14 ms·
I gave commit rights to someone I didn't know (2016)
- dang 3y agoDiscussed at the time: I gave commit rights to someone I didn't know - https://news.ycombinator.com/item?id=12522654 https://news.ycombinator.com/item?id=12522654 - Sept 2016 (100 comments)
- psacawa 3y agoAnother possible outcome of "I gave commit rights to someone I didn't know": https://github.com/dominictarr/event-stream/issues/116 https://github.com/dominictarr/event-stream/issues/116
- ipaddr 3y ago"he emailed me and said he wanted to maintain the module, so I gave it to him. I don't get any thing from maintaining this module, and I don't even use it anymore, and havn't for years" This is the risk of open source not figuring out funding.
- jamietanna 3y agoListening to https://podcast.sustainoss.org/157 https://podcast.sustainoss.org/157 yesterday a great point was made about two distinct roles - the "author" (original person creating the library) and the "maintainer" (person continuing updates, feature requests, etc) and sounds like in this case this is an author who was nudged into being a maintainer, and them being funded may still not have been beneficial
- byroot 3y agoNot really. Even if it was somehow funded, the original author may still want to stop maintaining it and hand it over to someone else. So it's an entirely different issue.
- ipaddr 3y agoI don't understand why he didn't tell them to fork. The risk of him making new changes was so low.
- BrandoElFollito 3y ago> This is the risk of open source not figuring out funding. Not necessarily. There is software I built for me, thought that it could be useful to others, used for some time and then went away. Sure, if it brought me 1M€/month I would work on it hard. But it was not the primary goal anyway.
- pca006132 3y agoI think authors usually give admin access to active contributors that seem reliable, instead of some random guy who ask for permission without doing much previously...
- aaron695 3y agoYou can not compare an email asking for rights, to someone who has written a massive amount of work, which you can randomly pick a section and see it is correct. This commentator puts it well - https://news.ycombinator.com/item?id=36121561 https://news.ycombinator.com/item?id=36121561 This is simple spammer entropy. Now with GPT spammers can create entropy very easily, so it's tricker.
- MagicMoonlight 3y agoAn attacker would be willing to write a 40 line commit like this guy in order to get the access needed
- griffinmb 3y agoI created/maintained a popular project for years[^1], and recently passed ownership to someone else. It's been great seeing issues resolve, PRs merge, etc, after languishing for a while :) [^1]: https://github.com/nccgroup/sobelow https://github.com/nccgroup/sobelow
- sedatk 3y agoTrust goes a long way. Microsoft had given me read/write access to full Windows source code on my first day despite that I was only hired to work on certain parts of the kernel and drivers. I'd never been shown this kind of trust before; other companies I'd worked with always had layers around trust, so, this kind of "you're 100% one of us now" message on my first day had made me extra happy and motivated at Microsoft. I was extra careful protecting source code too. Loved working there until the day I quit.
- ipaddr 3y agoNot to worry, it's in a source control and mistakes can be reverted.
- Rygian 3y agoIf detected.
- qingcharles 3y agoExactly. I worked for an (unnamed) company once. For some reason I needed to update the gender of a user on the production server with two million users on it. (There was no interface to change gender I expect) I accidentally forgot the WHERE clause on the SQL UPDATE and made everyone male. A fellow developer was watching over my shoulder and we decided to just use the Title column (e.g. Mr/Ms/Mrs) to repopulate the Gender of all users without letting anyone know. I want to apologize to all the female Drs. in that database.
- waveBidder 3y agohonestly the security of that makes me nervous. I would frankly expect nation state levels of paranoia around the windows source. Was there any investigation into whether you could be compromised by someone? or maybe I'm underestimating the amount of checks between you and code in windows updates?
- mytailorisrich 3y ago
- BehindTheMath 3y agoI maintained the pjax library at one point. This is what the author posted at the time: https://twitter.com/MoOx/status/955903710617620482?t=BvPIWQ-ntvKNHmS-6uL2bQ&s=19 https://twitter.com/MoOx/status/955903710617620482?t=BvPIWQ-...
- kemenaran 3y agoI did this with every first committer to https://github.com/zladx/LADX-Disassembly https://github.com/zladx/LADX-Disassembly : giving commit rights immediately (so that they can merge their first PR themselves). I did wonders to foster a community of contributors, and get more patches coming. The CI ensures nothing breaks, and there never was any trust incident.
- riffraff 3y agoI was around around when pugs[0] was a thing, and the "commit bit to everyone who wants it" was kind of magical. I am not sure you'd want this for everything, but for quick paced experimental work it seemed to be incredibly effective. [0] https://en.wikipedia.org/wiki/Pugs_(compiler) https://en.wikipedia.org/wiki/Pugs_(compiler)
- kqr 3y agoI think Graeber used to say that if you tell most adults that "Here's your power. I dare you to be responsible with it" they will. (The notable exception are people who specifically seek power. Somehow they seem to be the least responsible with it.)
- inglor_cz 3y agoI think Graeber's principle works better in meatspace. Online, anonymity/pseudonymity, distance and ability to block communications tends to erode responsibility somewhat.
- kqr 3y agoThis is true. I've run a couple of co-ops and there's a huge difference in engagement when you mostly discuss tasks remotely and when you actually get together and do stuff in the same room. I still haven't figured out why that is[1], and if there are aspects of it that can be recreated remotely. ---- [1]: Some ideas I've had is that it's about sunk costs ("Now that I got my ass here anyway, I may as well contribute") or that there's a visual component (perhaps seeing a face triggers some responsibility chemistry in our brains?) or that it's harder to avoid persistent questions when you share a room with someone. I've also speculated that eating together may enhance engagement, but I don't know if that acts as some sort of Skinnerian reward mechanism or if people feel cared for and that triggers their desire to care in return.
- dEnigma 3y agoOnly somewhat related but in my experience people are also much quicker to be rude over the phone than when you meet them face to face (something which I paid close attention too, as someone who used to have irrational anxiety about interacting with people)
- jrochkind1 3y ago> I've also speculated that eating together may enhance engagemen Definitely definitely. Even without eating. If it's just "seeing a face", then zoom might suffice -- and zoom might improve things. But I think it's clear that actually being in the same physical space with other people is an important ingredient of building relationships of trust and respect. I imagine neuroscientists could do a lot of research into why, and I imagine it's not just one thing (like "seeing a face"), but fairly complicated. But from many people's experience, it seems pretty clear that it's true. (And I agree eating together is special extremely powerful "magic" here -- which btw is/was another severe cost of people's covid pandemic habits of not eating with people they aren't already intimate with...) Still, I've built relationships of respect and trust with people online too. I think another thing going on is that when someone shows up with an agenda to abuse your trust, it's somewhat easier to detect face-to-face (which doesn't come close to meaning universally reliable; of course it is quite possible for manipulative and sociopathic people to show up face-to-face with agendas of abuse and get away with it).
- bbbobbb 3y agoI know this is not point of the article but: > The PR was bigger than what I felt I could sensibly review and, in honesty, my desire to go through the hours of work I could tell this would take for a project I no longer used was not stellar. The PR: https://github.com/django-money/django-money/pull/2/files?diff=split&w=1 https://github.com/django-money/django-money/pull/2/files?di... Do others share this sentiment? This doesn't look like a particularly big PR to me, judging solely by the amount of code changed and the nature of the changes at first glance. Are most of your PRs at work tiny, couple lines of code at most? Am I sloppy for not even consider reviewing this for "hours"? Are all code bases I have worked on sloppy because features often require changing more code than this?
- MentallyRetired 3y agoIt's certainly not hours of work to review it... or maybe it is since it's financial? Either way, "it was in the script" as my wife and I say about corny movie moments. It made for a good article.
- robertlagrant 3y agoCritical Drinker has a phrase for nonsensical things in movies: "X occurred... so the movie can happen".
- golergka 3y agoThat's literally 300 something lines. I'm buffled, 5k PRs aren't that rare at work.
- plugin-baby 3y ago> at work Level of trust with colleagues will hopefully be higher! And individual ownership of and responsibility for the code probably lower.
- g8oz 3y agoWhich is the philosophy behind Gerrit as opposed to Github.
- langsoul-com 3y agoThis would be a godsend for a popular repo that's abandoned. But, other packages still use it and they may or may not migrate to a new package.
- ranting-moth 3y ago> Spoiler: trusting your contributors works I'm glad it worked for him, but just want to remind people of survivorship bias: https://xkcd.com/1827/ https://xkcd.com/1827/
- deleted 3y ago[deleted]
- wly_cdgr 3y agoGlad it worked out that one time, but, could never be me
- CapsAdmin 3y agoI've given commit and other "dangerous" access (moderator or admin privileges) to people I don't personally know or barely know for a long time now and I don't think I've ever regretted it. My criteria is usually just a willingness to improve the situation. I can observe this over time via pull requests, forks and general community participation. I'm very reluctant to give access to someone asking for it. I firmly believe this is something that should be given and not to be expected.
- totetsu 3y agoI gave moderator and admin rights to someone over my Ingress Google+ community I hard worked hard to build, because I didn't play anymore. He promptly removed my admin rights and pursued his agenda with regards to some community Drama. That was an education to me in the human appetite for meaningless petty power plays when all is needed is a bit of good will and cooperation.
- ricktdotorg 3y agohah! i _think_ i remember that? i was an avid ingress player in downtown LA for a time. was definitely part of a few ingress circles/communities and do remember some BS happening in one, basically caused me to stop bothering with google+ after that, i wasn't part of many communities other than ingress. i think g+'s death knell was not soon after?
- bee_rider 3y agoIs this sort of different, since it is a game or game-adjacent space? I’ve heard that, for example, Eve Online players do stuff occasionally that would normally be pretty Not Cool, it were done for some non-game reason.
- londons_explore 3y agoI've never had giving away commit rights backfire on me. And if it did, sorting out the mess and reverting a malicious commit wouldn't be the end of the world.
- ptx 3y agoIf the malicious committer is able to publish releases, that malicious commit might have already reached users (and stolen/deleted their data, or whatever it was meant to do) by the time it's detected, and reverting won't help.
- sergioisidoro 3y agoGiving commit rights to some random person is risky, and will only happen to "celebrity" contributors, with enough social validation. That means not everyone will get it, regardless of how good job they do contributing to a fork or proposing solutions. So I really appreciate projects like JazzBand [1], that gather likeminded contributors and individuals that want to harbour open source repos around an ecosystem (Eg. Django), while giving some assurance on governance. If JazzBand would be around in 2016, django money would be a very good candidate to be harboured by the org. On a meta level, I really would love that more OSS devs would user orgs, rather than personal accounts and repos, so that they can grow their projects with a team, rather than becoming the bottleneck and gatekeeper for development. [1]- https://jazzband.co/ https://jazzband.co/
- masklinn 3y ago> Giving commit rights to some random person is risky, and will only happen to "celebrity" contributors, with enough social validation. Meh. I once stumbled upon a repository the maintainer had abandoned following a change of employment, there were a few things to fix which didn’t seem to hard so I figured I’d ask (thankfully this repo was part of an org I could ask the owner of). I was able to get access to the repo and have been low-key maintaining it (updating the infra, etc…), it’s small and simple so it ain’t much work anyway. I can assert that they’d never heard of me, because I never actually used the package. Still don’t. > On a meta level, I really would love that more OSS devs would user orgs, rather than personal accounts and repos, so that they can grow their projects with a team, rather than becoming the bottleneck and gatekeeper for development. A personal repo doesn’t preclude “growing your project with a team”, you can give write access to a personal repository. An org means extra overhead and complexity, it doesn’t just pay for itself when you create it. Do you create a new org every time you create a new project? Because that’s essentially what you’re suggesting.
- boxed 3y agoJazzband was mostly a graveyard though. And like you said, it's pretty much dead too. So seems like it would be bad to give something quite alive like Django to an org that died.
- klntsky 3y agoStrange that all of this happened without a single bit of ongoing communication. I always talk with people continuously whenever there is a collaboration.
- rorykirchner 3y agoThis happened with clojupyter for me. I just gave everyone who submitted something good commit access, and a handful of people who are way better clojure coders than me made it way better in every way.
- amelius 3y agoGlad it's not the case but that could have worked out very differently for him and all the users of that project.
- boxed 3y agoMy personal rule is that you get commit access after some number of good PRs, depending on the project. Has worked out quite well: - instar. I had two guys basically rewrite the entire thing and make it WAY better. I had a good vision for the API but my implementation was pretty bad. - mutmut. I would never have gotten windows support going without help. (Although I am thinking of abandoning windows anyway soon...) - iommi. This project is much more complex and has a certain philosophy, but we gave commit access to one developer pretty fast as it was super obvious from the first PR what kind of deep thinking he did. All in all, great success.
- verhovsky 3y agoI wanted contribute a fix for a bug that I ran into all the time to https://curlconverter.com/ https://curlconverter.com/ . The author gave me commit access while I was still working on my first PR (or shortly after) without me asking. I appreciated the trust and I ended up contributing way more than I originally intended to.
- teekert 3y agoSee also [0]. Rutger argues that if you have never trusted someone like this (somewhat) blindly, you may have indeed protected yourself from some misery, but you are also overwhelmingly denying yourself the better parts of life. Because "most people are kind" (which is the original Dutch title of the book btw). [0] https://en.wikipedia.org/wiki/Humankind:_A_Hopeful_History https://en.wikipedia.org/wiki/Humankind:_A_Hopeful_History
- VBprogrammer 3y agoMan I remember having to monkey patch that library to do some caching of the exchange rates. Otherwise it would do dozens of requests for the same information exchange rate.
- faitswulff 3y agoCounterpoint: gorhill and uBlock. IIRC, gorhill (Raymond Hill), creator of the popular uBlock adblock extension, wanted to step down and hand the reins off to a contributor. The contributor then promptly removed all references to gorhill and started charging for the plugin and turning the extension into an affiliate marketing product. This reddit comment covers it pretty well: https://reddit.com/r/ublock/comments/32mos6/_/cte0a3n/?context=1 https://reddit.com/r/ublock/comments/32mos6/_/cte0a3n/?conte...
- stainablesteel 3y agoi'm interested in this but that link doesn't work, what happened with ublock?
- NoahKAndrews 3y agoThe link works fine for me. The quick version is that when gorhill handed the repository over, the new maintainer immediately took actions that didn't exude confidence, so gorhill forked it into uBlock Origin, which he still maintains and is the one you should be using.
- shkkmo 3y ago"exude" isn't the right word here. In this context "exude confidence" mean "exhibits a high level of confidence". "Instill" or "inspire" would have the meaning you're going for here.
- pbhjpbhj 3y agoLooks like style to me. Like saying "their actions weren't exemplary" when you really mean "their actions were bad"; maybe a British-English style? When one uses this format, like in the phrase "[something] wasn't ideal" (eg 'I crashed my car and missed my own wedding, which wasn't ideal') the claim to less-than-perfection is really an implicit statement that the object/situation was the opposite of perfection.
- jrochkind1 3y agoThese days getting commit rights to inject malware into an already popular gem has become a real threat. In 2016 I think it wasn't yet/wasn't recognized. I am very sympathetic to the suggestion in OP prior to recognizing that there may be people actually actively trying to abuse your trust to intentionally inject malware.
- rvba 3y agoYour milage may vary
- ptx 3y agoIf the maintainer of a package trusts everyone on the Internet, then users who trust that maintainer (by installing their package) transitively trusts everyone on the Internet, which they might not have expected if the maintainer didn't declare this position upfront. Maybe we need a way to declare in the package and repository metadata that the maintainer considers it world-writable and it shouldn't be installed or updated without very carefully reviewing the code of every new version.
- cat_plus_plus 3y agoCareful there, some made one mistake like this and still have to support it 20 years later.
- mizzao 3y agoAnother similar article, "the pull request hack": https://felixge.de/2013/03/11/the-pull-request-hack/ https://felixge.de/2013/03/11/the-pull-request-hack/
- IYasha 3y agoVery positive article, thank you! I wish I had similar experience!