Slashdot Mirror


Napster Attacks Open Source Clone

Anonymous Coward writes "In a letter, the author of a Gnome-based Napster clone was pressured to remove distribution of the program due to the fear that source availability would make the Napster servers less secure [if] gnap is not ceased." UPDATE by RM: Ryan Dahl, gnap author, has spoken with Napster, says they've come to a happy understanding, and has removed the "letter from Napster" (and his response to it) from his page. He also tells us that he and Napster are working together on an article for tomorrow, which we eagerly await.

141 comments

  1. dead link by Anonymous Coward · · Score: 1

    FYI: Letter link is dead/inaccesible.

  2. another unix napster client by DAVEO · · Score: 2

    http://www.gis.net/~nite/

    --
    -DAVEO
  3. Permission? by matty · · Score: 0
    I don't seem to have permission to read the letter. :) Can someone mirror it, please? Or, email it to me, and I'll post a mirror.

    -matty

  4. visit the gnap link by Wah · · Score: 3

    and end this before it gets silly, non-issue.

    --
    +&x
  5. grrr by fringd · · Score: 0

    security through obscurity sucks. those napster lamos should just not bite boners.

  6. The problem is... by DanJose52 · · Score: 1

    once the source is out in one place, people have it, and it spreads...like wildfire...napster cannot win this fight and should just welcome its counterpart. It's hard to stop the spread of source code.


    Dan

  7. Ain't that the pot calling the kettle black by JohnG · · Score: 2
    Hmmm, isn't napster the same program whose creators are being sued by the recording industry for aiding in the piracy of MP3s?
    There seems to be a double standard in a borderline legal product that was created for the sole purpose of piracy (they say it wasn't, but come on, what did they think was going to happen?) complaining because a clone is compromising it's own security.

  8. Resolved? by wampus · · Score: 4

    From the gnap homepage:

    1999.11.29
    Thank you to all the people that supported me today. The situation was fairly heated for awhile. All I really want to do is code this client. Let me say that Napster (the person) and I discussed this issue completely. He was very resonable and nice when I got to talk to him alone. I hope we can work together to make Napster a good service.

    gnap is and will continue to be GPL.
    ---

    1. Re:Resolved? by Citrix · · Score: 2

      I know this is offtopic but really, post like this should not get moderated up.
      This specific instance probably isn't an issue but cut/pasting a chuck of text from another page and posting on /. could possibly get Rob and friends in trouble. I've seen post like this many time before and this seems to be the easiest way to inflate your Karma.
      Anyway, go ahead a mark this as flambait.
      Citrix

      --
      Leknor
      http://Leknor.com
      "So many idiots, so few comets"
    2. Re:Resolved? by quadong · · Score: 3

      From the top of each and every comment section:

      "The Fine Print: The following comments are owned by whoever posted them. Slashdot is not responsible for what they say."

      And here is how to get moderated up:

      1. Post quickly
      2. Post a link or block quote
      3. Post a very long self-written comment (note that the content, to first order, doesn't matter)
      4. Tell the moderators to moderate you down
      5. Use a lot of white space
      6. Already be at +3 or +4, most people will moderate up at this point assuming that it must be good

      And, oh yes, there is also:
      7. Say something original that adds to the conversation. Possibly something that was missed in the original posting or an update/clarification to that post. Possibly a new and different way of looking at the issue.

      Sigh, I almost want to go set it so that I can't see scores and I never get moderator points, but you know what? I will still see all these comments which are not about the real topic, but just about moderation and I won't be able to see the context, so I'd just have to go turn them back on to see what was going on. Look at me! This conversation is supposed to be about Napster! have I said anything about Napster yet? Could I, in fact, be posting this without even knowing what Napster is? Am I just wasting space on the comments page?

      Now that everyone can see their Karma, Slashdot seems to have become, for a lot of people, a game of "who can get their Karma highest." Wake up people. Karma doesn't matter. The issues matter. I'd call for complete elimination of moderation, but that will never happen. A comprimise would be, oh I don't know...
      1. Hide Karma. People can't fight over what they don't know about.
      2. Remove the automatic +1 bonus for high Karma. This way there is nothing to fight about, not even an invisible something.
      3. Remove metamoderation. It was a good idea, but how many people activly meta-moderate anyway? It's just more time spent not reading things that matter.

      So there's my rant, I don't know why I did it here and I realize that by putting it here, I am part of what I am complaining about, but I had to say it.

    3. Re:Resolved? by paranoid.android · · Score: 2

      How could this type of post get "Rob and friends" in trouble? It explicitly states at the bottom of each /. page that Comments are owned by the Poster; if the owner of any copyrighted material finds something of his posted on /., /. is not responsible or liable.

      I think it's good when posts like this get moderated up; they're very informative and I don't have to click through a link to see what the news is.

      Just my opinion.

      paranoid.android

    4. Re:Resolved? by Anonymous Coward · · Score: 0

      >>>>Remove metamoderation. It was a good idea, but how many people activly meta-moderate anyway?

      Well, I do.

      Although, I pretty much leave alone anything that was moderated up. When I meta-moderate, I'm mostly looking for posts that were unfairly moderated down.

    5. Re:Resolved? by Citrix · · Score: 2

      I know it says Comments are owned by the Poster but the reality is Rob/Andover/whoever is ultimatly responsible for /. I work at a bank and we disclaim everything we can but that doesn't really matter because if/when there is a dispute it is the courts that have the final say.
      If disclaimers were truly meaningful, Microsoft should have disclaimed it's business practices. :-)
      Citrix

      --
      Leknor
      http://Leknor.com
      "So many idiots, so few comets"
    6. Re:Resolved? by cybaea · · Score: 1
      How could this type of post get "Rob and friends" in trouble?[...]/. is not responsible or liable [for postings].

      Actually, as the publishers they presumably are liable. Compare it to newspaper editors who routinely gets sued.

      It is (in most cases) the publication of material that is illegal. I can write all the treaties I want at home denouncing [insert ethnic group here] as sub-human and advocating that they should be treated as pack-animals, if I so desire. That is legal in most free countries: I'm entitled to my opinions, no matter how offensive. The problem arises when the material gets published - that's when the offence occurs. I may think like a racist (for example), but I can not advocate it in public. No can you (or "Rob and friends") even if you use my words.

      Disclaimer: I'm not a lawyer - don't take anything I say serious.

      --
      Hi!
    7. Re:Resolved? by Chandon+Seldon · · Score: 1

      Actually, as the publishers they presumably are liable. Compare it to newspaper editors who routinely gets sued.

      The difference is that the Slashdot crew doesn't do the publication or editing --- they don't look over the comments before the comments are posted, and therefore can disclaim responsibility for the comments.

      --
      -- The act of censorship is always worse than whatever is being censored. Always.
    8. Re:Resolved? by CrayDrygu · · Score: 2
      3. Remove metamoderation. It was a good idea, but how many people activly meta-moderate anyway? It's just more time spent not reading things that matter.

      I came across your post while I was -- guess what -- meta-moderating, and I just had to comment.

      You may think of meta-moderation as more time spent not reading things that matter. Well, good for you. Don't do it, then. I, on the other hand, have found some very interesting and insightful comments while meta-moderating, and have even become interested (even if only for a brief while) in topics that I otherwise would have held no interest in whatsoever. That's part of why I do it, in fact. Sure, there's a lot of crap that goes through there, but you can just click the little "Fair" button and scroll past it. Occasionally, though, you get that one comment that makes it all worth the trouble. The one that makes you think.

      --

      --
      "I personal[ly] think Unix is "superior" because on LSD it tastes like Blue." -- jbarnett

  9. Letter Gone and... by Unknwn · · Score: 1

    He's taken the letter down. He says he spoke with Napster (the author of the program) and the guy was nice and that they're going to work together.



    --
    Jeremy Katz

  10. Yet another proprietary protocol? by Asparfame · · Score: 3

    What makes some of these companies think that whenever somebody writes a piece of software that exploits the flaws in their software, it's not their fault? This is just like the whole DeCSS business. Big (well, Napster isn't that big in this case) corporates trying to protect their "proprietary" software when the only reason it needs protection is because it's weak. It also seems pretty hipocritical to me when Napster, a company which is basically devoted to assiting people engaging in music piracy, tries to shout the same "it's mine!" call as the music industry. I don't know about you, but this I downloaded the gnap source code as soon as I saw this posted.

    --

    There's no reason for a sig here.

  11. The IRC discussion by Carl · · Score: 3

    Miguel de Icaza's activity log has a link to the irc discussion that the author of gnap had with the people from Napster. I am not sure if this discussion took place before or after he received the letter.

    1. Re:The IRC discussion by Asparfame · · Score: 1

      darn. That also seems to have been taken down. :(

      --

      There's no reason for a sig here.

    2. Re:The IRC discussion by Roundeye · · Score: 2
      It took place before the letter. This was cited on hack the planet yesterday.

      The IRC conversation shows that Napster and one of his "partners" were being idiotic dickheads about the whole situation. I took it that de Icaza et al got motivated due in good part to the IRC conversation.

      The arrogance and stupidity of the Napster partners is staggering. Based upon their hype one would think they were going public next week and had a staff of thousands. Based upon their technical discussions one would think they were trying to figure out pointers to get through "Intro to C". These guys will fortunately point the way to more capable companies who wish to accomplish the same thing. Their blatant mistakes will be avoided by smarter people next time around.

      --
      "Cause there's 40 different shades of black, so many fortresses and ways to attack, so why you complainin'?"
  12. Before freaking out by jfunk · · Score: 5

    Look at the comments on the main page.

    The Napster guy is valid in his assumption that open specs will cause lots of hacking. However, he seems to forget that keeping it closed will not stop hacked clients from emerging. Gnap is proof of this.

    If you're going to bombard Napster with email, don't flame. Just indicate that security-through-obscurity simply doesn't work. Any sort of protective measures he wants to do should be done on the servers, not so much the clients which everyone has access to.

    I personally would like to see lots of encryption.

    1. Re:Before freaking out by Lev_Arris · · Score: 1

      I just wonder when developers will finally realize that if THEY do not support Linux SOMEBODY WILL! (Even if the latter has to reverse engineer the software to port it)

      As DeCSS and now Napster have shown, the Linux community simply is one of do-it-yourself people and if somebody locks them out, (by not supplying a client or whatever) they will hack they way in.

      Anyway, I've read that the author of gnap and Napster are discussing the problem and I'm pretty confident that they'll find a solution.

      Just my 0.00245 LUF ;)

    2. Re:Before freaking out by Control+Group · · Score: 2

      Two things: first, if it can be reverse-engineered, it can and will be hacked, regardless of its status as open or closed source. Second, the easiest way to avoid hacked clients is to provide the clients in the first place, so there's no reason to hack them. Assuming that the developer(s?) don't have the time for that, help with it from the respective OS communities probably ought to be solicited, not rejected--the friendlier they are about others coding, the more control they can retain over the code that's being written.

      Oops, I lied, there's a third: didn't it occur to anyone at napster that client-side security isn't really the tightest one can have (licq's "spoof UID," anyone?)? if that's napster's only security, client hacks are the least of their worries, IMHO.

      On the other hand, I've never tried to write a secure client-server protocol, so maybe I'm full of it.

      --

      Reality has a conservative bias: it conserves mass, energy, momentum...
    3. Re:Before freaking out by Betcour · · Score: 1

      Good programmers design a solid and secure protocol first, then write the app they have in mind. The problem is that most programmers start the app first, then build the protocol around it as the app grows. They get buggy, overly complex and unsecure protocols... that they can't get rid of because everyone is using their app by the time they realise their mistake.

    4. Re:Before freaking out by Imperator · · Score: 2
      (licq's "spoof UID," anyone?)

      Yeah, the first time I saw that I laughed. I haven't used ICQ seriously since.

      --

      Gates' Law: Every 18 months, the speed of software halves.
    5. Re:Before freaking out by greenrd · · Score: 1
      Mind you, email From:'s are easy enough to forge, and we still all use email...

    6. Re:Before freaking out by fwr · · Score: 1

      Yea, but you can PGP it if you really need to be sure, with a humongous key like 2048 bits or over...

    7. Re:Before freaking out by kurowski · · Score: 1
      I personally would like to see lots of encryption.

      No no no! "Lots of encryption" is not the answer. A correctly implemented, wee bit o encryption, with a secure protocol is the answer.

    8. Re:Before freaking out by Jeos · · Score: 1

      Actully there was a linux client for Napster already out. It just wasn't open source. Also it didn't have a GUI and didn't work that well.

      They have some weak security measures you have to pass to connect to a Napster client, and didn't want an open source client for security reasons. However they were trying to use security through obscurity, which dosen't work. Any idiot can run a packet sniffer and try to figure out what's going on on there own.

  13. I am surprised... by leiz · · Score: 1

    I am surprised napster is _suing_ someone instead of being sued. Considering the fact that napster itself barely seems legal as it is, I'm also surprised that RIAA haven't shut napster down yet.

    And what exactly would be the harm of releasing the source code for napster? As long as it only transfers mp3s and it is not used to transmit viruses and trojans, it is safe to use. If napster is really serious about protecting its users, it should open up the source and let people work together to fit napster's security problems (if any, surely there's gotta be a bug somewhere) instead of hiding the source, having someone discovering the bug, exploiting the system from three weeks, and then napster respond with a patch.

    just my $100/5000



    _______________________________________________
    There is no statute of limitation on stupidity.

    1. Re:I am surprised... by four · · Score: 2

      The article is in correct. Napster is not sueing, is not planning on sueing, ever will sue , or has even ever threatened to sue me. The whole thing has been a massive misunderstanding. (i am the gnap author)

      --
      -- four
    2. Re:I am surprised... by cybaea · · Score: 3
      Considering the fact that napster itself barely seems legal as it is, I'm also surprised that RIAA haven't shut napster down yet.

      According to this Salon article lovingly preserved by Yahoo news service, they have indeed started to try and do just that:

      And to top it all off, the RIAA this week slapped an MP3 search engine called Napster with a lawsuit, claiming that Napster contributes to piracy by letting users swap file libraries with each other. Never mind the fact that many of the songs that people are swapping might be legal.

      --
      Hi!
    3. Re:I am surprised... by cybaea · · Score: 2
      The whole thing has been a massive misunderstanding. (i am the gnap author)

      First of all: that you for posting and contributing to this thread on /..

      However, it would be so much more useful if you would help us to clear up the "misunderstanding". Obviously a lot of us were sufficiently concerned to (a) start this thread and (b) contribute to it.

      It does not help that you have removed the original letter. That does not sound like a misunderstanding to paranoid /. readers like myself (:-)). It sounds like you were bullied into submission. And we don't like that, so this thread will continue and I suspect that Napster has lost whatever goodwill they had within this community at least.

      If Napster is really serious that this is a misunderstanding then they should make public the whole story, unedited. This includes original e-mails, IRC logs, etc. Add whatever comments you and they think are appropriate. Then, perhaps, we will all forgive them and be friends ever after (or something)....

      At the moment it looks like they are using strong-arm techniques against an Open Source movement. That approach is going to win them few friends.

      --
      Hi!
    4. Re:I am surprised... by ghazban · · Score: 1

      I will reiterate. they are not suing . Sheeesh.

    5. Re:I am surprised... by cybaea · · Score: 1

      Oops - I wanted to write:

      First of all: thank you for posting...


      --
      Hi!
    6. Re:I am surprised... by BJH · · Score: 1

      Yeah! 'Cause we're /. readers and we're R3477Y KEWL!!!!!

      Come on, get off your high horse. The problem was between gnap's author and Napster - and they settled it between them. That makes it a private matter.

      While Napster might be better off going public with what they did and said (if only to clear the air), there is ABSOLUTELY no excuse for ragging on the author of gnap. I mean, what does he care whether you like the fact that he removed a letter that now has little relevance to what he is doing? Free source != full disclosure of private correspondence. F'chrissakes, it's HIS BUSINESS, so leave him alone. Sheesh.

    7. Re:I am surprised... by Anonymous Coward · · Score: 0

      Concerned? You mean Rob saw an opportunity to get a bunch of people to freak out and to wave the big G word around, and you all flocked like the sheeple you are... ppffffft.

    8. Re:I am surprised... by Anonymous Coward · · Score: 0

      This company (Napster) is being defended by same company (mine) that defended Diamond's RIO.

      As such, it should be legal very soon ;-)

      I choose to post this as AC, so sue me!

  14. Thanks Rob Limo by boc · · Score: 0

    sigh... you should talk to Justin.

  15. GNoooooooo! by Listerine · · Score: 2

    Gnot when Gnapster was just getting goood! Gnow the company had to go and pull this shit... goddam give it a break, its gnot like anyone's stealing money from the company, it has no real future except to helpe me pirate my mp3s...

    1. Re:GNoooooooo! by Anonymous Coward · · Score: 0

      I'M GOING TO FUCKING

      GKILL

      YOU

      GFUCKER

      note: these words represent "GNU" speak and therefore cannot be moderated down because I speak the language of RMS and all that is good. moderation is against freedom! can you pass me a gbeer?

  16. When do developers learn... by kgasso · · Score: 2

    never, apparently. Didn't ICQ teach us that putting 'security' in the client was pointless? Come on, whining because someone released information detailing the protocol(s) used is pathetic. Security through obscurity, client side security, whatever you want to call it.. developers need to understand the plus side of the open source movement, as they will have problems pointed out (and usually solutions presented) by people who care, rather than having the problems unknowingly exploited by some script kiddies.

    People seem so quick to hop on the lawsuit bandwagon when the words "reverse engineering" emerge, but think.. Using tcpdump (or similar utilities), I can see what's being transmitted, and work from there. Thinking that your protocols will be kept secret by not releasing source doesn't make sense.

    (a bit offtopic)
    I'm reminded of one software reviewer's criticism against a windows "firewall" product called "Lockdown 2000". The creators of the product encrypted the executable, but they forgot that it was decrypted and loaded into memory.. just examine the memory with a utility and.. you get the idea. The company later threatened to sue the software reviewer for "cracking" their software (more than likely, fueled by the fact that the software blatantly lied about what it was "protecting" against, which was basically nil).

    Let's just remember, something like napster obviously uses networking to communicate.. and as far as I know, sniffing your own system is perfectly legal.

    (just my $.02)
    --

    1. Re:When do developers learn... by Anonymous Coward · · Score: 0

      Let's not be too fast in pointing fingers. Look at it this way: Notice that in the napster software users that share their mp3s are only recorded through their username and not their ip address. Maybe the reason why napster close up their source is to protect all of you people that use napster so that you don't get sued like those poor Carnegie Melon students. The RIAA can't simply look up at the source to figure out where the ips are stored and proceed to sue the hell of napster users, they have to ask napster first and if he's really a good guy he can just dump the ip list in the toilet. This whole "corporate=evil" image that's floating around in slashdot bothers me. Not all companies are evil, people.

    2. Re:When do developers learn... by kgasso · · Score: 2

      Yes, it does "protect" the user somewhat, but if someone was to get the file from the user, I'm assuming that there's a direct connection to their machine (assuming, because: 1. downloading through a central server would be illogical and 2. the napster setup under 'doze requires direct access to the machine on at least one port for data transmission, as documented in firewall setup). When this direct connection is requested/established, there is all sorts of diagnostic software ('netstat' included) that can tell you the remote peer's IP.
      --

    3. Re:When do developers learn... by blackwizard · · Score: 1

      Agreed -- with a closed source product, how do we know that the product isn't doing something that it is not advertised to do -- like sending out personal information, opening up my computer to crackers, etc? When I tried the closed-source napster, I created a 'testuser' account on my linux box, and ran it from there... there was no way in hell that I would risk running a closed-source product from an untrusted company using my main user account. I shudder at the idea of using it on a Windows box; that would essentially open up my entire computer to attack, should anything sneaky be in the client. Gnap, on the other hand, I can trust! Why? Because when the source is open, I can be reasonably sure that there is nothing malicious in it. (and if it was ever found out that there was, someone would make a huge stink about it and I would find out.) And besides, if I suspect foul play, I can always look over the source myself. It's a win-win situation for everyone! Unless you happen to want to make money off of proprietary code, or something...

    4. Re:When do developers learn... by alecto · · Score: 1

      This is absolutely true. A direct connection is established to actually transfer the MP3 file, which can be seen in netstat, among other things, as you said.

      Transferring MP3s through a central file server would likely open Napster to more liability for potential copyright violations than they would like to assume.

    5. Re:When do developers learn... by Foogle · · Score: 2
      Well, I don't want to be a prude here, because I'm just as guilty of MP3 Piracy as anyone. But let's be honest -- why do Napster users need protection? The only reason the RIAA would be prosecuting people would be because they are pirating copyrighted material. Now, I like getting free music, but most of the time it happens to be illegal.

      The bottom line is that the RIAA is not "Big Brother". The only reason they're going to bring a suit against someone is if that person is doing something illegal. If they are doing something illegal, then they probably deserve the charges. They don't need protection. Piracy is illegal, plan and simple.

      -----------

      "You can't shake the Devil's hand and say you're only kidding."

  17. Security through Obfuscation? by sparkmanC · · Score: 1

    Why don't they simply let the linux folks pound on it for a while and pick up the (open source) bug fixes?
    Otherwise people will just find the 'sploits on their own and, well, 'sploit them.
    Security behind compiled code just isn't security.

  18. Read the link. by BJH · · Score: 3

    Roblimo, at least look at the link before you post a story. There's been a number of stories on /. lately that caused a lot of problems for a few people and got a whole lot more people in an uproar simply because the story poster didn't check the linked story properly.

    1. Re:Read the link. by Bishop · · Score: 1

      It is ironic really. Slashdot condems law enforcement and others when they falsely accuse someone making that person's life hell. Yet the story editors often falsely accuse others when posting new articules.

      I like Slashdot. I just wish a little more thought went into the headlines.

  19. Headline misleading by Xerithane · · Score: 4

    I think that the headline for this story is very very very misleading. This is like the 5th time in the last couple weeks that /. has ramped things up more than they really are. He says specifically that Napster (the person) was a nice guy.. doesn't sound like a threatening attack to me from what I read. Please, try to be an unbiased news source from now on, I'm resorting to ignoring any and all comments from the posters at this point (Especially Roblimo and michael, hemos at least apologized)
    I'm not trying to start a flame war,but I hope someone pays attention to this.

    --
    Dacels Jewelers can't be trusted.
    1. Re:Headline misleading by etherised · · Score: 1

      mildly off-topic but a very good point. i have noticed this also and just wanted to add voice to the plea that this gets attention from the /. crew.

      stay good, slashdot, stay good!!! --kiki

    2. Re:Headline misleading by Anonymous Coward · · Score: 2

      Note that he said Napster was nice WHEN ALONE...

      The threats were coming from another Napster, Inc. employee whom I will note name but will quote, "Fuck him. napster, he's goign to fuck us."

      "All I know is some dipshit 17 year old is trying to fuck me."

      "And I will fuck each and everyone motherfucking one of you."


      They spent hours arguing over this last night... and it seems like Napster (the person) is a nice guy when talked to alone... this other guy isn't nearly as nice to gnap...

      BTW, there are logs floating around of the discussion they had last night in #gnapster on EFNet... if anyone manages to get ahold of them, read it... you might not like this other developer that much. :)

    3. Re:Headline misleading by dilger · · Score: 2

      You're right, the headline is inaccurate. But...

      I'm resorting to ignoring any and all comments from the posters at this point (Especially Roblimo and michael, hemos at least apologized)

      I think it would be better if you kept reading the comments, and kept pointing out problems such as these. That sort of tacit approval (or at least lack of disapproval) doesn't fix the problem. Roblimo and others set too powerful an example for this sort of thing to be ignored.

  20. Another /. mistake... by Anonymous Coward · · Score: 0

    Well, it turns out that 15 seconds of work AGAIN could have avoided this problem. there is no lawsuit, there never was a lawsuit, and there isn't a problem.

    Slashdot - lies for nerds, stuff thats ignorant.

    OPEN THE SLASHDOT SOURCECODE OR STOP CLAIMING TO SUPPORT OPENSOURCE.

    1. Re:Another /. mistake... by blackwizard · · Score: 1

      Hey buddy, guess what -- the slashdot source is out there, and a lot of other sites use it. It might not be the latest version, but who cares; It's not our right to always have the latest code. Having any code at all is a priveledge that is much appreciated.
      Pretty ironic that 15 seconds of work on your part could have prevented you from screaming that out.

    2. Re:Another /. mistake... by Anonymous Coward · · Score: 0

      The source on that page is months out of date. You know it, I know it, and you can bet your ass Andover knows it and is very happy about it.

      Is the source ours by rights? Hell no. Do we have any ability to force it's release? Hell no.

      No... the only reason to expect the source to "slash" to be up to date and out there is the constant championing of OpenSource here. Over and over again we hear about how important OpenSource is, how slash readers dont't trust proprietary stuff.

      Hypocrasy. Of course, that is nothing new on /.

      If, say, Microsoft releasesd the source to IE 2.0 and said "OK - now we consider ourselves to be part fo the OpenSource" world there would be flames a-plenty about how stupid and useless it was to release code so out of date.

      But /. can do no evil in it's minions eyes.

      The reality is that keeping "slash" effectively closed source has dramatically increased the value of /. when it wanted a buyout - and now that it has gone corporate I doubt we will ever see the code.

      No problem, more power to 'em. But it is very funny when they bitch about how the "evil capitalist" companies keep their source closed.

    3. Re:Another /. mistake... by Vesperi · · Score: 1

      Well I'm not an AC - and I agree completely with this. I wanted to look at the code and see how some things are done, but those functions arn't in the old posted client.

      But I belive there is also a "alpha" archive that's more upto date.

      So when do we start the GPL slash movement :)
      --
      James Michael Keller

      --
      "Linux is not our destination, it is simply the open road to tommorow"
    4. Re:Another /. mistake... by Bob[Bob] · · Score: 1

      Surely the thing that makes Slashdot valuable is its content, not the particular Perl scripts that generate the HTML? I would have thought that most of the people who read Slashdot could easily produce a site with similar functionality, but that's not the point. One of the biggest factors behind the "value" of a website like thisis the number of readers... and you get readers by having useful content. I think the fact that it might use some clever Perl is way down on most peoples' priorities list.

    5. Re:Another /. mistake... by Anonymous Coward · · Score: 0

      why not simply clone it :) make an exact replica and then wait for the flames of hypocrisy to rise up again

    6. Re:Another /. mistake... by Anonymous Coward · · Score: 0

      >>>>No... the only reason to expect the source to "slash" to be up to date and out there is the constant championing of OpenSource here. Over and over again we hear about how important OpenSource is, how slash readers dont't trust proprietary stuff. >>>If, say, Microsoft releasesd the source to IE 2.0 and said "OK - now we consider ourselves to be part fo the OpenSource" world there would be flames a-plenty about how stupid and useless it was to release code so out of date.

      Good point. And absolutely true. Furthermore, these flames would be from exactly the same people who are defending Rob's right to release or not release whatever amount of code he feels like.

      Now, having said all that, let me add that I do, in fact, support Rob's right to not release his code if he doesn't want to. I think it would be really cool of him, and I wish he would, but it IS his right not to do it.

      I do, however, think that pointing to the code that is available and claiming that supports the notion that slash is open sourced is a bit ridiculous. Download it and run it. The posted code bears almost no resemlance to what Slashdot is today. Borland at one time had Turbo C version 1 available for free download (maybe they still do). Nobody announced this with the blanket statement "Borland giving away free compilers!". Same with the slash source that is available, it's interesting from a historical point of view, but it's barely useful, and certainly isn't representative of what the current "product" is capable of.

      OK, I'm done ranting. Just let me stress again that this is *NOT* a flame against Rob or anyone else, is not intended to imply that Rob is doing anything wrong, and is not intended to get Rob to alter his position regarding releasing the slash source. It is simply meant to inject a little reality back into the discussion of whether or not slash is Open Source.

      Thanks for your time...

    7. Re:Another /. mistake... by Anonymous Coward · · Score: 0

      Surely the thing that makes Slashdot valuable is its content, not the particular Perl scripts that generate the HTML?

      Apparently Andover.net doesn't think so. The new owners seem to think keeping it closed source is JUST fine.

      No coincidence that right after it looked like /. was a runaway success the source just sort of ... stopped happening.

  21. Slashdot and (ir)?responsible journalism by elflord · · Score: 1
    Here we go again. Slashdot posts some flame bait and tries to make a flame war out of nothing. Let the "two minutes of hate" begin. Come and scream your outrage against the "bad guys" !

    1. Re:Slashdot and (ir)?responsible journalism by wnissen · · Score: 1

      Yes, but also note that the link provided is dead, meaning that when Roblimo posted the link was alive. Thus he didn't know the affair had been resolved, and was at least justified in posting the story, although we can argue about the title...

    2. Re:Slashdot and (ir)?responsible journalism by elflord · · Score: 1
      From what it looks like (judging by the other posts), the situation was much less adverserial than the slashdot headline and story would have the readers believe. This should be seen for what it is -- a naked attempt on the part of slashdot to incite readers to pour torrents of rage at someone who clearly doesn't deserve it.

  22. But that client is console-only & not open source. by Anonymous Coward · · Score: 0

    The author says it will be eventually, but gnap being open source will probably result in it moving forward more quickly than the console client.

  23. A more serious issue ... by HalJohnson · · Score: 2

    Is whether or not it is illegal to utilize "public services" with non-approved access methods. In particular, utilizing public net services. I am of the belief that if you are running a public server on the internet, you cannot expect people to use the client you specify. Imagine if you only had one browser to choose from? The web is a different concept in that it's decentralized, but ICQ is a good example. ICQ has the lion's share of the latest "hot" market, and as much as they'd like to retain total control, I wouldn't appreciate being tied into one client.

    If we get to the point where the precedent has been set that public services are within their legal right to restrict which clients are able to connect, we're in a position where competition will be severely stifled.

    I'd really like to know if this type of concept already falls under some law, or if its just another grey area in the merging of law and the net.

    1. Re:A more serious issue ... by cybaea · · Score: 2
      Is whether or not it is illegal to utilize "public services" with non-approved access methods.

      Often, it is illegal. It obviously depends on which country you are in, and many other things. I doubt a legal precedent has been set, but some "real world" examples:

      • In the UK at least, just because my front door is wide open that does not give you any right to enter my house. Only if I invite you can you enter. It seems to me that this is a close example of a "public net service" as you discuss it. My door is open, but I only invite you if you use my client.
      • Anything I plug into a socket in my house has to be approved. I can not use any telephone that I have knocked together. Nor any electical equipment. They must all be approved by some authority. Until recently it was technically illegal for people in the UK to change their own lightbulbs - you were supposed to call a qualified electrician (sp?) for that. (Somebody please remind my: why am I satying in this stupid country? ;-))
      • There are lots of monopolies: "last mile" telephones, gas, water, ...

      Anyhow, as with most things on the web, I suspect the law is at best unclear. I do feel, however, that the "open door" precedent is valid in this context so I would suggest that it is valid to restrict the clients. (It might be technically hard - or impossible - but that is another matter.)

      --
      Hi!
    2. Re:A more serious issue ... by otis+wildflower · · Score: 1

      so I would suggest that it is valid to restrict the clients. (It might be technically hard - or impossible - but that is another matter.)

      Why not steal the validation code from the Netrek source?

      Your Working Boy,

  24. Not a major barrier to competition... by Anonymous Coward · · Score: 0

    If services start pulling that, other less restrictive services can emerge and steal away the market with openness. Seems simple enough.

  25. Controversy = banner ad revenue. by Wakko+Warner · · Score: 1
    You think they care that the story's inaccurate? Muckraking and hearsay is well worth it when you consider that they're probably getting a few thousand impressions out of this story. That means money, plain and simple, journalistic integrity be damned. Expect a follow-up retraction well after the fact while the hits keep rolling in.

    - A.P.
    --


    "One World, one Web, one Program" - Microsoft promotional ad

    --
    "Remember when the U.S. had a drug problem, and then we declared a War On Drugs, and now you can't buy drugs anymore?"
    1. Re:Controversy = banner ad revenue. by Anonymous Coward · · Score: 0

      Any creditability was lost ages ago. I've been sickened with /. posting rumors that are meant _only_ to create outbursts and be damned if they destoy the creditability of the innocent, its the money and media attention Andover wants. You'd think more money coming in would be improve quality, but ever since Andover bought them its been rock bottom. Before any lacks were acceptable, considering it was home grown and all. If they would actually admit at times there wrong and outright lies instead of just dropping the story after the blitz is over.

    2. Re:Controversy = banner ad revenue. by AxelBoldt · · Score: 1
      I doubt that banner ad revenue is so hot at slashdot, since readers here are mostly technically minded and therefore use products such as junkbuster to reduce unnecessary bandwidth requirements.

      --

  26. Re:Not all companies are evil by radja · · Score: 1

    True, but most are. The goal of most companies is making money at any cost. Evil enough for me, by default I do not trust any company.

    //rdj

    --

    No one can understand the truth until he drinks of coffee's frothy goodness.
    --Sheikh Abd-Al-Kadir, 1587
  27. Re:But that client is console-only & not open sour by ghazban · · Score: 1

    Actually, the author has decided to never make it open source..

  28. to everyone by four · · Score: 4

    I have removed the logs and emails on the gnap site because they do not show Napster (the company) in very good light. This disision was mine and mine alone.
    I had a long chat with Napster (the person, the owner of the company) this afternoon, and we worked everything out.
    Many of the gnome developers had a meeting this afternoon (which I didn't join) with napster about this whole issue, everyone learned alot. After reading these logs I feel alot better too.

    It turns out that Napster's (the person) request to have me remove the source code, was a request as a person (which didn't come clear across to me) not as a company. After that I wrote a letter back to them saying I would not remove the source. Then Saterday afternoon Napster (the person) his co-worker (?) nocarrier and I had a chat.
    To say it bluntly, they were being rude and I was feeling threatened. (I WAS NEVER THREATENED THOUGH)

    For about 24 hours the sourcecode was offline, before I decided to email them saying I would not take it off. That was that.

    They have no legal case, nor do they want any legal case.

    This has all been cleared up hours ago. I will put this on the gnap page.

    --
    -- four
    1. Re:to everyone by Anonymous Coward · · Score: 0

      This is Bruce Perens II. Slashdot should stop posting stories that become non-stories quickly, and that cause embarrassment to the parties involved.

  29. a few points... by whocares · · Score: 4

    1 - Napster owns the servers that the client uses. Period. They provide the servers for use by the client. Any unauthorized client using the servers is just that - unauthorized. This is exactly the same as someone relaying mail through your server that you do not authorize, and they should be equally free to do whatever they wish to make sure that only authorized clients use their servers.

    2 - The service is provided without charge to the user. The client is provided without charge to the user. This does not == free, and it does not == public domain. The 'rights' of the users are just that of any other service - use it, enjoy it, if you don't like it, well... in so many words, shove it. I have yet to see someone build a free public domain server architecture and client to do the same, and when they do I hope that all of you will support it with gusto. Until then, you frankly have nothing to complain about. I don't see what is so wrong with using the client provided to you, and if you want to build your own and your own backend and open source it, more power to you.

    1. Re:a few points... by kgasso · · Score: 2

      1 - Napster owns the servers that the client uses. Period. They provide the servers for use by the client. Any unauthorized client using the servers is just that - unauthorized. This is exactly the same as someone relaying mail through your server that you do not authorize, and they should be equally free to do whatever they wish to make sure that only authorized clients use their servers.

      There's really two meanings to the word "client" - one could be a user, connecting to the server or service; the other could be the software of the user, which connects the user to the server/service. AFAIK, the Napster servers are open to anyone who has the required software, whether it's made by Napster or by a third party. Restricting users to one specific client would be a BadThing, IMHO.. let's take IRC for example: all necessary security measures are built into the server so any client's software can connect to the server. I've yet to see an IRC server that says "You must use the XYZ IRC client here or you will be banned!" - that would be ridiculous. Likewise, ICQ seems to have no problems with third-party clients (licq, micq, etc.) connecting to their service - in fact, makers of these clients prove that ICQ's "security features" are lacking. Requiring a user's authorization to be added to their ICQ list, etc. is all client-side security.

      Yes, Napster owns the servers, but I disagree with the comparison to mail relaying. In this case, the issue isn't the clients (as in users), its the client's software. (hope that makes sense, it's getting late here :) If the software makers are willing to port their software to different platforms, more power to them.. they must remember, though, that if unencrypted communication is made over any network interface, the protocols won't be "secret" for long ;)
      -----------------
      2 - The service is provided without charge to the user. The client is provided without charge to the user. This does not == free, and it does not == public domain. The 'rights' of the users are just that of any other service - use it, enjoy it, if you don't like it, well... in so many words, shove it. I have yet to see someone build a free public domain server architecture and client to do the same, and when they do I hope that all of you will support it with gusto. Until then, you frankly have nothing to complain about. I don't see what is so wrong with using the client provided to you, and if you want to build your own and your own backend and open source it, more power to you.

      I definitely appreciate the free services that people provide online, but sharing protocols used by services was a precedent set long, long ago - I personally believe it's a good precedent, as it allows developers to create clients for all platforms. If there was a Napster protocol published, there more than likely would have been a *NIX client quite some time ago. Unfortunately, publishing the protocol would reveal weaknesses only known by the developers of the software(and curious hackers - "hackers" as in those who reverse-engineered the software or sniffed the traffic from the software, NOT crackers). Not to put down Napster, but he more than likely knew there was little server-side security, and quite frankly, didn't want to let the cat out of the bag. This is a bad precedent to set, as any malicious kiddie with half of a brain could probably construct a client that would reveal all sorts of interesting information (hostnames/IPs, passwords, etc). This is why the open source movement has so much momentum - it (usually) creates better, more secure products; and believe me, I want my software to be secure with the number of script kiddies running around these days.
      -----------------
      These are just my opinions on this matter, and they really don't matter one bit :)
      --

    2. Re:a few points... by whocares · · Score: 1
      There's really two meanings to the word "client" - one could be a user, connecting to the server or service; the other could be the software of the user, which connects the user to the server/service.

      I was refering to the software client aspect of the service, for the sake of clarity I'll use the term 'user' for the users of the software.

      AFAIK, the Napster servers are open to anyone who has the required software, whether it's made by Napster or by a third party. Restricting users to one specific client would be a BadThing, IMHO.. let's take IRC for example: all necessary security measures are built into the server so any client's software can connect to the server.

      IRC is different for the reason that it is a distributed, volunteer service, not a centralized service being run by a single company, assumedly for profit. It *is* a public internet service in the traditional sense. As far as I know, no one charges for acccess to their IRC servers (though some only allow their customers to use them). I'm not saying that napster is right or wrong for not making it a public service, or that they *won't* go on to distribute the servers, but that's the current state of it.

      I've yet to see an IRC server that says "You must use the XYZ IRC client here or you will be banned!" - that would be ridiculous. Likewise, ICQ seems to have no problems with third-party clients (licq, micq, etc.) connecting to their service - in fact, makers of these clients prove that ICQ's "security features" are lacking. Requiring a user's authorization to be added to their ICQ list, etc. is all client-side security.

      I don't know a lot about ICQ for the main reason that I don't use it - I find IRC preferable for basically the reasons that it is different from Napster or IRC. It's not run by any one company for profit and there are a variety of clients available for it. I don't disagree that it's a better architecture to have things be distributed and open. I simply feel that if a company has chosen a different route they have the right to do so - the internet *has* for better or worse become increasingly commerce-driven.

      I definitely appreciate the free services that people provide online, but sharing protocols used by services was a precedent set long, long ago - I personally believe it's a good precedent, as it allows developers to create clients for all platforms. If there was a Napster protocol published, there more than likely would have been a *NIX client quite some time ago.

      The main flaw I see with this logic is that as it stands now, the servers still belong to Napster. If I were to advocate opening something up, it would be the protocol and the *server code*. If you want a distributed service that is in fact open, you have to have the servers, and hence the server code for people to implement, for it be open, not just the client. I absolutely agree that the protocol should be open, and I think it'd be great if people developed their own independant network using the technology - the key word being if people developed their own. I don't see anything wrong with Napster protecting their resources (if you've seen their servers lately, they're *swamped* - and unfortunately issues of client compatability etc *are* more easily addressed during growth periods when you do have a single set of clients which are centrally maintained and authorized).

      Unfortunately, publishing the protocol would reveal weaknesses only known by the developers of the software(and curious hackers - "hackers" as in those who reverse-engineered the software or sniffed the traffic from the software, NOT crackers). Not to put down Napster, but he more than likely knew there was little server-side security, and quite frankly, didn't want to let the cat out of the bag. This is a bad precedent to set, as any malicious kiddie with half of a brain could probably construct a client that would reveal all sorts of interesting information (hostnames/IPs, passwords, etc). This is why the open source movement has so much momentum - it (usually) creates better, more secure products; and believe me, I want my software to be secure with the number of script kiddies running around these days.

      I think it's weird that this was hailed as a security issue to begin with, really. And I agree that more client/server security is probably necessary - after all, if all you needed to dial into an ISP was the phone number, ISPs wouldn't let that sit long - but the fact remains, if you *did* just dial in and use their service, it would be theft of service. Just because the service Napster provides is not being charged for does not mean that it is free, nor that it cannot in effect be stolen. Whatever 'security' issues are at hand, I think that's really where the interesting point lies.

      It seems to be a moot point anyway, gnap and napster are working things out... but if people want to advocate opening the source to things, I would hope that it would be in a meaningful way, ie protocols and server code, rather than just wanting everyone to be able to modify the widgets. :)

  30. Eh? by Anonymous Coward · · Score: 0

    Not according to the web page... from http://www.gis.net/~nite/ The Open Source Issue Whoops, the plans to eventually open source it are still on, I accidentally editted an old version of the page.

  31. PR in the internet age by cybaea · · Score: 1

    Hm, I don't think I was "ragging on" four but I apologise if it sounded that way.

    Instead, I was trying to suggest that Napster had a little PR problem on their hands, and that the way to get out of it was to come open about what happened.

    As for /. being important or not: I guess the results speak for themselves. Obviously four thought it was important enough to make him contribute.

    The serious issue (if there is one) in this sprawling sub-thread is how to handle PR in the internet age. Obviously nobody are going to comment this deep in a thread, but I think companies have to re-evaluate their PR strategies. If nothing else then they now have to repond much faster to get their message accross (how long before a /. thread goes inactive and none of the posters read it anymore? A day? Six hours? One?).

    I guess I'm advocating an Open Source approach to PR: get all the facts out in the open, fast. By all means annotate them and make sure your version of the story gets across. But don't hide or insult your customers by assuming that they can not think for themselves or that they are unable to handle the truth.

    This whole story seems to be an example of PR going bad. Apparently everybody are friends now - or at least have a common understanding - but it does not appear like that to the outside world. That's a PR issue. It's not about who is "good" or "bad", "right" or "wrong", but about your company is percieved by your customers. And that is Napster's problem, as I see it. I suggested a way to handle it. Maybe it is not the best way, but it does try to tackle the problem instead of just hiding. And in any case it suggests an approach to PR rather then just a haphazard, ad hoc, inconsistent response.

    --
    Hi!
    1. Re:PR in the internet age by BJH · · Score: 1

      No, this is not a PR issue. It's an issue with the way that /. posts stories. In particular, Roblimo seems to succumb to the urge to post stories with inflammatory titles ("Napster attacks open source clone") and without proper confirmation (which in this case simply means "reading the link yourself").

      And as for your remark about how it was important enough for four to respond on /., what do you think he's going to do? He's probably had a whole bunch of gibbering /. monkeys piling all sorts of garbage into his mailbox about how they'll mailbomb Napster/crack Napster's server/otherwise harass Napster. It's happened before and it'll happen again...

  32. ha! by jebbono · · Score: 1

    Personally, I think this is really funny. Even if it is all peacefully resolved now, it would be funny if the gnap guy just sent back all of Napster's quoted press in response to the RIAA and changed "music" to "OSS". The Napster releases are like, "It's all about community and sharing." That would be too funny. Anyone know how napster plan to make money, anyway?

    1. Re:ha! by Mr+M · · Score: 1

      In the previous version of Napster there was banner space indicating that it was available for rent. It's possible that this was removed due to the RIAA scare, but there may be other motivations. Personally, if I were at a music company, I would welcome Napster and pay for the ad space. If you can't beat em, well...

  33. What is the danger? by PG13 · · Score: 4

    As I understand the fear is that hacked napster clients will be able to report incorrectly what mp3's I have availible. But what prevents me from merely creating files of the appropriate size filled with random bytes?

    It would appear that it is easier to fool the napster program in such a manner rather than messing with the source. Everyone can make a file not everyone can code a client.

    Secondly who are they scared of? Even script kiddies probably have something better to do than falsely posting mp3's. If it is groups such as the RIAA flooding the server to make it unusable....well they could certainly reverse engineer the client just as well as I can.

    Thridly while in this case the client seemed to be easily reverse engineerable security through obscurity is not impossible. If you capture a piece of my own private code the fact that you are unsure of the algorithm renders it difficult to decode (Re: those papers supposedly detailing buried gold in virginia where only one has been decrypted). Sure it isn't as secure as a well tested publicly availible algorithm but if your intent is to hide the actions of an algorithm your choices are limited.

    Hell if security through obscurity never worked the wine project would be done.

    --
    Marriage is the "pseudo-ethics" that cloaks the messy truth of sexuality in the raiment of propriety -- it's "Don't Ask,
    1. Re:What is the danger? by thal · · Score: 1

      i think what people are afraid of is the fact that the napster client allows the world to relatively anonymously access a specific directory of your system. if there's any kind of security hole, it could be hacked to allow access to your _whole_ system (that's bad). it needs to be as secure as an ftp daemon.

      i think the non-ratio format of napster doesn't encourage people to post false mp3 files. you mostly see this on mp3 ftp servers where you need to upload something before you can download. with napster, there's no benefit to this, aside from causing chaos.

  34. Napster and my big fat big dong by jwxyz.org · · Score: 1

    Napster has tried to be all corporate now claiming to be an all mighty "silicon valley" company. haha... one day it's a hacker site, the next day it got all corporate... do i here the words portal, .COM, and television commercials soon? yuck... how about i throw up right now on MP3.com valuation and take some of that puke and through it into the future at something as trivial as napster... which i'm sure will puff it's feathers up and hire frat boys who play golf all day so they can IPO within 4 months...

  35. Grrrr by jmweeks · · Score: 4

    I guess this is a little offtopic (if Slashdot had a general posts board I suppose it'd go there) but I've been seeing a lot of posts criticizing the headings/content/comments of topics lately. People criticizing i.e. Roblimo for "Napster Attacks Open Source Clone" (others come to mind, such as the ID spying post and the Bruce Perens vs. Corel thing).

    I just have one thing to say. Grow up.

    Slashdot as a media source is not your classic 1/2 hour news jive. It's an immediate source that shows what's being said in the moment, links us to where it's being said, and let's us hash it out on our own. So when it gets wind that something happens, when it gets a link to a rather rude (I take it, I didn't get to read it) email that may be threatening, it is Slashdot's place to post it. Things change, and updates can (and in this case, I expect will) be made. If you don't like it a little raw, what are you doing here in the first place?

    Jose M. Weeks

  36. why restriction? by RoLlEr_CoAsTeR · · Score: 1

    Anyhow, as with most things on the web, I suspect the law is at best unclear. I do feel, however, that the "open door" precedent is valid in this context so I would suggest that it is valid to restrict the clients. (It might be technically hard - or impossible - but that is another matter.)

    I agree to the extent that, if it's your server, technically you have rights over it, and so I can see how someone could begin trying to justify the statement that you should be validated in your efforts to restrict access to your server. Isn't this similar to actions in the instant messaging scruffle between Microsoft and AOL? (I seem to recall something about one of them changing protocol so they couldn't connect... err.. I can't remember, but here's a link.) As someone else posted, this situation can also be likened to web browsers viewing pages; there are many different web browsers, but they can all connect to all web pages (unless it's down ;-). Webmasters can't/don't restrict access to their servers based on what browser is used (AFAIK), so, by the same token, Napster can't/oughtn't restrict access to their servers based on client.

    Then again, I wouldn't know all the legalities of this, the implications, consequences, etc. I just think, as others have mentioned, that we're all doing about the same thing... why not work together?

    --

    Insert mind here.
    1. Re:why restriction? by mihalis · · Score: 1
      Webmasters can't/don't restrict access to their servers based on what
      browser is used (AFAIK), so, by the same token, Napster can't/oughtn't restrict access to their servers based on client.


      Actually the TurboTax site wouldn't let me use it because I wasn't using Windows or a Mac. It was their loss, but there is definitely a risk of this type of thing increasing - one of the reasons I have started to familiarise myself with Mozilla.



      Chris Morgan

    2. Re:why restriction? by Pope · · Score: 1

      Guess you never saw what happened last week with MSNBC:
      They were blocking out Mac clients to their videos page with a JavaScript that put up a message saying that there was no Microsoft Media Player for the MacOS. This despite the fact that there IS a Media Player, albeit a beta version, available.
      When asked about this, MSNBC claimed it was an "error" made by the HTML programmer.
      Uh, yeah, right.
      Here's part of the code:

      if(sUa.indexOf("mac")==-1) {
      (snip)
      alert("Windows Media Player for Macintosh in not currently available.");

      Pope

      --
      It doesn't mean much now, it's built for the future.
  37. Open Source Napster could be a good thing. by mwarps · · Score: 1

    After using the closed-source Win32 Beta of Napster, I can safely say that it is a buggy little thing. Hopefully all this work that is being done to bring it to open-source will at least get some of the bugs out. And there is always the joy of having such a cool program for Linux.
    I've heard a lot of complaints from tons of people about how Napstar doesn't work with their firewall, and how they can't seem to get their hotlist to work. I've experienced the same problems these people describe, but they seem to be intermittent at best. I don't know if it's a Win32 problem, or a Napster issue, but it is definitely annoying. Hopefully with this new open-source version, some, if not all of these problems will disappear faster than they would have if the source had stayed closed.

    1. Re:Open Source Napster could be a good thing. by Anonymous Coward · · Score: 0

      I dont't know what version you used but Version 2 Beta 4 works fine, no problems here it logs me into the server on the first time every time. And it never crashed once. Gets me every song I need.

  38. We need a decentralized form of this service by Asmodean451 · · Score: 3

    What we really need, is a distributed form of the napster service. The protocol could be based loosely around IRC.. in fact it might just be easier to sit it on top of the IRC protocol. In any case, its not a terribly complex protocol.. and it would be so much nicer if the servers were distributed. Granted there is the whole speed issue.. but with some caching thrown in it could be pretty decent. We need a completely decentralized file search service ...

    oh... and of course.. it'd be much harder for people to squash the service for distributing ~1 TB of mp3s =]

    1. Re:We need a decentralized form of this service by Darth+Yoshi · · Score: 1

      Isn't/wasn't there a group working on a secure IRC replacement? If that has a file transfer protocol, it might make a good basis for Nap-like clone.

      This is not a sig.

      --
      // TODO: fix sig
    2. Re:We need a decentralized form of this service by jtraub · · Score: 1

      IRC is a poor choice to sit something like this on top of. For searching to be reasonably fast you *DO* want a semi-centralized search mechanism, otherwise you are connecting to each of 3000 (or more) clients and asking them to do the search for you.. That is just not the right way to do it and congests the network in a bad way.

      I will freely admit that I was a person who is/was getting fed up with the unix nap client and it's crashing, and the lack of connectivity between the servers. I've even started hashing out specs in my mind for what I'd consider the right way to do this (and yes, before someone says I'm blowing smoke out my buttocks, I do have the knowledge and experience at writing TCP/IP servers ala MUDs or IRC servers to write something of this magnitude)

      --
      --JT
    3. Re:We need a decentralized form of this service by Jamie+Zawinski · · Score: 2
      IRC is a poor choice to sit something like this on top of. For searching to be reasonably fast you *DO* want a semi-centralized search mechanism, otherwise you are connecting to each of 3000 (or more) clients and asking them to do the search for you.. That is just not the right way to do it and congests the network in a bad way.

      The way around this would be to store the whole database in each client, and broadcast updates to everybody. That way, any node dropping out of the system doesn't bring down the whole network. This is the trick about Usenet that makes it immune to censorship, and has kept the p0rn flowing for so many years...

      Whether this should be done by piggybacking on top of IRC, or by inventing a new, parallel protocol, is left as an exercise to the implementor...

      If it's centralized, someone will be sued and shut down. If it's decentralized, there are too many people to sue, and the network adapts itself and routes around the problem areas.

      Not that I'm advocating breaking the laws of whatever country you happen to be in, of course. That would be wrong. I'm just talking about robust network design.

    4. Re:We need a decentralized form of this service by jtraub · · Score: 1
      The way around this would be to store the whole database in each client, and broadcast updates to everybody. That way, any node dropping out of the system doesn't bring down the whole network. This is the trick about Usenet that makes it immune to censorship, and has kept the p0rn flowing for so many years...


      While that might be the best solution for robustness's sake (and I won't argue that) I don't think storing the entire DB on each client is a) feasible or b) warrented.

      Instead think of the following scenario. You have 4 classes of servers + clients.

      1st class of server: a web of interconnected server-servers. These are responsible for telling other servers or clients where resources (such as login servers, other server server, chat servers, search servers) are located. Updates to any server-server are propogated along the network of server-servers keeping them syncronized, so that you can talk to any server-server and get substantially the same results back. These are tasked with picking an appropriate server to service any request given that server-servers knowledge about location of requester, locations of servers, load of servers, etc.

      2nd class of server: A web of interconnected login servers. These maintain the user accounts and authentication. Changes are propogated along the web of login-servers. Login-servers are talked to by the chat servers when a user requests login, NOT by the clients themselves. Communicate with the search server web when a user logs in/off

      3rd class of server: Search servers. Maintain a database of shared files in various file classes (I'm assuming here that you could share multiple file 'sets' where the files in the set were all of some 'class' and that these categories were server defined). Thus one could share music, poetry, and lyrics, but they would still be searchable. Someone searching for a music file wouldn't find the poetry unless they searched that category as well. These are also an interconnected web of servers. Clients when they log in publish deltas of shared files. These deltas are given to the search servers to add/remove things from their database. Files which return errors when fetched by clients are also reported back and marked as unavailable. Some security needs to be in place to prevent a client from spuriously marking a file as unavailable. (Probably some threshold of unavailable marks from a certain minimal number of discrete IPs over a certain time period)

      4th class of servers: Web of interconnected chat servers. These publish the list of channels (possibly fixed like napster or expandable like irc, I tend toward fixed). They also transmit channel traffic along the web of servers in a manner similar to IRC. IRC would actually make a decent base for this specific type of server with some modifications. Clients connect to a chat server, and present their authentication. Chat server checks authentication against login server and accepts or rejects the connection.

      Clients: Know about 1 (or more) server-servers, from which they can find out about the rest of the server-servers and chat servers and search servers. If one such server is down, just ask for another one.

      I think such a mechanism would work and would be robust. Anyone else's thoughts?
      --
      --JT
  39. A few thoughts... by jd · · Score: 3
    • Security through obscurity is an exercise in futility.
    • If Napster has a problem with unauthorised clients, do better validation.
    • Specifications are never really closed, merely hidden.
    • Removing one site's copies of a program doesn't remove the program elsewhere.
    • Competition is GOOD, monopolies are BAD.
    • Ideas and code thrive with evolution, not convolution.
    --
    It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
  40. Isn't this illegal use of servers? by dirk · · Score: 1

    I find it amazing so many people are in favor of hacking out a Napster-clone to use their servers. This is what MS did with it's IM, using the AOL servers, and that was completely blasted everywhere (and justifiably in most cases). Yet, now that someone is doing it to the Napster servers it's okay, because it's a Linux clone? Seems to me if using someone's servers is a bad thing, it's a bad thing for everyone, for any reason.

    --

    "Information wants to be expensive" - Stewart Brand, the same guy who said "Information wants to be free"
    1. Re:Isn't this illegal use of servers? by kyhwana · · Score: 1

      Auctally, it much depends on the ethics of the people who are writing the clone. AOL Didn't like M$ doing what they did.
      If you had a service/protocol, would you mind if someone wrote a different client for it? Just look at AOL.
      It also depends on wether or not the stable clone (im thinking gnap so far) will allow other people to leech off you, once they can't tell the difference, does it really matter?

      --
      My email addy? should be easy enough.
    2. Re:Isn't this illegal use of servers? by Xkill_ · · Score: 1

      wasnt it the other way around? i seem to remember lots of people criticizing AOL for their attempt to block M$, amidst their Mozilla work. I am afraid that you have your stories mixed up.

      "The importance of using technology in the right way has never been more clear."

      --

    3. Re:Isn't this illegal use of servers? by ghazban · · Score: 1

      Actually most people supported MS on their actions on that event. It was however the fact that ms only wanted it when it was to their advantage, and would not like it the other way around.

    4. Re:Isn't this illegal use of servers? by whocares · · Score: 1

      It's not an issue of the *service* or *protocol* per se, but the *use of the servers on which the service or protocol is running* which is a distinct and separate thing. People seem to keep confusing the two. Napster, and ICQ as far as I know, is a centralized service, meaning that the servers on which the server part of the service are currently *only* Napster-owned machines with Napster-owned resources. For everyone who is complaining that they should open up the client, if you actually wanted to do more than leech off of someone else's work, you'd be asking them to open up the server instead.

  41. Good idea by Mawbid · · Score: 2

    Possibly, a permanent messageboard about Slashdot would serve to reduce the clutter in the news section.
    --

    --
    Fuck the system? Nah, you might catch something.
  42. Lets attempt to look at Napster's side of this.... by Mikesch · · Score: 1

    Napster is a company whose only source of revenue will probably be banner advertisements on their client (unless they choose to go ugh, portal). By creating an open source clone without banner ads the company is losing impressions and therefore money.

    As much as we would like to see people in an altruistic light, Napster as a company needs to make money to stay in business (theoretically, although that is apparantly not the case with today's .com startups).

    Napster is a neat toy and it would be great if they encouraged OS development, but don't be surprised that they don't. They would like to make some cash. Yes, OS software makes money, but the typical OS revenue model doesn't apply in this case (i.e. Napster won't be selling support).

    Regardless of what they say about security, cash is what it all comes down to.

    Before I get flamed, yes, I know that there is an "official" console based client out there, but I'd imagine that banner ads will be on that too once it goes GUI. And when he does in fact go OS with it, there will probably be some clause in the licence stating that banners will have to still be in there somewhere.

  43. [OFFTOPIC] slash moderation (was Re:Resolved?) by doom · · Score: 1

    > 3. Remove metamoderation. It was a good idea,
    > but how many people activly meta-moderate
    > anyway? It's just more time spent not reading
    > things that matter.

    You mean you *don't* metamoderate? And you're
    complaining about poor moderation?

  44. Just curious.... by Darth+Yoshi · · Score: 1

    I guess I'm a little dense this morning (and I'm not into ICQ/chat progs and swapping MP3 files) so I have a couple questions...

    Several people have mentioned security problems. I'm curious what kind of security problems are involved here? (The only one I can see is the programmer losing control over his protocol, but as I said, I'm a little dense this morning.)

    Given that there are security problems, how should they be addressed? Offhand (and not having taken a close look at Napster), the biggest problem I can imagine is there seems to be only one master server for Napster clients, I would imagine a hierarchical arrangement of a few master servers and sub-master servers, similar to Gamespy, would be more efficient (but that's more a performance issue).

    Off-topic (but as long as I'm blathering), is there a Linux version or clone of Gamespy.

    This is not a sig.

    --
    // TODO: fix sig
  45. That's being worked on... by Millennium · · Score: 2

    Thing is, they're doing it in PHP.

    Here's where you can find it.

    Thing is, it's still the old version. Honestly, I think Rob should be putting out the source more ovten. Perhaps CVS access would be something to try? Yes, I know the code's beta; that's never stopped Open-Source development before.

  46. How about by Eimi+Metamorphoumai · · Score: 1
    Ok, I just created one. Go to http://slashdot.org/comments.pl?s id=slashdot/misc. Maybe we can push all the metacomments there.

    Just an idea.

    --

    Visit me on #weirdness on the Galaxynet.

  47. On the Issue of Slashdot by Jeff+Knox · · Score: 1

    Exactly my thoughts. This is not meant to really be dis against slashdot, believe me, I have loved slashdot since it was Chips and Dip. There are, however, some serious problems as mentioned by some AC's. One is the things they are posting on slashdot. There is still alot of good articles, but not nearly as good as it originally was. I used to read every slashdot article and every comment associated with it. Now I find that only a few articles a day are even interesting. And lately Slashdot has been posting stories that were posted a year or so ago, like they forgot they were posted (which is understandable I guess, but if the news link is over a year old, at least search the archives). Another big problem I see is the moderators. I am all for moderators moderating comments and such, but I disagree with some of the things they moderate. If anyone questions soemthing about slashdot, or the open source movement, it is considered troll bait and marked down to zero or below. I have seen an abundance of good, intellectual post in the past few months that should no have ever been moderated down. If anything, they should of been moderated up. Slashdot is starting to become like , say a government, someone questions it and they are silenced. No matter how intellectual and how good of apoint they have. And about the issue of open source and slashdot, my sentiments exactly. I have always thought slashdot code should be CVS'ed. Dont get me wrong, I am not open source extremist, but if they are going to open the source, at least give us the most recent versions. Dont open source an initial version, then keep everything private. Thats not open source. I would also like the see the financial records of slashdot open sourced (or content, whatever you feel is appropriate), as in how much Andover paid for Slashdot. Rarely does a company not disclose the takeover/merger price, especially in the internet industry. Anyway, I cant really say keep up the good work Rob. But you have a good site here, I hope it gets better then where its been going.

    --
    Jeff Knox
    1. Re:On the Issue of Slashdot by dgerman · · Score: 2

      I have similar feelings to what this message mentioned. Somehow, Slashdot seems to start getting stale.

      I think that one of the problems Slashdot is starting to face is that it is turning away news submitters. How many times have any of you submitted a story, just to find that it is never posted. Fine, it does not have to be posted. But after you have submitted item several times, none of them worked, then you think, "why bother?". The less people are willing to submit stories, the more difficult for Slashdot to be as comprehensive as fast in reporting news.

      And then we are starting to read news that lean more towards gossiping than real jornalism (the Corel fiasco with regard to teenagers and the EULA). Yesterday we had to read a "press release" about Y2Brand that looked more like a commercial than a news item.

      Slashdot is starting to offer t-shirts to book reviewers, why not offer something to the first whose news item is published? At least that will attract back some of those who have decided that everytime they fill the form is a waste of their time.

      I suspect that like many, I am starting to mine for my own news. I don't find many pieces worth reading. In the past, I could spend all my free time reading Slashdot. Now, I just skip many of the headlines.

      Don't get me wrong. I like Slashdot. I want to see it shinning. But I think that it has to continue to grow up. It has the money and the resources to do it, and that has increased our expectations. It cannot and should not continue as a "garage" project. After its takeover by Andover our expectations on Slashdot changed accordingly.

      And like many, I think Roblimo is doing an excellent job and I love the interviews he is doing. We need more people like him, that bring a fresh air and a professinal face to Slashdot. We also need to have more relevant articles. Finally, make sure that you understand the ramifications of your postings and the responsibilities that the community has put on it. Somehow, Slashdot readers are starting to note this and they start to believe that they have to keep a cool head despite the "news" sometimes they are presented with. The item on Napster shows that sometimes, in an attempt to be the "first", Slashdot is willing to put a headline that might dramatically change the outcome of it. I just hope that we don't lose a battle because Slashdot worked against us. On the contrary, we have to make sure Slashdot works along our Free Software ideals.

      Now I just have to wait for somebody else to pump the rating on this message. Otherwise, like many comments, it might be lost in a sea of many others.

  48. On the Issue of Slashdot by Jeff+Knox · · Score: 2

    Exactly my thoughts. This is not meant to really be dis against slashdot, believe me, I have loved slashdot since it was Chips and Dip. There are, however, some serious problems as mentioned by some AC's.

    One is the things they are posting on slashdot. There is still alot of good articles, but not nearly as good as it originally was. I used to read every slashdot article and every comment associated with it. Now I find that only a few articles a day are even interesting. And lately Slashdot has been posting stories that were posted a year or so ago, like they forgot they were posted (which is understandable I guess, but if the news link is over a year old, at least search the archives).

    Another big problem I see is the moderators. I am all for moderators moderating comments and such, but I disagree with some of the things they moderate. If anyone questions soemthing about slashdot, or the open source movement, it is considered troll bait and marked down to zero or below. I have seen an abundance of good, intellectual post in the past few months that should no have ever been moderated down. If anything, they should of been moderated up. Slashdot is starting to become like , say a government, someone questions it and they are silenced. No matter how intellectual and how good of apoint they have.

    And about the issue of open source and slashdot, my sentiments exactly. I have always thought slashdot code should be CVS'ed. Dont get me wrong, I am not open source extremist, but if they are going to open the source, at least give us the most recent versions. Dont open source an initial version, then keep everything private. Thats not open source. I would also like the see the financial records of slashdot open sourced (or content, whatever you feel is appropriate), as in how much Andover paid for Slashdot. Rarely does a company not disclose the takeover/merger price, especially in the internet industry.

    Anyway, I cant really say keep up the good work Rob. But you have a good site here, I hope it gets better then where its been going.

    --
    Jeff Knox
  49. On the other hand by Hard_Code · · Score: 2

    On the other hand, it is /their/ servers, and /their/ service, so they get to dictate who uses it and how it is used. Not unlike AOL dictating who can interoperate with its instant messaging software. Since they have put the time, money, and effort into building the backend they should be able to dictate how it is used. If I provided a service to users, I wouldn't want the possibility of a foreign client disrupting or corrupting that service. In reality, in light of the fact that they give out their own client free, an open-source client probably wouldn't hurt anything, and in fact probably help, since they would gain a rather large, tech-savvy audience (I'd guess geeks have the monopoly on MP3s right now anyway).

    How many people who agree they should open up their backend to foreign clients agree that AOL should do the same for MSFTs messager? What if they weren't giving their client away free?

    --

    It's 10 PM. Do you know if you're un-American?
  50. Re:Resolved? [OT] by wampus · · Score: 1

    I honestly don't give a shit about Karma, and personally think slashdot has been going down hill since I got my user account. I tried to post something relavent and I get flamed for it. I appologise. My next post will be more on topic, and (just to keep on topic) I must add:


    I JUST POURED NAKED AND PETRIFIED GNULIX BRAND GRITS DOWN MY PANTS SO J00 Mu57 Ph3@R m3!^%&^%@?
    ph1r57 p057!!&(*&(*@?!(!!



    PS: The second best way to get Karma is to ask to be moderated down. I'm glad I haven't had moderator access since THAT bullshit started.
    ---

  51. Linux only? Who cares? by Anonymous Coward · · Score: 0

    Who cares? So a handful of Linux freaks use a new client! Big deal.

  52. Client Validation Impossible by Brian+Ristuccia · · Score: 1

    What prevents someone from extracting the key from a signed binary and using it with their own?

  53. Some factual information by raph · · Score: 2

    I am one of the Gnomers who has been following this issue, and was also present at one of the irc conversations with the Napster people. I've done a little writeup of the events, which I'm hoping will help set the record straight.

    The writeup is here, posted on Advogato. As usual, anyone can read, but posting is restricting to free software developers.

    --

    LILO boot: linux init=/usr/bin/emacs

  54. ..source code availability.....less secure..! by gatekeeper-eu · · Score: 1

    The message has not got through. If security relies on 'closed' or 'secret' code the code is not secure. Only by 'many eyes' who know what they are looking for will any code ever be 'reasonably' secure. "Secure is an aspiration not an achievement."

  55. Another program in the Napster genre by Anonymous Coward · · Score: 0
    Since not many people seems to found this out, so I thought to make everybody aware of the existence of 'CuteMX'. This program comes from the makers of CuteFTP and other 'cute' products.

    This moment there are 173 users logged on, which means they has far from as many users as Napster has, even if just counted by server.

    The client is neater that Napster, but seriously lacks some vital features that the latter has. And as I stated previously, not many people has found this client. I predict this will change in short time.

    The url to the client (hard to find as you cant navigate there from Globalscapes site) is:
    http://www.globalscape.com/Beta/cutm x1032b.exe

    Else try this:
    http://www.cybertropix.com/software .phtml?id=70

    Btw: I don't know if it's a result from the /. effect but you could definately notice an increasing number MP3's on Napster following the /. article a few weeks ago...

  56. unnecessary exaggeration by Anonymous Coward · · Score: 1

    Hello - its unfortunate that a simple discussion and request by the creator of napster (as an individual) to simply delay the release of client source until a new server (that is in testing phase) was put into place. I was privy to this discussion, and I saw that the concerns were for napster users and the implications of a premature source code/protocol spec release as opposed to any type of oppression. From what I read, there were no threats or imperatives involved - simply involved a request that it be delayed until the proper message/channel flood throttles (among other throttles) were in place. The information in this post regarding "Napster" was very ambigious - the post did not make it clear that it was Napster the person and not Napster, Inc. Its easy to see how an issue of this nature could be blow out of proportion - there are thousands of open source freaks waiting to flip out about how they are being oppressed by the man. The advantages of open source are evident and stem from the fact that vendors are forced to make problematic code a higher priority. This situation seems interesting - the developers were aware of the problem, asked for a bit of time to put the proper fixes into place.

  57. how much Andover paid for Slashdot by chacal · · Score: 2

    If you poke around the link listed under "slashdot parent andover.net files for IPO", or whatever it is that the link says, you can find this. Looks like around 11 million? But who knows how much more if Andover successfully offers, and the stock price rises.

    Slashdot.org Purchase Agreement

    Under the terms of the Asset Purchase Agreement between BlockStackers, Inc. and Andover.Net, dated as of June 18, 1999,
    Andover.Net purchased those assets of BlockStackers relating to the Slashdot.org web site for 1.5 million in cash paid at closing
    and maximum future cash payments of $3.5 million payable over the next two years contingent on the continued employment of
    two key employees. Maximum future stock consideration of $7.0 million is payable over a period of two years following this
    offering. For the purposes of these issuances, the number of shares of common stock to be issued is determined using an assumed
    initial public offering price of $13.50 per share. Thus, the total consideration that will be paid is valued at $8.5 million and the
    maximum contingent consideration payable is $3.5 million. All consideration has been or will be paid to BlockStackers. The number
    of shares paid is contingent on the continued employment of two key employees and the achievement of performance milestones
    relating to traffic on the web site.

    *
    148,148 shares issuable upon the closing of this offering;
    *
    74,074 shares issuable seven months after the closing of this offering;
    *
    49,383 shares issuable 12 months after the closing of this offering;
    *
    98,763 shares issuable 12 months after the closing of this offering provided that the milestones in the agreement have been
    met;
    *
    49,383 shares issuable 24 months after the closing of this offering; and
    *
    98,765 shares issuable 24 months after the closing of this offering provided that the milestones in the agreement have been
    met.


    Pursuant to this purchase agreement, BlockStackers also agreed not to compete with Andover.Net or to solicit its personnel,
    customers or suppliers. Specifically, BlockStackers may not compete with Andover.Net, its subsidiaries or affiliates by engaging
    in any business that involves a real-time or contemporaneous news web site until June 28, 2004. Prior to June 28, 2001,
    BlockStackers may not solicit personnel, customers or suppliers from Andover.Net, its subsidiaries or affiliates. Mr. Malda, a
    director of Andover.Net, owns 25% of BlockStackers. Mr. Malda, the President and co-founder of BlockStackers, was a web site
    manager of BlockStackers, running Slashdot.org. Mr. Malda continues to run Slashdot.org as a web site manager and editor of
    Andover.Net.

  58. Re:But that client is console-only & not open sour by Kyobu · · Score: 1
    The Open Source Issue

    Whoops, the plans to eventually open source it are still on, I accidentally editted an old version of the page.

    He changed his mind. If he plans to OSS it, I don't know why he doesn't do it from the start.

    --
    Switch the . and the @ to email me.
  59. Slashdot irresponsibility by nrc · · Score: 2
    Your writeup makes reference to slashdot's "irresponsible journalism." In some way's I agree, they do sometimes go off half cocked. But in this case I think there's still a very real issue. The effort by "the GNOME people" and Napster to smooth things over and make nice should not be allowed to hide the fact that Napster seems determined to ignore the problems with "security through obscurity" until it jumps up and bites them on the ass.

    Obviously they're too busy trying to ride the wave they've created to worry about something as trivial as security.

    1. Re:Slashdot irresponsibility by Anonymous Coward · · Score: 0

      Obviously you're too busy making assumptions about what the issues really were and not assume it is in any way 'security through obscurity'. The real issues were not security issues, but user annoyance issues, like user flooding with messages or downloads. Napster has fixed all of these problems in their latest server that is going into production within the next few days. I have heard this server has been in testing for a few months. If the facts were layed out properly, I'm sure you would have come to a different conclusion.

    2. Re:Slashdot irresponsibility by nrc · · Score: 1
      You're missing the point. Denial of service attacks are a security problem. They're just a hint of the kinds of security problems that Napster could have hidden in their proprietary protocol.

      I'm glad to hear that Napster is going to fix their known problems "real soon now." I was not making assumptions, I was responding to a summary of the chat with Napster which said:

      Shortly after this, Shawn and Ryan had an irc discussion in which Shawn reiterated his belief that the existence of an open source client would invite abuses of the Napster server. He also pointed out that Napster plans to roll out some anti-abuse features in a future server. Ryan asked for a timeline, but Shawn basically said he couldn't say when that would be.
      So does this mean that Napster has set a timeline now that they've had their feet held to the fire or were they just once again being deliberately obscure?
    3. Re:Slashdot irresponsibility by Anonymous Coward · · Score: 0

      As I stated, the servers have been in testing phases for quite some time - including tests with live users. The problems were known about back when the next generation server was being developed, and its functionality cannot be utilized until it is placed in production. This being said, it seems very feasible to me that they would request a delay on a source release.

  60. Blowing Smoke by Tasty · · Score: 1

    (and yes, before
    someone says I'm blowing smoke out my buttocks, I do have the knowledge and experience at writing TCP/IP servers ala MUDs or IRC
    servers to write something of this magnitude)


    I say you're just blowing smoke.
    Prove me wrong.

    Marc

  61. OPEN THE SLASHDOT SOURCE!!!!!!! by Anonymous Coward · · Score: 0

    WHERE IS THE CURRENT SLASHDOT SOURCE??????????

  62. It's already open by Anonymous Coward · · Score: 0

    http://slashdot.org/code.shtml

    Please try to stay on topic...

  63. It's not rob's site anymore by CrAlt · · Score: 1

    Now that Andover owns Slashdot im sure they have the final say in what to open up and what not to.

    --
    I have to return some videotapes...
    1. Re:It's not rob's site anymore by Anonymous Coward · · Score: 0

      OK, fine. Go through my post and replace "Rob" with "Andover."

      The argument still stands.

  64. Thats OLD code!!!!! by Anonymous Coward · · Score: 0

    Thats an ancient version! WHERE IS THE OPEN SLASHDOT SOURCE????????/

    1. Re:Thats OLD code!!!!! by Anonymous Coward · · Score: 0

      What, are you planning on running your own open-source, GNOME-based version of slashdot? gnashdot? If nothing else, press that key over yonder marked "caps lock". Yeah yeah, the light goes off, but don't worry, your keyboard still works.

  65. Yes, I Am! by Anonymous Coward · · Score: 0

    As a matter of fact, I am.

    Oh, does it now matter what I use the source for? Source code should be FREE, right hypocrite?

    WE WANT THE CURRENT VERSION OF THE SLASHDOT SOURCE CODE!!!

    --- Just focus on scrapping Windows, 'kay?

  66. Re:The RIAA isnt Big Brother by Anonymous Coward · · Score: 0

    Of course not. It's the Racketeering Idiotic Assholes Association.

  67. Re:That's why you read at level 0, genius by Anonymous Coward · · Score: 0

    The moderation system is OPTIONAL, Einstein. Don't set your threshold high and you get to see everybody's comments, not just the SlashDotApproved[tm] ones. And who cares if some twit's post gets moderated up to 5, just don't read the point scores. Matter of fact, There Should Be An Option to turn off moderation points entirely? Maybe there is somewhere, but I don't have the time or inclination to create a login for myself on every single freaking web-based discussion board I read.

  68. Re:The RIAA isnt Big Brother by Foogle · · Score: 1
    Gee that was great -- Did you think that one up yourself or pay an advertising firm to come up with it for you?

    -----------

    "You can't shake the Devil's hand and say you're only kidding."

  69. Re:That's why you read at level 0, genius by Jeff+Knox · · Score: 1

    I am posting this 2 days after this thread was on slashdot,so it will probably never get read. The point wasnt that I couldnt see comments or what not, its the principle of the thing. I frankly dont care about the moderation system as an object, but the overall principle of censorship of perfectly good comments.

    --
    Jeff Knox