by google: http://www.reddit.com/r/technology/comments/3a9h9x/soureforg...
http://safebrowsing.clients.google.com/safebrowsing/diagnost... http://safebrowsing.clients.google.com/safebrowsing/diagnost...
>> What is the current listing status for sourceforge.net?
>> This site is >>>not currently listed as suspicious<<<.
>> Part of this site was listed for suspicious activity 333 time(s) over the past 90 days.
>> What happened when Google visited this site?
>> Of the 205785 pages we tested on the site over the past 90 days, 588 page(s) resulted in >>>malicious software being downloaded and installed without user consent<<<.
>> The last time Google visited this site was on 2015-06-18, and the last time suspicious content was found on this site was on >>>2015-06-18<<<.
>> Malicious software includes 5877 virus, 4347 trojan(s), 1132 exploit(s).
[1] http://safebrowsing.clients.google.com/safebrowsing/diagnost...
||sourceforge.net^$other
uBlock Origin has prevented the following page from
loading:
Because of the following filter
||sourceforge.net^$other
Found in: uBlock filters
1) Originally (a couple years back or so), they started (as an opt in from the project owners) bundling adware with the Windows versions of installers on selected projects.
2) Recently, SourceForge editors have taken over abandoned projects (i.e., projects that no longer use SourceForge as their primary distribution page, and haven't updated the project pages), and have replaced the installers for some of them with their adware-bundled installers.
3) A firestorm erupted over this, SF stated that they would back away from the adware (on taken-over pages -- it would still be present on projects with an agreement from the project owners).
4) They are still taking over abandoned projects and updating them.
Now my question -- for point (4), are they just updating the project download pages with the current versions, or are they still bundling their adware with the projects? Everything I've seen so far (after their "apology" post), it appears that they haven't done any new adware bundling, just taking over the projects. Is this the case? And if so, is the concern that they will slip in the adware in the future?
So did Sourceforge. Github has competition in business space (Gitlab Enterprise, Stash) and if it falls out of favor with businesses, anything can happen.
The only thing thats bad on GitLab is that you don't have a Startup license for Enterprise, so we are running Community, since we are only 4 people. However the only things that are won't as good as on your enterprise version is the linking with jira, which however we need since the standard "issues" are just not enough for us. However thats not a fault of gitlab itself. they are good enough for the most things / projects.
However we just use a half of JIRA's feature so providing a better way to define issue's for external without code access would definitly help. Also I'm looking forward to migrate away from stash / jira as soon as possible however we have a 3 year subscription which is now at it's half so we need another year to finally go to GitLab Enterprise.
Github.com goes down; Github Enterprise crawls on very large repositories. (Not everybody's, of course, but the bigger they come, the worse Github performs, and the more money the customer is worth.)
When you call Github support, a support engineer will tell you, "At Github, engineers work on projects that we find interesting. Github Enterprise doesn't get that much interest on our team."
When you call Atlassian support, they fix your problem.
http://safebrowsing.clients.google.com/safebrowsing/diagnost... :
> Part of this site was listed for suspicious activity 332 time(s) over the past 90 days.
edit: Now happening for me in Chromium. (Both of these on Xubuntu 14.04, versions from the repos.)
I can reproduce it if I visit exactly: http://sourceforge.net/projects/camstudio/
but not http://sourceforge.net/ on it's own. Perhaps they only apply the warning to malicious projects rather than the site as a whole.
tl;dr: uBlock Origin
Wonder what's up with that?
On Firefox in Windows they do appear to work fine, as you say.
Edit: I'm an idiot, after the last HN article about sourceforge I pointed them to 127... in my hosts file.
> uBlock₀ has prevented the following page from loading: > http://sourceforge.net/projects/lame/ > Because of the following filter > ||sourceforge.net^
Tech superpowers cannot coerce me through (direct) regulation or force.