Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Plenty popular names on there. That's shocking.


To be clear - there is a difference between mirroring (which is good netizen behavior, and to be complimented), and trojaning (which is modifying the upstream sources before delivering them to users - which is decidedly not good netizen behavior).

It's important to understand which is which for those accounts.


As long as one of those accounts is trojaning (or even just suspected of possibly having been trojaning once) it instantly poisons all the mirrors. Even if they are perfect netizens 99% of the time, that 1% makes all their other efforts useless.


Whoa what. Are you suggesting that suspicion of possibly maybe having put a trojan in someone else's files somewhere is grounds to make all one's efforts useless and poisons everything else you do?

Geeze, I guess we should stop using Google. They've been accused and suspected of much worse by a lot of people. I hope that's not what you meant.


Are you suggesting that suspicion of possibly maybe having put a trojan in someone else's files somewhere is grounds to make all one's efforts useless and poisons everything else you do?

Short answer: Yes. Downloading and running arbitrary binaries from the web inherently a quite dangerous thing do to, and I only feel comfortable taking such a risk with sites I trust. I no longer trust Sourceforge and there is very little they can promise me to make me start wanting to download from them again.


Er, okay.

Well, I don't agree¹ with your method of evaluating trustworthiness (which seems to me rather too quantized and "chastity"-minded), but at least you know exactly what you're doing and who you're trusting.

[1] Read as "I believe it's sub-optimal for a given cost-benefit formula, after some assumptions about certain variables and certain opportunity costs, and other methods would likely be more useful in context."


suspicion of possibly maybe having put a trojan in someone else's files

Isn't it a hard fact at this point?


For Sourceforge specifically? Sure.

In general, the way the comment was worded? No, suspicion does not equal hard fact.

We were talking about the latter.


No, it is not important at all - because today's mirror will silently be replaced with tomorrow's trojan.

It is important to expose this behavior for what it is.

And in the process, remind everyone that abuse of power is a question of WHEN, not IF, whether it's a government entity or a corporate one.


Sourceforge's mirrors are a complete miss-use of the term mirror. A mirror should be an exact copy of the source and should be approved by the original project, which I doubt any of these 'mirrors' are.


Interesting weaseling of SourceForge is to add a "downloader" which fetches either the actual unmodified installer/sources. The "downloader" installs adware while fetching the real installer for the software. In the case of GIMP the filename of the downloader was made to be the same as the filename expected of the installer for a given version. This dirty approach might be thwarting ways of protecting with cryptographic signatures, or even trademarks/copyleft.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: