4 ms·
>It kind of feels like this fork is the better-maintained piece of software now. Maybe, but I feel the value of the index is the storage and bandwidth and not
by nomdep 1y ago
>It kind of feels like this fork is the better-maintained piece of software now.
Maybe, but I feel the value of the index is the storage and bandwidth and not the software itself, isn't it?
Could an index work by just being a search engine for gems, storing the hashes, but pointing to external resources, like GitHub repos, for the download itself?
- soraminazuki 1y agoTrustworthiness is far more important for a package manager. No amount of storage or bandwidth can compensate for an untrustworthy package manager.
- stanislavb 1y agoWith this is in place. A ".coop" domain does not signal trustworthiness. It's more like a childish revenge attempt. Don't get me wrong. I think it's a great idea for the original maintainers to begin work on a form. However, they could have chosen a better domain name.
- mijoharas 1y agoI saw someone else saying something about the domain name, but I didn't really give it a second thought when I read it. Can you explain what the issue is?
- seanw444 1y agoI'd only say it's a real issue if this were a "normie-facing" website. But being a developer tool, we all know that there are legitimate domains other than .com, .org, and .net.
- LexiMax 1y agoIt's one of those "attractive distractions" that us nerds like to bikeshed over. Honestly, after "tweet" caught on as a verb, I've given up on thinking that we have any sort of crystal ball when it comes to names.
- soraminazuki 1y agoWhat? Which part of the word "co-op" sounds like a "childish revenge attempt"? https://en.wikipedia.org/wiki/Cooperative https://en.wikipedia.org/wiki/Cooperative It's a word that nicely captures their objectives.
- florkbork 1y agoRead https://en.wikipedia.org/wiki/.coop https://en.wikipedia.org/wiki/.coop Think about all of the organisational structures you know of. Then ask yourself how is a cooperative fundamentally untrustworthy?
- hatthew 1y agoMy first-order heuristic is that legitimate websites tend to get one of the top TLDs (.com/.org, maybe .net/.io). In general, why should I trust domain_name.xyz over domain_name.com? There are obvious caveats, e.g. it doesn't matter as much for generic words like "gem" and for personal sites that I don't trust much in the first place. In this case, 3 seconds of critical thinking makes it clear that they have a plausible reason for choosing .coop. But given that much of this controversy is premised on toolchain trust, there's plenty of other domains that seem even more trustworthy to me at first glance, e.g. gem-lib.org, gemcoop.org, stuff like that. Again, a domain name is pretty minor in the scope of this whole fiasco, and I wouldn't have bothered with bringing up this point, but on balance I agree with it.
- ajb 1y agoUsing .coop is actually a costly signal that you are, in fact and in law, a cooperative; and intend to stay one; since non-cooperatives are not allowed to occupy those domains. Dot Org, while it's used by a lot of well known organisations, is an open domain that anyone can register in. Of course, it's also true that many people won't have the spare time to find that out.
- krainboltgreene 1y ago> My first-order heuristic is that legitimate websites tend to get one of the top TLDs (.com/.org, maybe .net/.io) This is so funny to hear after 18 years in the west coast silicon-valley lead tech industry. All of the app, io, tv, tech, guru, and now ai I've seen and only when it's "coop" does anyone complain.
- hatthew 1y agoI'm pretty sure people have been complaining about weird TLDs for as long as I've been on the internet. .guru, .tech, and .app are all equally untrustworthy to me. I don't recall seeing any .tv websites other than twitch. .io and (only recently) .ai are used often enough that it's contextually plausible a legitimate company would use one of those TLDs as their first choice, but if someone linked to chatgpt.ai or chatgpt.io for example, I'd still assume it's a scam.
- JimmaDaRustla 1y ago> It's more like a childish revenge attempt. Gaslight much? "coop" implies intention and direction...you know, that thing that rubygems.org could have used?
- skywhopper 1y agoCoop as in co-op, as in “co-operative”.
- monkaiju 1y agoI view ".coop" quite highly given it is restricted to actual, legally recognized, cooperatives. Its definitionally more meaningful and "trustworthy" than .com or .org
- akerl_ 1y agoIs it? Anybody could publish to Rubygems. Baring obviously malicious packages that happened to get noticed by a researcher, what trust were folks placing in Rubygems?
- soraminazuki 1y agoThe package repository going rogue is a significant escalation compared to merely having individual malicious packages that go undetected. You can't possibly argue that those two are the same.
- akerl_ 1y agoTo put my cards on the table: RubyGems.org seems plenty trustworthy to me. They seem to be shitty at communication, but locking down production access to systems in light of the state of supply chain attacks in 2025 is the kind of thing that reduces the risk of rogue repo-level activity. But to your comment: I'm not arguing the same, I'm arguing that the results are the same. If I'm consuming packages from a repo, and I care about the security of the thing I'm running, I need to think about how I know I'm getting legitimate code that does what I expect it to do. One of the risks to that is malicious developers at the package level (either outright malicious or stolen publish credentials). Another is malicious substitution by the package repo. The detection strategies and next steps are different but as a consumer of code, bad code is a risk regardless of who injects it.
- soraminazuki 1y agoNonsense. The solution to a malicious package is to not use that single package. The solution to a malicious package repository is to abandon that package repository entirely. Also, you don't secure a package repository through hostile takeovers, and you certainly don't build trust with such an obvious lie. Claiming that the current rubygems.org is in any way trustworthy is utterly absurd.
- baobun 1y agoTFA is about a new server/registry hosting for community gems. Not a fork of Bundler.
- soraminazuki 1y agoYeah, it's a fork of rubygems.org. It doesn't look like anyone here is confused about that, but thanks?
- mijoharas 1y agoIsn't that how golang works? I remember some complaints about the traffic that it produced[0] (though I don't think it's a bad idea. Basically federated downloads). [0] https://sourcehut.org/blog/2023-01-09-gomodulemirror/ https://sourcehut.org/blog/2023-01-09-gomodulemirror/
- Imustaskforhelp 1y agoCombining this with something like tangled.sh/bluesky's AT protocol or what forejo is working on in their activitypub federation integration can actually make it genuinely federated as well Or maybe radicle as well if someone is okay with swapping in a custom software but the hiccups can be too much imo so tangled.sh is the most interesting thing to me right now What is stopping something like gem.coop to exist with the at protocol/tangled.sh??