7 ms·
He is mentally unstable. His motives are probably irrational. This is not the first time he reaches the news for strange criminal activities. (Yes, it's his co
by rsstack 5y ago
He is mentally unstable. His motives are probably irrational. This is not the first time he reaches the news for strange criminal activities.
(Yes, it's his code. No, it isn't legal to maliciously add an infinite-loop to a library that you know is used by other companies. The license adds some liability protection, but it's not so simple.)
- deleted 5y ago[deleted]
- ziggus 5y ago"...it isn't legal to maliciously add an infinite-loop to a library that you know is used by other companies" Um, what?
- netr0ute 5y agoIt can't be illegal if the software is provided as-is without any warranty as most OSS licenses do.
- rsstack 5y agoI'll leave it as an exercise for the reader to understand the difference between "I am not liable if I have a bug that ruins your production environment" and "I am not liable if I maliciously introduce a fatal bug knowingly into your production environment".
- fulafel 5y agoMost of those (malice, who introduced it to your environment, fatal bug) seem contestable, even if we grant for the purpose of argument that the as-is disclaimer does not cover all cases.
- rsstack 5y agoDid you see the commit before it was deleted? I'd love to see a lawyer claiming anything else.
- fulafel 5y agoWhich of the 3 claims are you referring to? The commit is here as far as i know, not deleted: https://github.com/Marak/colors.js/commit/074a0f8ed0c31c35d13d28632bd8a049ff136fb6 https://github.com/Marak/colors.js/commit/074a0f8ed0c31c35d1...
- WJW 5y agoAny reasonable expert in the field will testify that it is not possible to write an infinite loop like that unintentionally.
- fulafel 5y agoThe commit had a comment to the effect of being test / toy code not meant to be put into a release. I don't think a claim of randomly producing the snippet would be put forward in the hypothetical court case. Then there's the question of malice vs some other motive of expression in looping and printing some ASCII / zalgo art in your own terminal art lib.
- salawat 5y agoAny reasonable expert in the field will tell you you don't plug an auto-updating dependency into production. Marak wrote code. You, (the consumer), pulled, and deployed it without due diligence. That is entirely on you. Not one person is obligated to keep your crap working except you. This has really outed all the people who really should know better.
- phkahler 5y agoBut he didn't introduce it into any particular production environment. For fucks sake, people need to pin dependencies to a known good version at the very least.
- cecilpl2 5y agoOf course he did. Intent matters, and this was a reasonably foreseen consequence of the way the system is set up. He knew how npm works and he knew the implication of adding that code is that hundreds of libraries and production systems would automatically upgrade and install it. In fact, the whole point of what he did was to introduce the code into production environments.
- jessaustin 5y agoRaise your hand if you pull directly from the internet into production without testing! <no hands raised> How can we claim he did anything to production if no one will admit they're dumb enough to push this latest version without testing it?
- Supermancho 5y agoIt could be illegal (regardless of warranty or license), but it happens to not be in most of the US.
- marwis 5y agoIf you put a bomb in a box and attach a button with a note that the button is provided as-is and author disclaims any liability, then leave it in public place and someone presses it, do you think you will not be found liable?
- LegitShady 5y agoif you build a car oitside in public view and someome copies it and crashes are you liable? tbis ismt a bomb in a box its his project car you copied without any warranty or.gurantee of stability.
- MattPalmer1086 5y agoNo, he has no civil liability to the extent permitted by law, as the license states. He basically can't be sued. That's different to criminal liability.
- justupvoting 5y agoRational motives can produce irrational actions, and do so somewhat reliably.
- Isthatablackgsd 5y ago> No, it isn't legal to maliciously add an infinite-loop to a library that you know is used by other companies. Could you cite an source for this? Because I got a impression that it "isn't legal" which mean it is not illegal based on your comment. I would assuming you are referring to USA Computer Fraud and Abuse Act?
- rsstack 5y ago"18 U.S.C. § 1030(a)(5)(A) knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;"
- awinter-py 5y ago'without authorization' here is going to be tricky. author probably did have authorization to both github + npm? and didn't knowingly cause transmission to anywhere else? the rest of the steps were pull, not push.
- rsstack 5y agoIf we're honest about the US justice system, this would be a subjective decision decided by non-technological lawyers, jurors, and judges. The purposeful malicious intent is working hard against his stance.
- onesmartmofo 5y ago
- site-packages1 5y agoHe did breach basic ethics and standards of professional conduct by his actions, for sure. I would lean against considering what he did illegal, but I think there is an argument to be made that it would be illegal under the CFAA.
- _fat_santa 5y agoPersonally I think he did it to prove a point. IIRC he made a post last year where he said he would no longer be developing software for companies to use for free. This gripe is that he does all this work for free and companies then use his code to make money and do not contribute back to the ecosystem. IMO this was not the most graceful way to make the point, but at the end of the day it's his project, his code. If you want the expectation of it always working, then pay him. Don't bitch and moan that the old man giving out free bread on the steps isn't here this morning.
- peoplefromibiza 5y ago> he made a post last year where he said he would no longer be developing software for companies to use for free I understand the sentiment, but why chose MIT license then? GPL would be the right choice if one wants to stop companies profiting from free work without giving anything back.
- accoil 5y agoWould GPL help though? It's a library used by tests, not part of the end product distributed to users.
- peoplefromibiza 5y agoI don't know in this case but in general a GPL fork must stay GPL and, AFAIUI, importing a GPL package in your code it's similar to linking to it, so if the code that uses your GPL package is published (on GH for example) that could be considered redistribution. Not sure about the legalities but it could create enough friction to keep companies not willing to contribute away.
- accoil 5y agoI guess I'm thinking more in terms of faker, which I believe was a library for creating test data. Makes me wonder if licenses matter much for tools that are never intended to be included in the final distribution. Internal changes aren't going to be detectable, so it feels like the best you can hope for is that they don't want the maintenance burden of a patch set on top of your project. At that point it's not much different than MIT. That said, AGPL would scare off most companies :p
- deleted 5y ago[deleted]