Slashdot Mirror


SourceForge Responds To nmap Maintainer's Claims

An anonymous reader writes: A few days ago, the maintainer of nmap (an open source network mapping tool) complained that SourceForge had taken over the nmap project page. SourceForge has now responded with a technical analysis of the nmap project history. They said, "We've confirmed conclusively that no changes were made to the project or data, and that all past download delivery by nmap on SourceForge was through our web hosting service where content is project-administered."

They detail the history of services used by the nmap project, and use screenshots from the Internet Archive to show how long the project was empty. SourceForge said, "The last update date in 2013 relates to the migration of the nmap project (along with all other projects on the site) from SourceForge's sfx code base to the new Apache Allura-based code base. This migration was an automated operation conducted for all projects, and this platform change did not augment data in the Project Web service or File Release System. We therefore conclude that no content has been removed from the nmap project page." They also confirmed that nmap downloads were never bundled with ads: "Infosec professionals do not generally wish to install secondary offers."
Note: SourceForge and Slashdot share a corporate overlord.

16 of 172 comments (clear)

  1. Nice phrasing dice by Anonymous Coward · · Score: 4, Insightful

    There's no apologizing for the malware spewing shitfest that SF has become. Do the right thing and close the site.

    How long until you guys face trademark lawsuits from the ors and foundations that don't want to be associated with your site?

    Because that's the next step. I'm surprised it's not happened already.

  2. Obvious solution by gatkinso · · Score: 4, Insightful

    Migrate to github. Shut down SF repo.

    --
    I am very small, utmostly microscopic.
    1. Re:Obvious solution by Anonymous Coward · · Score: 5, Insightful

      You can't. As in the case of GIMP, they took control from the guy who owned the actual dev account for the project, took new binaries from the official GIMP site, put their malware in and called it a day.

      Shut down if you like, watch as they reopen a "mirror" of your project.

    2. Re:Obvious solution by coofercat · · Score: 5, Insightful

      +1 for this, and a strong caution about using someone else's server to host your stuff. One day, Github might well end up doing the same thing (yeah, I know it seems unthinkable now, but SF looked pretty cool and was never going to do something like this just a few years ago too).

      PS. This post noticed that you have a virus on your PC. Please download AwesomeSuperWhizzoCrap and run it to fix the problem.

  3. dafuq? by Penguinisto · · Score: 5, Insightful

    "Infosec professionals do not generally wish to install secondary offers."

    WTF? Nobody with a clue wants to install "secondary offers". Otherwise we'd seek that crap out and install it ourselves, dumbasses...

    --
    Quo usque tandem abutere, Nimbus, patientia nostra?
    1. Re:dafuq? by dunkindave · · Score: 4, Insightful

      "Infosec professionals do not generally wish to install secondary offers."

      WTF? Nobody with a clue wants to install "secondary offers".

      That's the point. Infosec professionals normally have a clue, and the general population in general does not. Desire isn't the problem, understanding the situation is.

  4. No Trust by Anonymous Coward · · Score: 5, Insightful

    Here's your problem, SourceForge. You've abused your trust with the community. Why should the community trust you? Even the evidence you provide requires the community to trust you haven't been doing nefarious things to ensure the evidence looks good later on when you need it. Sure, it's far fetched.

    And 15 years ago, I would have said it's far fetched that SourceForge would include malware with their downloads. Today? We're a stepping stone away.

    How can SourceForge fix this? I don't know. I simply don't get myself into this sort of situation in the first place, so I don't have to weasel my way out of them.

  5. Re:Slashdot is Bullshit by Anonymous Coward · · Score: 5, Insightful

    "We" haven't come to anything. You're not part of any major projects and have no say in any of this. You're just a worthless spectator.

  6. Re:Controlling the message by Monty845 · · Score: 1, Insightful

    I'm done with Slashdot. Its long had quality issues, but this is just over the top. The whole network of companies is contaminated at this point. Deleting my Slashdot shortcuts.

  7. Sourceforge eats good software and shits it. by Needs2BeSaid · · Score: 3, Insightful

    They ruined Filezilla
    They pissed of GIMP.org
    .... now nmap.

    --
    Some things need to be said...
  8. Re:Slashdot is Bullshit by msobkow · · Score: 2, Insightful

    Who is this ranting, cross-posting idiot with a "mission"? Why should anyone give a damn about them posting the same drivel over and over to every comment branch on this thread?

    --
    I do not fail; I succeed at finding out what does not work.
  9. That's it- I'm out by eigenstates · · Score: 2, Insightful

    No more DHI Group anything, ever.

    You want to bitch about it- call these people- don't even bother posting here:

    http://www.dhigroupinc.com/investors/corporate-governance/default.aspx

    --
    quis custodiet ipsos custodes
  10. If they're to be believed... by aardvarkjoe · · Score: 4, Insightful

    If Sourceforge is to be believed -- that all they did was create a mirror, without touching the owner's page -- then that's not in itself a bad thing to do. Providing mirrors of open-source software would be perfectly acceptable for another organization.

    But this isn't another organization, this is Sourceforge. They've already demonstrated that they have no qualms about using their "mirrors" to distribute malware by misrepresenting the content of the downloads. Therefore, they have no credibility to be running a mirror, and nobody should trust anything that comes from their download pages.

    --

    How can we continue to believe in a just universe and freedom to eat crackers if we have no ale?
  11. Soylent News Looks pretty good by FreeUser · · Score: 3, Insightful

    As a result of this, I've been looking for a slashdot alternative, since I expect Dice to wreck this site as well in the not to terribly distant future. Sad, because I've been here for years.

    Anyway, Soylent News looks promising:

    https://soylentnews.org/ ... anyone have any other suggestions? Kiro5hin looked good at one time, but went full-bore political.

    --
    The Future of Human Evolution: Autonomy
  12. Logging Out by l0ungeb0y · · Score: 4, Insightful

    I know that people posting "I'm done here" is usually a sign over short term anger -- but I am feeling utterly compelled to abandon this site. After the years of general decline and now these actions by Dice Network I really don't see any other option.

    Seeing the abuse of SourceForge by Dice was cause for concern
    Seeing that they were actively denying the acceptance of stories reporting this was distasteful
    Seeing the earlier Slashdot "story" that essentially put words in the complaining code maintainers mouth while downplaying everything was alarming
    Being fed this one sided propaganda piece by Dice/Sourceforge/Slashdot is simply taking things too far.

    Fact of the matter is people put their trust into SourceForge to host their code repos -- SourceForge decided to no longer act as a trusted partner and started hijacking popular software to repackage it with adware for their own profit -- profits not share with the creators or maintainers of the software nor done with their consent.

    Such behavior is exploitative to those who have labored to create those OSS Projects and SourceForge's actions not only damage their relationship with the Developers of those projects, but is an affront to the entire OSS Community world wide.

    Due to the actions of Sourceforge and The Dice Network's use of Slashdot as a propaganda tool to first quash all discussion of their actions then disseminating these ridiculously slanted "stories", has caused Slashdot to lose all credibility. I now see Slashdot as a news source to be on the level I view FOX News and will for now on hold them in the same regard

    *logging out*

  13. Re:Slashdot is Bullshit by Ramze · · Score: 5, Insightful

    This is the crux of the issue.

    When SF takes over a page and replaces an installer from the project with an SF program; it's deceptive and fraudulent.

    If that SF program is a modified binary, a modified installer, or even a "download helper" or a wrapper around the original installer which prompts for crapware; SF is misrepresenting the download as coming from the project rather than SF unless stated clearly otherwise.

    When a user downloads this fraudulent download, they blame the crapware on the project authors and not SF. This isn't simply a theory - the feedback on many projects includes numerous negative reviews due to this crapware which they falsely attribute to the project creators. This negatively impacts the projects and their reputations with their users. Real financial harm could be done if fewer donations are made due to the harmed reputations - or support contracts not renewed due to suspicions.

    I believe SF's recent assertion that they will no longer do this is, at least in part, because they know this sort of activity will not stand up in a court of law and it is detrimental not only the projects they've vandalized, but to themselves in showing their poor character and lack of trustworthiness in choosing to implement such a scheme to begin with. Stopping the harmful practice does not undo the harm already done, so it would be nice to see some legal recourse to inspire fear in those who would dare to do this sort of thing in the future.

    Even when an author approves such nefarious wrappers and crapware through an agreement, SF is using deceptive practices towards users by not clearly distinguishing their regular binary downloads from crapware downloads. The same green "download" button appears in either case, but with crapware there is sometimes a small print of "installer enabled" and an "i" in a circle one can hover over which will display that there may be crapware in the installer. In filezilla's case, it warns of an ad-supported installer.

    http://sourceforge.net/project...

    IMHO, there should be clear distinctions between binaries offered by (or approved by) the project author and those offered or modified by SF as well as clear indications of when one is downloading a "download helper" or advertisement supported downloader or installer.