Diseased Open Source Software Community - it's about ethics in Code of Conducts

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.
JWZ and his butt-buddies are butthurt over Mozilla soliciting donations in crypto.

View attachment 2857334

View attachment 2857351
View attachment 2857352
View attachment 2857350
What a smarmy cunt, doing this "do you know who I am" spiel. They might know who you are, but that doesn't mean shit and you don't matter either, because you left the company. Your co-founder feels differently on this issue as well, having an entire browser built on the base of ad blocking and crypto.
 
anyone who bitches about carbon neutral should immediately stop using all electronic devices
for the environment, of course
And because the rare earth minerals in that brand new iPhone they buy every year are obtained both by slave labor and by absolutely annihilating the environment.
But these sanctimonious cunts could give a fuck less so long as they aren't personally inconvenienced. What a batch of fucking pricks. Also most of the electricity that goes into crypto is surplus anyway. It's not like they're building power plants just for crypto or this grid electricity is otherwise going to go into batteries or some shit to be saved for future generations.
 
And because the rare earth minerals in that brand new iPhone they buy every year are obtained both by slave labor and by absolutely annihilating the environment.
But these sanctimonious cunts could give a fuck less so long as they aren't personally inconvenienced. What a batch of fucking pricks. Also most of the electricity that goes into crypto is surplus anyway. It's not like they're building power plants just for crypto or this grid electricity is otherwise going to go into batteries or some shit to be saved for future generations.
There's also a shitton of energy pissed away using humans to handle our financial infrastructure right now. All those bankers hanging out in skyscrapers in Manhattan need to be kept chilly in the middle of the summer and all that gold and paper that needs to be trucked around by armed guards.

Certainly crypto as currently implemented is fairly wasteful, but there's no reason why a more carefully implemented cryptocurrency couldn't make more efficient use of energy in the future.

But then I guess a bunch of bankers would be out of jobs and we can't have that.
 
Last edited:
There's also a shitton of energy pissed away using humans to handle our financial infrastructure right now. All those bankers hanging out in skyscrapers in Manhattan need to be kept chilly in the middle of the summer and all that gold and paper that needs to be trucked around by armed guards.

Certainly crypto as currently implemented is fairly wasteful, but there's no reason why a more carefully implemented cryptocurrency could make more efficient use of energy in the future.

But then I guess a bunch of bankers would be out of jobs and we can't have that.
Not to mention the ridiculous amount of resources invested in getting a .00000000000001 second faster transaction in high frequency trading.
 
I was looking into the XenForo license ordeal and found some Linux troon on Twitter who keeps tabs on KF, bitches at Cloudflare, hates archive.org, etc. He has been talked about a few times on the farms due to being a Pleroma dev and for his comments on Byuu's "death" at the hands of evil kiwis. Today I bring you a little more, but first my favorite tweet of his:

View attachment 2794730

He is William Pitcock from around Tulsa, Oklahoma. NIgga is called Willy PitCock lmao.
Aliases: kaniini, nenolod, Ariadne Conill, ariadneconill

View attachment 2794737
totally age appropriate for any adult woman to take pictures with stuffed animals, not a sad attempt to hide his massive chin and distract from his shaggy eyebrows and kilometric forehead
View attachment 2795156
nightmarish

Few pics from his fb (archived):
View attachment 2794776View attachment 2794777
take ahold of his Chris Chan phenotype lol. Imagine the smell

He was somehow involved in Freenode and gaineed some enemy from there. Someone circa 2018 registered williampitcock.com (archived) to try to mek him look like a white supremacist pedo lol, including a section titled "trannies diluting the pro-pedo cause", mind you this was before he publicly trooned out. He does use the word "MAP" and wants children on the fediverse though mhmmm (archived):
View attachment 2794837

and if you were wondering, yes, he just so happens to be a lesbian (many such cases!)
View attachment 2794883

and he's involved with Reddit-famous tranny Laurelai (kf thread) and some other grotesque crossdressing freak with a thread: NekoArc (kf thread). Also another mentally ill troon furry with multiple personalities ,that goes by hte names ElizaFox or Elizabeth Myers, is William's ex boyfriend.

here he is looking for dirt on 1776 Solutions LLC, lol at Null not even having an email to report abuse, based. http://archive.md/ezTTA
View attachment 2795295
I swear the only reason this troon considers MikroTik to not be a "real router" is because MikroTik is a Latvian company, and that's like near Russia so it's basically Russia and they murder trans people, while Cisco routers are from California and they personally suck the tranny dick so only Cisco routers are real routers. That and maybe because it has the same mental attitude that the more you pay for something the better it is. Cisco routers are much more expensive than MikroTik routers, even though MikroTik routers can do about as much as Cisco ones.
 
I swear the only reason this troon considers MikroTik to not be a "real router" is because MikroTik is a Latvian company, and that's like near Russia so it's basically Russia and they murder trans people, while Cisco routers are from California and they personally suck the tranny dick so only Cisco routers are real routers. That and maybe because it has the same mental attitude that the more you pay for something the better it is. Cisco routers are much more expensive than MikroTik routers, even though MikroTik routers can do about as much as Cisco ones.
They might not have even thought about that, just the usual tranny 'but but it's not BRAND' thinking. Simping for Cisco. Sad!

Also Mikrotik is pretty notorious in security circles for being botnettable, but that is (mostly) down to retards implementing it and not changing the default password.

(we had a great time at work recently where a security researcher called Mikrotik 'Romanian or something' and there was a Latvian in the room :D )
 
They might not have even thought about that, just the usual tranny 'but but it's not BRAND' thinking. Simping for Cisco. Sad!

Also Mikrotik is pretty notorious in security circles for being botnettable, but that is (mostly) down to retards implementing it and not changing the default password.

(we had a great time at work recently where a security researcher called Mikrotik 'Romanian or something' and there was a Latvian in the room :biggrin: )
According to the official MikroTik statement, the botnet attack was due to a security hole in WinBox from 2018 that was quickly patched, but barely anyone bothered to change their password or even update RouterOS after that, or even check if something was wrong. So you cannot place all blame on MikroTik for that, it's mainly because of the sysadmins who are too lazy to update their shit and periodically change their passwords.

EDIT: The vulnerability in question. It's been patched in RouterOS version 6.42.1.
 
According to the official MikroTik statement, the botnet attack was due to a security hole in WinBox from 2018 that was quickly patched, but barely anyone bothered to change their password or even update RouterOS after that, or even check if something was wrong. So you cannot place all blame on MikroTik for that, it's mainly because of the sysadmins who are too lazy to update their shit and periodically change their passwords.

EDIT: The vulnerability in question. It's been patched in RouterOS version 6.42.1.
Yeah. I knew there was -a- bug in winbox. Our researcher feels there's two 'groups' of compromised hosts, the other being ones who literally have never changed off default passwords, which is fully on the admins.
 
  • Agree
Reactions: Slav Power
Yeah. I knew there was -a- bug in winbox. Our researcher feels there's two 'groups' of compromised hosts, the other being ones who literally have never changed off default passwords, which is fully on the admins.
Heh, reminds me of how when I got my MikroTik for home usage and opened up the console I noticed a whole bunch of random IP addresses trying to get into the router with default credentials and no passwords, since I'm opened up on BitTorrent. I even added firewall rules to automatically block these people, but I think after I added some other rules to block anyone not from a local network or something it no longer finds any brute force attackers. Basically I have no idea what I'm doing in WinBox and I did something that blocked the attackers but I don't know what it was exactly.
 
Marak, web developer, author of several very popular NodeJS packages and also a participant (1, 2) in earlier NPM drama, is back to make webshitters suffer again.

On January 5th, the repo for Faker.js, a Node package for generating various fake testing data, is apparently deleted and remade, taking every issue and pull request with it. It then sees a single commit [A] named "endgame", which bumps the package version to 6.6.6 and you're greeted with this Readme:
faker_new.png


The original version (that I couldn't save in time) contained a link to /r/conspiracy that he also posted in a Twitter thread [A]: "The fact that Ghislaine fucking Maxwell was a reddit power mod should be more investigated". Either because of this, or due to one of his repos being suspiciously wiped, Github suspended access [A] to his account.

On January 8th, Marak returned to deliver some more liberty - literally.
marak_colors_zalgo.png

Looks like another one of his packages, colors.js (just colors for terminal output), that hasn't seen any activity since 2019, got a commit named "Adds new American flag module" and a version bump with a "-liberty" postfix. The bleeding wall of text is from an infinite loop that starts from 666. He really likes symbolism. Users were understandably confused, so he made a pinned issue [A] for it.
zalgo_issue.png

fixing1.png

fixing2.png

fixing3.png

In short, everybody who had either of the two packages unpinned and not locally archived, got fun surprises. Faker's gone, but just from the issues linked to the Zalgo one, colors hit Amazon's Cloud Deployment Kit, Facebook's Jest (JS testing) and Microsoft's Playwright (test automation) to name a few. Likely a lot more, because, based off NPM stats, Faker had ~2.5 million downloads total and ~2500 dependents, and Colors had ~22 million downloads and ~19000 dependents.

Why did he do it? Nobody knows. he mentioned reverting back to a previous version in the comments to the Colors issue (see spoiler), so maybe it's a comment on how moronic NPM dependency hell is and how nobody bothers to pin versions. Or maybe he was tired of essentially working for free, providing people who actually profit with working code as he mentioned a year ago [A] in Faker:
does_it_for_free.png


Although the 2020 drama may have been because his apartment burned down [A]. Speaking of Maraks from New York whose houses burned down in the fall of 2020:
Link (Archive)

Neighbor on Queens man with bomb-making equipment: 'Obviously the man is sick'​


ASTORIA, Queens (WABC) -- The investigation continues into the discovery of bomb-making materials after a fire inside a home in Queens, and the neighbor who first noticed something strange is speaking out about what led authorities to the suspect.

The incident started with a fire around 2 p.m. Tuesday at the home on 19th Street in Astoria, near Astoria Park, with fire crews extinguishing the flames and taking a tenant described as "emotionally distraught" to the hospital with burns to his hands.

Hours after emergency crews left the scene, the landlord and a neighbor discovered what appeared to be a fireproof box outside of the home. Next-door neighbor Debbie Riga said the box was suspicious, and so they decided to open it.

"I saw long fuses, and I saw some kind of powder," Riga said, "It was packaged, but I also saw an awful lot of FedEx packages. They were sealed. I was tempted to open them, but the police said that I would be breaking the law, so I didn't open them"

The tenant, 37-year-old Marak Squires, remains hospitalized and is charged with reckless endangerment. Federal agents are scouring his electronic devices and other evidence, and more charges are possible

"The fire really concerned me," Riga said. "My God, because these houses are so closer together."

Squires is a software developer and early Bitcoin investor, and neighbors said he kept to himself, that his blinds would mostly be shut, and that he had little to no interaction with anyone.

The materials were not assembled, but they were enough for Riga and the landlord to flag down firefighters, who called the police and FBI.

When investigators entered Squires' apartment to look further, they found more bomb making items including potassium nitrate.

Magnesium powder, sulfur powder, copper powder, aluminum powder, hobby fuse and mixing cups were also discovered in the home.

"The chemicals separately are what they are, but taken together they can assemble an explosive device," Deputy Commissioner of Intelligence and Counterterrorism John Miller said. "There were books about military explosives, booby traps and other things...What we're looking at here is the totality of the circumstances that raised our concern to a level where we're going to need more investigation."

Investigators are still trying to determine what caused the fire and looking into the mental state of the tenant.

"Obviously the man is sick," Riga said. "He didn't get the help he needs, and it results in things like this."

A second suspect suffered second-degree burns and is in the Cornell burn unit at the hospital where he is being evaluated.

Squires has one prior arrest for misdemeanor assault for a dispute with his 28-year-old girlfriend over a cell phone. She suffered a bruised arm and a scratch in the scuffle.

Squires graduated from East Hampton High School.

The Joint Terrorism Task Force and the NYPD bomb squad responded to the scene, and Astoria Park was evacuated as a precaution.
Watch out which JS dev you call a weak soyboy, fellow Kiwis. Or you just might end up with a small but heavy package sitting on your office desk.
 
Or maybe he was tired of essentially working for free, providing people who actually profit with working code as he mentioned a year ago [A] in Faker:
"Wtf coding for free and licensing under a permissive license means other people get to use my code for free?! Fuck that I quit."
Could of easily solved this by using a non-wuss license like AGPL.
 
"Wtf coding for free and licensing under a permissive license means other people get to use my code for free?! Fuck that I quit."
Could of easily solved this by using a non-wuss license like AGPL.
That's really the best part of the regularly scheduled NPM drama. Everyone involved deserves what he gets, and they never learn from it either so it's infinitely repeatable.
 
"Wtf coding for free and licensing under a permissive license means other people get to use my code for free?! Fuck that I quit."
Could of easily solved this by using a non-wuss license like AGPL.
Why do the boring thing when you can use a corpo license for years, let them become dependent, and then pull out the rug from under them?
He should have left the package as-is, but relicensed it under AGPL. Watching FAANG legal depts scramble as a bunch of their products because infected would have been more entertaining than his bizarre schizo-activism (schizotism?)
Wouldn't that only apply to future versions and not retroactively?
 
Why do the boring thing when you can use a corpo license for years, let them become dependent, and then pull out the rug from under them?
The company would just fork your project, which costs it very little - especially if the company is FAANG and your project is a terminal output colorizer. Even if they don't notice the license change and end up violating the new license, this has happened before and accomplished approximately nothing outside of a bit of social media noise. Laws are for the plebs, sadly.
 
How many more incidents of this type are going to happen before fucking javascript developers figure out that pulling directly from random peoples' githubs and deploying to live products without any human intervention is insane?

Like, who ever thought this was a good idea? NPM is a cancer on the javascript community, which is itself a cancer on humanity.
 
Like, who ever thought this was a good idea? NPM is a cancer on the javascript community, which is itself a cancer on humanity.
Rust did, they've reimplemented it with cargo, and the culture again is to use a mile deep tree of tiny crates of which you personally picked only 3-4 of.
Only a matter of time until history repeats itself in Rust/Cargo.

Say what you like about C, the lack of dependency management means that you hand pick what you depend on, and you know the dependency tree is going to be small and manageable.
 
Back