The dubvee guy made something the way he wanted it and shared it with others. If someone doesn’t like the way he did it they can fork it or use another front end. Not everyone likes the same things and that’s okay.
The dubvee guy made something the way he wanted it and shared it with others. If someone doesn’t like the way he did it they can fork it or use another front end. Not everyone likes the same things and that’s okay.
But who did he force it on? No one can (should) support him attempting to ddos db0 on his way out but is uncommented code or a less than exhaustive readme force? Is it violence by omission?
He forced it on any user and admin that used his front-end. People would be livid if Google started blocking websites in Chrome without consistent reasoning or warning to their users, whereas being up front about it allows for users to opt in or out of their own will with knowledge of what’s happening.
I think alphabet is a weird example to use for your opt in vs opt out analogy but the point is taken. That doesn’t change the fact that the list was available in published, clear (not obfuscated) code. Does the maintainer of a project have a duty to warn about their political leanings or weird social peccadillos? Was there any point that a user or admin performing their due diligence via code review would be unable to see that information?
The maintainer has a duty to publicly note any changes they make so that their users are aware and can consent to continue using the platform with said changes.
Edit: Also putting the burden on a user to be tech savvy enough to discover changes made should also be something made aware to the users. In addition, a user did audit the code and found out what the changes were and got railroaded as a result (db0)…
Commit 22326: added </foo/> to hidden blacklist
No different in action that all the major companies and governments putting in backdoor stuff for various purposes. The only saving grace is that it is readable code here, but is the fact it wasn’t found early on the fault the person who wrote it, or the community that didn’t see it?
Would people have used it if it was commented and documented on its purpose? That should tell you something. And if you say yes, that should tell you something as well on how much you want to defend this.
All the drama and stuff beyond this was wrong. But this is core of open source, to make sure code is valid and honest and to call out bugs and maliciousness. Are the people who found and reported it responsible for others’ actions after they were pissed about it? Of course not. Doesn’t make things beyond dropping the use of it okay, but hey, consequences. Maybe don’t do things behind people’s back.
I’m not sure anyone did anything wrong except AP when he attempted to ddos db0. I certainly would not blame someone for doing their due diligence and posting their results or think they should be to blame for the actions of others (in response to your last paragraph.) I’ve been in the open source community a long time and I’ve always hated the dog piles that come after someone wrongs the group. There is something about the FOSS community that attracts people who think they know better than others. This makes the transgressions bolder and the response nastier than would otherwise be necessary.