6 ms·
The link in the article sums up the "what happened to Sourceforge" pretty well: http://www.gluster.org/2013/08/how-far-the-once-mighty-sourceforge-has-fallen/ h
by mathrawka 13y ago
The link in the article sums up the "what happened to Sourceforge" pretty well: http://www.gluster.org/2013/08/how-far-the-once-mighty-sourceforge-has-fallen/ http://www.gluster.org/2013/08/how-far-the-once-mighty-sourc...
The OSS project I maintained for several years was always in the top 10 downloaded lists on Sourceforge, but I got frustrated with how things were going and eventually moved the code to Github and hosted a simple website on my own.
Honestly, I can't think of a reason why an OSS project would choose Sourceforge in this day and age.
- conductor 13y agoTheir mirrors system is working very well. It's very easy to distribute big files (like ISO images) through Sourceforge's mirrors. No wonder that Adobe's leaked users database was (or still is) being distributed using Sourceforge mirrors.
- leeoniya 13y agoi cant imagine that it's better than torrent
- conductor 13y agoI don't think it is. Sourceforge is very user-oriented (in contrast, GitHub is very coder-oriented). Non tech-savvy users don't know how to download software using torrents while HTTP just works using one click.
- Semaphor 13y ago> Sourceforge is very user-oriented For users with adblock. I would never send my technically illiterate friends to SF as there is a high chance they click on an ad instead of the real download.
- hnriot 13y agomost companies block torrent downloads. edit - I mean when at work, I can't torrent any large ova's or iso's. Sadly fortune 500 america will hardly ever allow torrent through their firewall for obvious reasons.
- JohnTHaller 13y agoMost companies block torrents. And software that does torrent downloads often gets flagged as badware. We considered building torrent into the PortableApps.com Platform and getting users to help share bandwidth with other users, but those stumbling blocks are pretty big ones.
- fredsted 13y ago>Most companies block torrents. Most companies also block random software like PortableApps.com.
- JohnTHaller 13y agoYou'd be surprised how very few do. We keep things clean, well-behaved, and virus-free for a reason.
- fredsted 13y agoI know you do - I use your apps. But I think writing off torrents because companies filter them isn't a reason to do so. As long as they can download random executables and run them, they'll be able to download torrents, either via .torrent files, magnet links, via a proxy or whatever method they figure out.
- JohnTHaller 13y agoTorrents themselves are blocked by most corporate firewalls (and many university ones). Adding torrent abilities to the PortableApps.com Platform, even if we custom wrote it to work with our app store, would encourage places to block our whole platform. Like it or not, even with all the legitimate uses torrent has, to many people it's about stolen software, stolen music, stolen movies, and porn.
- fredsted 13y ago>Adding torrent abilities to the PortableApps.com Platform, even if we custom wrote it to work with our app store, would encourage places to block our whole platform. >Like it or not, even with all the legitimate uses torrent has, to many people it's about stolen software, stolen music, stolen movies, and porn. I think that's a little far-fetched, nearly all open source projects utilize torrents for distribution with noone blocking them. Torrents are just the default way of providing high-speed software mirrors these days.
- idupree 13y agoIt's hard to download from Sourceforge using HTTPS. (Or even to use HTTPS to get the SHA hash of a download.) Can you tell me how to do it, so I can download from Sourceforge without risk of a man-in-the-middle modifying the download to, say, contain malicious code?
- simonhn 13y agoNavigating to the directory from the 'Files' tab and clicking the 'i' icon to the right of each filename available for download displays the 'View details' panel with the SHA1 hash of that file. Is that not enough?
- idupree 13y agoNo, because you can't access that hash from https://sourceforge.net/ https://sourceforge.net/ ( https://sourceforge.net/ https://sourceforge.net/ is just a redirect to http). It's slightly more of a nuisance for the attacker to modify the hash as well as the file, but if they can modify the .zip you get, then they'll surely have no trouble doing "s/the original zip's hash/their malicious zip's hash/" on all your unauthenticated web traffic too. It's a simpler modification than Upside-Down-Ternet. In this case, they do need to create a compromised version of the zip before you view the hash, but that can be arranged with good probability by tracking the web pages you visit, pre-computing compromises of popular downloads, and/or slowing down your page load speed to give them enough time to compute and serve you compromised hashes. It wouldn't be too hard for an accomplished Web villain to have a good shot at compromising your computer if you are using public WiFi or they have ISP or NSA level access, provided you download software insecurely. ( My unfortunately ranty blog post on the matter: http://idupree.dreamwidth.org/3233.html http://idupree.dreamwidth.org/3233.html ) HTTPS isn't perfect, but it (and/or other cryptographic signing) is the minimum we should accept for downloads of code that can quietly pwn your user account when you run 'make'.
- Theodores 13y agoI go to SourceForge for civiCRM and it works pretty well. However I am downloading something to install on a linux box where there is no .exe installer. I have heard that GitHub has been DDOSed a few times in recent times. Therefore, for me, it is swings and roundabouts.
- mathrawka 13y agoSourceforge used to get DDOSed as well. You can probably dig up some older articles on Google. But I am not sure about these days. Perhaps that is a sign of losing relevancy...
- smoyer 13y agoI used to love SourceForge so it's a bit painful to admit that it's no longer important enough to waste the bots needed for a DDOS on it. The reality seems to be that they're destroying themselves.
- JohnTHaller 13y agoThat article gets a lot of things very wrong as I pointed out when it was posted on HN last time (you'll see my comment at the top): https://news.ycombinator.com/item?id=6262347 https://news.ycombinator.com/item?id=6262347 Github is an option for some folks but not for us. We need solid file hosting with lots of bandwidth (pushing well over 50TB a month at SF) that will be sticking around next month and next year. In my comment linked above, I mention that Github ditched binary downloads (they did last year). In the ensuing discussion, it was pointed out that Github added the feature back in this year as 'Releases'. It remains to be seen if the feature will stick around, though, and I wouldn't put my all my eggs in that basket. When Github discontinued binary downloads last year, users were offered no alternative. So, it's not inconceivable that Github would pull the binary hosting feature again in the future as they stabilize their product offerings. SourceForge has been serving our binaries for 7 years now.
- jeswin 13y agoYou should then consider a better host. SourceForge is clearly a scamware host now; maybe ever since Dice.com took over. And to be honest, just seeing a file hosted on SourceForge casts doubts on the quality of the app. - Most users just click OK for installers, it is like the EULA - I am yet to see a toolbar that does anything useful to anybody; other than make their system slower and buggy. I hold a very low opinion of people (like Ask.com) who bundle things with the clear knowledge that most people are unknowingly installing their app/toolbar. Much worse than spammers. With your extensive experience with user behavior, it is interesting that you see this differently.
- jlgreco 13y ago> And to be honest, just seeing a file hosted on SourceForge casts doubts on the quality of the app. I couldn't agree more. Whenever a session of searching for a solution ultimately lands me on a sourceforge page, I feel a pit form in my stomach. When it happens it typically means one of two things, often both: I took a terribly wrong turn somewhere, and/or I am in for a world of hurt. Contrast this with finding myself on a github page, which very often signals success. My hypothesis is that a sourceforge page signals that the author is dated, the author has abandoned the software, or the author doesn't care much for the users.