4 ms·
> Adding of namespaces only moves the squatting problem from squatting crate > names to squatting namespaces. People like nice namespaces too. What if > someone
by hashhar 3y ago
> Adding of namespaces only moves the squatting problem from squatting crate
> names to squatting namespaces. People like nice namespaces too. What if
> someone grabs an official-looking namespace like "aws", and what if that's
> a legit project?
Solved using domain ownership via TXT record for example.
> Using usernames for namespaces makes typosquatting even worse, because many
> usernames are odd and hard to remember correctly (would you remember digits
> in winapi's owner handle? Is it BurnSushi, BurntSushi, BurnedSushi?)
Fact is that people don't write their package dependencies by memory, they usually go to the readme of the project and use the instructions there.
- pornel 3y ago> Solved using domain ownership This is not a silver bullet. Domain ownership can lapse, can change. When project changes owners, they usually want their domain. So this creates an extra layer of difficulty of having a non-permanent identity attached to permanent identifiers. > Fact is that people don't write their package dependencies by memory They absolutely do in Cargo. `cargo add serde; cargo add tokio`.
- MrBuddyCasino 3y ago> This is not a silver bullet. Domain ownership can lapse, can change. Domains rarely change, and when they do you can redirect or alias the namespace. It works in the real world, and has so for over a decade. Its a package repo, not a nuclear waste storage facility.