Diseased Open Source Software Community - it's about ethics in Code of Conducts

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.
Which is all bullshit because devops is meant to facilitate proper code->production practices but devs refuse to do anything but "code" and toss the code to someone else when "its done". Devops is such a shit role depending on the company and team. I don't know if devs are largely retarded or refuse to change from the old "waterfall" development and siloed department days. Gone are the days when you just do one thing. You are responsible for your code from inception to production which requires basic knowledge of the processes and systems.
"Basic knowledge" lol. What "devops" means in practice is you just fire the admin and tell the devs to to his job. Then complain when they're slow, because they're being spread thin between actual programming, firefighting and learning some obscure, ever-changing cloud tools. Division of labour was invented for a reason.
 
It's incredible that he's doing all this ... on the world's most popular open-source hosting platform, which is built on (and fucking named after) the source control software that inspired it, and where preserving historical versions of everything (comments, pull requests, text, issue titles, source code, etc.) is a fundamental feature. Anyone can go back in any issue's history or the repository's commits to see the original discussions and nefarious deeds. That and all the "juicy" stuff has been well-preserved by all sorts of people, has hit the search engines and has even formally documented at NIST as a vulnerability.

There's no erasing this now. This is a profoundly stupid person.


No. /g/ has been flooded with trolls (and idiots, I assume) all smugly proclaiming "but muh license!" indemnifies this idiot against damage claims. They're wrong, of course.

A license agreement cannot indemnify a party from prosecution for a crime they commit. Whether a piece of paper two people agreed to says "if you use my software you have to accept anything and everything it does" or not, pwning a computer system is still a crime. The vector of attack (and the license agreement governing it, if any) is irrelevant.

Consider the current plague of software-as-a-service. If you pay for a year of access to Adobe Photoshop, if you stop paying after that year, all they do is stop the software from working for you until you pay for it again. They don't go through your filesystem to delete anything you created with it (or just files at random). I don't doubt it's crossed their minds, but their lawyers have probably warned them they'll get in hot water for that. Even just holding a customer's data hostage on their own computers while resolving a payment dispute is a legal grey area.

This guy? He wrote malicious code with no legitimate purpose (i.e. his users would never want it to be triggered and perform its actions on their own systems), obfuscated it (a little), snuck it into an update without disclosing it or warning anyone and allowed it to be released and deployed. When confronted he openly acknowledged he did it to cause damage to specifically-targeted computer systems, then when he realized he'd made a big mistake he quickly began (poorly) trying to cover his tracks.

Null is spot on -- this was malware. You can't protect yourself from legal action or prosecution just by saying "lol I can do what I want" in the license agreement.

ETA:

This is standard operating procedure for Microsoft: embrace, extend, extinguish.

VS Code and WSL are the "embrace" phase (get everyone hooked on their tools and ecosystem). Typescript is the "extend" phase ("it's our flavor of Javascript! Totally backwards-compatible, but with more features!"). Screwing with the Javascript standards is the beginning of the "extinguish" phase ("everybody uses this anyway, so why not make it the new standard and throw out this old-and-busted ES5 stuff? Our technology includes all its features anyway! Why no, we'll never lock it down and/or remove features, why would you ever think that?").
Just imagine how many script kiddies are going to see this and copy paste the data over after seeing this idiot do it
 
Lol NGO didn't have working backups, their fault
even if it's fake it's believable because you know how these organizations are
If you read their statement, they've been flooded with so much data because of the war they've not been able to back up stuff.

It's sort of ironic that this guy did Putin a massive favor by fucking over a nosy Western NGO.
 
"Basic knowledge" lol. What "devops" means in practice is you just fire the admin and tell the devs to to his job.
It's a problem if devs have no idea what their code runs on.

Then complain when they're slow, because they're being spread thin between actual programming, firefighting and learning some obscure, ever-changing cloud tools. Division of labour was invented for a reason.
That's management in general who buy into the tech evangelist bullshit. There are also devops engineers who implement meme technologies to add to their resume to attract the FAANG companies who created it.
The entire thing is a shitshow and working with a competent team is uncommon.
 
Just imagine how many script kiddies are going to see this and copy paste the data over after seeing this idiot do it
LMBO. That's me.
It's 2022 and we're getting another wave of Lamer Exterminator clones.
 
>have ugry, old, bug wife who complains instead of suckifucki
>decide to cheat on her
>based_and_concubine_pilled.raw
>decide to troll for some hot trussy
>absolutely_catamite_pilled.img
>the tranny you go for is more manly than you, not even a bailey jay wannabe
>niggawat.dump
 
In reality this guy is a passive code monkey who is petty, jaded, and cannot appreciate anything. Always coveting what others have constantly looking for greener grass. Every time he gets what he wants it never meets the rosy and romantic vision that was in his head. This project was probably his greatest source of pride. Now that he has destroyed his best work the next step is to ruin his tenuous marriage and then become a troon.
View attachment 3086730
Wow his Youtube channel is exactly what to expect from someone who has never touched a soldering iron yet really loves electronic vehicles. Looks like his two friends are the mechanical and hardware guys while Brandon is the designated camera holder and tool fetcher. A troon saga is looking more and more like a reality.

This picture reminds me of Owen Wilson, only if he became a NEET instead.
 
A small pro-tip for le 1337 anonymous hackers who want to actually help Ukraine: Don't fuck with regular people who just so happens live in Russia, a lot of Russian people don't support the war either, especially people in the IT sphere.
 
Last edited:
People are cheering on this guy being fucked and his life ruined, but I'm not actually seeing any evidence anything bad has happened to him other than him being sent pizzas and a failed SWATting attempt.
I think the pizzas and SWATting are false, as I mentioned upthread. We only have his word that they happened and pizza joints don't work in the way he described.

That said, there are a couple bad things that have happened to him. First off, his wife (if she's paying any attention) now knows that he at least attempted to cheat on her various times throughout their marriage. What she intends to do with that info is up to her, but having been through an acrimonious divorce, I wouldn't wish that hell on anyone, and mine didn't even involve cheating (that I know of).

Secondly, his name is now mud in the software space. No FOSS under his name will be taken seriously in the future. He could come back with a new identity, but if/when it's ever linked to his old one, those projects will be toast too. In terms of employers or clients, nobody who searches his name will ever want to hire him for fear he'll leave similar little surprises in the software he writes for them. His future career in software development might not be totally fucked since he might be able to find freelance clients who don't know or don't care who he is and what he's done, but he'll never be able to have the success he could have had if he had not done this.

That's not even mentioni g the fact he created a fucking virus that can be weaponized against literally every one in the world with some minor modifications to it.
Just imagine how many script kiddies are going to see this and copy paste the data over after seeing this idiot do it
One, I wouldn't call this a virus because it can't replicate peer-to-peer and/or without user intention. It still requires the user to update their Node packages, and the code only came from a single GitHub repository, not from other randos. Two, I think both of you are thinking this code is more complex than it is. Someone who's only been writing JavaScript for a couple months could write something with this level of complexity, and could do it in a day. I'm certain both state actors and skiddies already have more sophisticated tools than this.

  • Libertarian guy with Asian wife
What makes you think this clown is libertarian?
 
A JS developer, Brandon Miller, has added anti-Russian/Belarussian malware to a nope-ipc, a module that is used in, amongst other things, the Vue.JS console. This means it has wide-ranging effects on developers using Vue. I don't know JS but it appears to try and delete .., ../.. , and / , so it's going to fuck up your project, and whatever directory your project was saved in. If you were dumb enough to run it as root, possibly your entire filesystem.
https://github.com/RIAEvangelist/node-ipc/issues/233 (a)
You know, someone once asked me why I didn’t start a forum on a MEAN stack instead of a LAMP stack. This is why. Shit like this.
:suffering:
 
There's no way he wanted to fuck that tranny. He just wanted to sperg out about electric vehicles, it's not possible that anything else was going on

What makes you think this clown is libertarian?
You really think someone would do that? Just go on the Internet and tell lies?
 
If you read their statement, they've been flooded with so much data because of the war they've not been able to back up stuff.

It's sort of ironic that this guy did Putin a massive favor by fucking over a nosy Western NGO.
I don't think what I'm about to suggest actually happened, but people like this are obviously easily influenced, and in the modern political arena the successful false flag is one of the few if the only immediately effective tool of persuasion, so it's not too far out there to think smart glowies would be looking to try and convince everyone they can on the other side to make that side look like complete assholes.

Again I don't think this is why this dude did what he did, I think a blue, bird-shaped brain parasite is more likely, but it's an interesting angle to consider in a glow-in-the-dark world.
 
What a walking stereotype.
  • California code monkey with ego complex
  • Obsessed electric vehicle hobbist
  • Crashes his own repo for clout
  • Oversells his skill as Director of Front End Technology rather than web developer for Spanish clothing company
  • Libertarian guy with Asian wife
  • Takes compound last name (listing hers surname first)
  • Lists his name in niponeese on Facebook 武嵐呑 aka weeb
  • Philanderer
In reality this guy is a passive code monkey who is petty, jaded, and cannot appreciate anything. Always coveting what others have constantly looking for greener grass. Every time he gets what he wants it never meets the rosy and romantic vision that was in his head. This project was probably his greatest source of pride. Now that he has destroyed his best work the next step is to ruin his tenuous marriage and then become a troon.
View attachment 3086730
Wow his Youtube channel is exactly what to expect from someone who has never touched a soldering iron yet really loves electronic vehicles. Looks like his two friends are the mechanical and hardware guys while Brandon is the designated camera holder and tool fetcher. A troon saga is looking more and more like a reality.
Shaggy but with down's syndrome.
 
Tragically, the tranny is also very ugly.


imagen_2022-03-19_160549.png


:story: And a typical one.
 
What a walking stereotype.
  • California code monkey with ego complex
  • Obsessed electric vehicle hobbist
  • Crashes his own repo for clout
  • Oversells his skill as Director of Front End Technology rather than web developer for Spanish clothing company
  • Libertarian guy with Asian wife
  • Takes compound last name (listing hers surname first)
  • Lists his name in niponeese on Facebook 武嵐呑 aka weeb
  • Philanderer
In reality this guy is a passive code monkey who is petty, jaded, and cannot appreciate anything. Always coveting what others have constantly looking for greener grass. Every time he gets what he wants it never meets the rosy and romantic vision that was in his head. This project was probably his greatest source of pride. Now that he has destroyed his best work the next step is to ruin his tenuous marriage and then become a troon.
View attachment 3086730
Wow his Youtube channel is exactly what to expect from someone who has never touched a soldering iron yet really loves electronic vehicles. Looks like his two friends are the mechanical and hardware guys while Brandon is the designated camera holder and tool fetcher. A troon saga is looking more and more like a reality.
Tards like him give us programmers a bad rep.
On the other hand, he can be an useful tard by making this line of job much less popular. Last thing I need are dudebros who can barely sum 1+1 becoming programmers. Sure, we got fucking Pajeets whose code quality is terrible but still.
 
I know you're being sarcastic but I think that only applies to accidental damage.

This "I hope you all learned a lesson about open source software" attitude is infuriating. It's like when I hit a car after it turned left against a red light and the driver tried to say, "Yeah, I ran the red light, but didn't you learn to keep an eye out for the drivers around you?"


I'm not so sure. I'd definitely be interested in hearing some arguments either way even if this doesn't end up going to court, but just from my armchair it seems pretty clear to me that all the major licenses have the "at your own risk" thing locked down. Is there precedent for intentional maliciousness being an exception to such statements?
IANAL, but typically contracts do not preempt criminal charges. You can’t just have someone sign a contract, and have it insulate you from criminal suits. Civil suits are a different thing, but I’m reasonably sure this’d fall under whatever cyber crimes statute the US has. In addition, I think the way those cyber crime suits work is they are bought by the state, and the state hasn’t agreed to the license anyway. At most, I see it being argued for a bit in court if charges are brought. Honestly, he deserves whatever is coming to him, NPM is a fucking mess, but this guys a right twat to have abused his position of trust like this. At the very least it’ll hopefully encourage JS developers to be a little more careful about dependencies, although it can be hard, since in JS development dependencies rapidly become horrendously nested, cause even now the standard library is quite lacking.
 
Back