I’ve heard people mention curl and imagemagick. Any others that you know about?

  • Eric_the_Cerise
    link
    fedilink
    87
    edit-2
    1 year ago

    Werner Koch, the guy who created, and who has maintained for 25 years now, pretty much all by himself, GnuPG, the modern email encryption replacement for PGP.

    Just the other day, I realized I actually live just a few kms away from the guy, here in Germany … very tempted to reach out to him someday and actually buy him an actual coffee.

    • @[email protected]
      link
      fedilink
      31 year ago

      That was the one I couldn’t remember, I got GPG and PGP confused but I remember it involved email encryption.

      This guy was the reason that every security dev had those personal public keys clearly posted next to their email address on every announcement and blog post they ever released.

    • @axtualdave
      link
      English
      371 year ago

      The neat thing about the log4j thing was even a cursory explanation of the vulnerability made anyone with a passing familiarity with security say, “Why the fuck would that even be a feature?!”

      • @[email protected]
        link
        fedilink
        English
        221 year ago

        As a non-java company developer at the time, I think our biggest challenge was explaining to everyone that Log4j didn’t affect us. It took a non-zero amount of effort because a lot of customers panicked. To be fair, it was also an industry where confidentiality is important.

        • JackbyDev
          link
          fedilink
          English
          61 year ago

          Also a lot of people were pulling it transitively.

      • @[email protected]
        link
        fedilink
        English
        61 year ago

        It was if none of your code used log4j. I remember being very grateful that I had chosen java.util.logging and Logback for my Java logging needs.

        • @[email protected]
          link
          fedilink
          English
          31 year ago

          Lol, yeah for us we didn’t own any of the code that used it but depended on server software made internally that did. At the time we managed our own hosts, so it was a long week of deployments.

      • @[email protected]
        link
        fedilink
        English
        51 year ago

        Oh man. I missed it by like a month. I graduated with my bachelors in December, and started in January. I was hearing horror stories from my new coworkers about how people had to cancel vacations to get stuff patched asap

    • elrac
      link
      fedilink
      81 year ago

      That one was so annoying because you had to be using the log server to have any issues. If your network was locked down, the log server was disabled, or if you happened to be using a version that was from before the log server was added, then there were no issues. But clients just heard “log4j” and thought it was unsafe.

    • Haus
      link
      fedilink
      31 year ago

      Couldn’t remember which logging library it was, thanks for mentioning it, it would have low-key bugged me all day.

    • @Wolfwood1
      link
      English
      11 year ago

      Came here looking exactly for this answer. What a week that was… And the next ones too

  • @fubo
    link
    English
    811 year ago

    Public NTP time servers have occasionally been that piece of infrastructure.

    NTP is used for synchronizing computer clocks, ultimately using highly-accurate time sources such as atomic clocks. The most authoritative public time servers tend to be run by research universities, national labs, and so on.

    Multiple home router vendors have sold devices configured to poll university NTP servers vastly excessively; effectively running a denial-of-service attack against public infrastructure. In a few cases, public time servers have closed down because of abuse by misconfigured consumer devices.

    https://en.wikipedia.org/wiki/NTP_server_misuse_and_abuse

  • Black616Angel
    link
    fedilink
    English
    811 year ago

    Sci-Hub anyone?

    Alexandra Elbakyan manages this truly awesome source of scientific papers completely on her own. She got sued twice and lost, had to change the URL multiple times due to takedowns and only gets along by donations.

    • @[email protected]
      link
      fedilink
      English
      211 year ago

      It is a crime to humanity to lock knowledge behind a huge paywall. She does God’s work.

      And it’s not like the actual scientists/academics support knowledge being locked away either, or profit from it.

    • @[email protected]
      link
      fedilink
      English
      111 year ago

      She’s the best thing that’s happened to the s scientific publishing field. I’m no longer a student but I still enjoy reading scientific papers and I’ll be damned if I have to pay $20 per article (which doesn’t go to the authors) since I no longer have access to a library that maintains relationships with these big publishers.

  • @[email protected]
    link
    fedilink
    English
    63
    edit-2
    1 year ago

    Left pad https://arstechnica.com/information-technology/2016/03/rage-quit-coder-unpublished-17-lines-of-javascript-and-broke-the-internet/

    Had GPT summarize what happened.

    The “left pad” incident refers to a controversy that arose in 2016 when a developer named Azer Koçulu removed his JavaScript package called “left-pad” from the NPM (Node Package Manager) registry. This caused a ripple effect, breaking numerous projects that relied on this package and highlighting the potential risks of relying on external dependencies. The incident sparked a debate about the stability and trustworthiness of the open-source ecosystem and led to discussions about best practices for managing dependencies in software development.

    • @[email protected]
      link
      fedilink
      English
      211 year ago

      This is the one I came to post about. The fact there’s a library for this is so stupid to me.

      I feel like it demonstrates how npm and modules have probably to some degree gotten out of hand.

      • @fubo
        link
        English
        1
        edit-2
        1 year ago

        “It broke the build at Big Tech Company” is mostly a testimony that Big Tech Company was deeply dependent on someone’s work and they weren’t paying for it.

    • AnonymousLlama
      link
      fedilink
      71 year ago

      From memory the NPM blokes had to have a think about how they handle important packages because of that. Didn’t they revert the changes to left pad to ensure everything else didn’t break?

      Fascinating to see the house of cards some of these solutions / libraries are built off

      • JackbyDev
        link
        fedilink
        81 year ago

        Yes. They added it back. The policy now is that you can’t remove packages that are depended on (or something to that extent, I don’t know the specifics).

      • ottercurling
        link
        fedilink
        31 year ago

        Yeah I’m pretty sure Github themselves restored the package if I recall correctly

    • Spiritreader
      link
      fedilink
      61 year ago

      That’s always the one I’m thinking of when anyone mentions the xkcd.

      npm is one crazy infrastructure.

  • @[email protected]
    link
    fedilink
    English
    521 year ago

    cURL was one of these for a while (according to my limited understanding)

    It was made in the 90s and it didn’t get commercial support until a few years ago.

  • @[email protected]
    link
    fedilink
    English
    491 year ago

    TzData is basically maintained by 2 guys. Pretty much every computer, phone and language relies on this database for timezone information.

  • muttley
    link
    fedilink
    421 year ago

    The core-js library is used by 1000s of top websites and is maintained by one guy
    https://github.com/zloirock/core-js

      • Highsight
        link
        fedilink
        191 year ago

        It’s honestly a fascinating read. We count so much on these kinds of people to keep our way of life intact, but when they ask for a little help in their own life, they get spat on.

        • gk99
          link
          fedilink
          101 year ago

          It’s really, really sad that this sort of stuff doesn’t get picked up and funded for the greater good. Stuff like the NLnet Foundation exists, which has helped fund some pretty major projects (including the development of Lemmy), but something this critical I feel should be consistently funded by even larger entities in order to keep things working right.

      • Baldur Nil
        link
        fedilink
        51 year ago

        This story got me sad. But also, the guy should know better as not to dedicate all of his time on that. This article talk a bit about this issue.

        • @lightsecond
          link
          English
          11 year ago

          Thanks for sharing that article. Most open-source projects start not with a plan to monetise but because an engineer wanted to solve a problem by themselves.

          Also, when i read zloirock’s post about what it takes to maintain ‘core-js’, i couldn’t understand why he would not just walk away or at least take on a lesser role. It isn’t good for any project if it depends on one person. Especially for something that is such a core part of the js ecosystem (pun intended). I’m sure he’d get lots of volunteers if not the money directly.

  • @dragontamer
    link
    English
    371 year ago

    OpenSSL / Heartbleed was the event when this comic came out IIRC.

    • @fubo
      link
      English
      1
      edit-2
      1 year ago

      OpenSSL was (and is) an actively maintained project; although some infrastructure users prefer Google’s stripped-down fork, BoringSSL.

  • @[email protected]
    link
    fedilink
    English
    36
    edit-2
    1 year ago

    Not a package but FileZilla is developed by Tim Kosse for over 20 years. I know that there are a lot of other FTP-Clients but FileZilla is my favorite. Easy to use and very very stable. There is a pro version sure, but most of the time the regular one does the job. My company throws thousands of dollars a month at Adobe, Microsoft and others. But they would never even think about giving anything to Tim Kosse and others, even though I’ve probably saved days of work with tools like this.

    • @[email protected]
      link
      fedilink
      English
      111 year ago

      My company’s anti-malware started triggering on filezilla’s installer a few years ago because they started packaging apparently sketchy ads in it. Dunno if that’s still the case or not. I ended up switching to WinSCP instead. (Which I believe is actually another example of just one or two guys running that show too.)

  • pwshguy (mdowst)
    link
    fedilink
    English
    301 year ago

    Basically every Windows sysadmin is indebted to Mark Russinovich and SysInternals. Fortunetly, PowerToys has come a long way because I’m pretty sure sysinternals haven’t been updated since Windows XP.

    • GrishAix
      link
      fedilink
      English
      191 year ago

      Mark Russinovich now works for Microsoft and they own Sysinternals. Also the tools get updated quite regularly.

      • @[email protected]
        link
        fedilink
        English
        191 year ago

        “Mark works for MS” is a massive understatement. He’s CTO of Azure now.

        And speaking of Sysinternals, arguably the most exciting update was when ProcessExplorer got a dark mode late last year :)

  • Baldur Nil
    link
    fedilink
    English
    28
    edit-2
    1 year ago

    Node frameworks are famous for this purely because of a lack of standard library. I feel like most languages have a standard library that balance being generic but still providing utilities of common used stuff. So a company that doesn’t want to rely on a random guy’s library can build their own with only the features they want. But with Node, any complicated feature is using a tree of hundreds of random packages that you have no idea who created them.