4 ms·
Agreed on all points. People are quick to jump on someone especially when they work really hard on something and then give it away for free. Companies turn arou
by ozfive 5y ago
Agreed on all points. People are quick to jump on someone especially when they work really hard on something and then give it away for free. Companies turn around all of the time and change their revenue model and nobody says a thing. It's their right. The guy still had the rights to do whatever he likes with the software he wrote for free. All the assholes vilifying him are shilling for corporations that didn't want to pony up to help this guy continue his work. His actions were pretty drastic, but remember he owns the rights. If he wants to delete what he owns he's in his rights and corporations better take note. You use something for free that you don't own and have no intention of compensating the people behind it you only have yourself to blame when those people rage quit. There is no real argument against this without looking like a freeloading dick.
- BoorishBears 5y agoYou don't get to have it both ways: If you go by the spirit of things tanking a package and Github/MS/npm taking over to undo that is fair game. Even if it's not literally a virus, obviously damaging basic functionality to make a statement is not a sustainable practice for NPM to continue functioning If you want to go by the letter and what legal rights someone has: https://docs.npmjs.com/policies/conduct https://docs.npmjs.com/policies/conduct > The Service administrators reserve the right to make judgment calls about what is and isn't appropriate in published packages, package names, user and organization names, and other public content. Package that violates the npm Service's Acceptable Use rules including its Acceptable Content rules will be deleted, at the discretion of npm. https://docs.npmjs.com/policies/open-source-terms https://docs.npmjs.com/policies/open-source-terms > Your Content belongs to you. You decide whether and how to license it. But at a minimum, you license npm to provide Your Content to users of npm Services when you share Your Content. That special license allows npm to copy, publish, and analyze Your Content, and to share its analyses with others. npm may run computer code in Your Content to analyze it, but npm's special license alone does not give npm the right to run code for its functionality in npm products or services. > When Your Content is removed from npm Services, whether by you or npm, npm's special license ends when the last copy disappears from npm's backups, caches, and other systems. *Other licenses, such as open source licenses, may continue after Your Content is removed. Those licenses may give others, or npm itself, the right to share Your Content with npm Services again.* https://github.com/Marak/colors.js/blob/master/LICENSE https://github.com/Marak/colors.js/blob/master/LICENSE - Seriously, why are people so adamant about defending this? We're all part of a giant ecosystem that relies on everyone being "a freeloading dick" in your eyes. Colors wouldn't have its audience without its creator being a "freeloading dick" and expecting NPM to serve it millions of times for free. NPM relies on a JS ecosystem propped up by "freeloading dicks". "Freeloading dick" is such a dumb characterization of what it really is: Expecting FOSS creators and maintainers to be somewhat cognizant of the ecosystem past the tip of their nose.
- ozfive 5y agoYou are toxic and a perfect example of shilling for corporations. I bet you depend on that package and many others that you and your corporate overlords haven't paid a cent for. Deplorable at best. I donate to projects that I use as a percentage of revenue. Name more than one OSS project that your company has actually donated money to on a regular basis to ensure that it's original maintainer has some sort of compensation for the work they put in based on your usage? I bet you can't because you are more than happy to exploit things that you consider free. Defending freeloading dicks just puts you in that category.
- dang 5y agoPersonal attacks like this and https://news.ycombinator.com/item?id=29885496 https://news.ycombinator.com/item?id=29885496 and https://news.ycombinator.com/item?id=29753758 https://news.ycombinator.com/item?id=29753758 are against the site rules and extremely not ok here. We ban accounts that post like that. I'm not going to ban you right now, since we haven't warned you before, but please don't do this again. If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.
- ozfive 5y agoIf we are all a part of a giant ecosystem then it should be acknowledged that work has been done and should be compensated for otherwise you are just continuing to advocate for the exploitation of FOSS software without handing any compensation over for the value that it adds to this giant ecosyatem
- lolinder 5y ago> If he wants to delete what he owns he's in his rights and corporations better take note. Except for that he didn't just delete the code. He added malicious code that without warning broke applications at runtime, most likely disproportionately affecting small projects that lack rigorous dependency controls. Companies can change their revenue model, but they don't get a blank check to do anything they want. See Toyota's recent blow-up with the key fobs as a counterpoint to your argument. It's one thing to phase out support for an old product. It's quite another to yank out the rug from under people without warning, and companies don't get a pass on that anymore than this guy should.
- taberiand 5y agoEveryone who had code that broke due to this (and, really, everyone else too) should see it as a clear wake up call that they need to do better managing their dependencies.
- chaostheory 5y agoIf he just wanted people to pony up, there are plenty of other alternatives like changing the license for future versions like SugarCRM did https://sugarclub.sugarcrm.com/engage/b/sugar-news/posts/sugar-community-edition-open-source-project-ends https://sugarclub.sugarcrm.com/engage/b/sugar-news/posts/sug... Since he's been acquired in the past, he could also make it into a SAAS play. He has the connections, skill and experience. Otherwise, he can just walk away like everyone else. Maliciously changing code to break people's stuff is uncalled for. If he wanted to charge people from the start, then maybe he shouldn't have used the MIT license for his code? If you want more restrictions on usage, choose a more restrictive license. On a related note, the developer in question is not well mentally which helps rationalize what he did https://www.qgazette.com/articles/more-charges-possible-for-astoria-bomb-suspect/ https://www.qgazette.com/articles/more-charges-possible-for-... "A team of NYPD investigators and FBI agents found potassium nitrate, which is used in fertilizer, metal containers, fuses and other bomb-making materials in the crate, along with printed bomb-making and survivalist materials and a book on how to make a bomb scattered throughout the home, the source said." “'The chemicals separately are what they are, but taken together they can assemble an explosive device,' NYPD Dep. Commissioner of Intelligence and Counterterrorism, John Miller, said. 'There were books about military explosives, booby traps and other things.'"
- kristjansson 5y agoSure, he can do that. But everything else is released under an open source license. Anyone that has a copy (like, I dunno, NPM) can continue to distribute whatever version of the software they want according to the terms of the license.
- hnlmorg 5y agoI think most on here sympathise with his frustration even if they don't agree with his actions. The real question is whether you believe as a maintainer you have the right to do whatever you want to your code while in the knowledge that others will run it. The emphasised part is important. I have zero issue with people writing malicious code purely out of academic curiosity but if you write in with the intention of that code propagating, as this author had done, your actions become far less sympathetic.