TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

“It appears that SourceForge took control of the 'GIMP for Windows' account”

166 pointsby patdavidabout 10 years ago

18 comments

scrollawayabout 10 years ago
Reposting what I wrote on the Reddit thread:<p>I&#x27;m one of the lead devs of LXQt and an LXDE sysadmin. We use Sourceforge for our mailing lists and some LXDE legacy stuff.<p>I&#x27;m absolutely sick of them. It&#x27;s not the first time this has happened. I&#x27;ve been pushing for us to move off SF for a while and this is a good occasion to push for it harder.<p>I&#x27;ve sent an email [1] detailing plans to move. I am urging everyone who still has projects on Sourceforge to do the same.<p>If you have similar migration problems to solve as the ones I&#x27;ve highlighted in the email, please contact me directly and we can share the workload. My email is available on my Github profile [2].<p>[1] <a href="http:&#x2F;&#x2F;sourceforge.net&#x2F;p&#x2F;lxde&#x2F;mailman&#x2F;message&#x2F;34148903&#x2F;" rel="nofollow">http:&#x2F;&#x2F;sourceforge.net&#x2F;p&#x2F;lxde&#x2F;mailman&#x2F;message&#x2F;34148903&#x2F;</a> [2] <a href="https:&#x2F;&#x2F;github.com&#x2F;jleclanche" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;jleclanche</a>
etixabout 10 years ago
This is precisely for these reasons we stopped distributing VLC via SF.net in 2013. I even wrote about it: <a href="https:&#x2F;&#x2F;blog.l0cal.com&#x2F;2013&#x2F;05&#x2F;02&#x2F;rethinking-vlc-mirrors-infrastructure&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.l0cal.com&#x2F;2013&#x2F;05&#x2F;02&#x2F;rethinking-vlc-mirrors-inf...</a>
评论 #9612799 未加载
评论 #9613699 未加载
jbkabout 10 years ago
Our VLC account has been taken too by sf-editor-1.<p>Fortunately, we&#x27;ve moved to our mirror infrastructure since quite some time, and it&#x27;s faster and way better.<p>Btw, if any other open source project needs help to distribute their binaries (because of the size), please contact me.<p>PS-EDIT: signing the installer was a good idea, I guess :)
评论 #9617158 未加载
geofftabout 10 years ago
What are the reasons for people to use SourceForge today? Why hasn&#x27;t everyone else (<i>especially</i> major projects like GIMP and Audacity) moved off?<p>Here are some possibilities I can think of, but I&#x27;m curious if they&#x27;re correct:<p>- Mailing list hosting<p>- Non-git repository hosting, for projects that prefer CVS or SVN<p>- Shell account (though it doesn&#x27;t seem very useful)<p>- Features GitHub has but few others do (binary hosting, website hosting, etc.) and the project wants to avoid GitHub<p>Are there others?
评论 #9612816 未加载
评论 #9613129 未加载
评论 #9613535 未加载
评论 #9617160 未加载
JohnTHallerabout 10 years ago
SourceForge made a blog post about the GIMP project here: <a href="http:&#x2F;&#x2F;sourceforge.net&#x2F;blog&#x2F;gimp-win-project-wasnt-hijacked-just-abandoned&#x2F;" rel="nofollow">http:&#x2F;&#x2F;sourceforge.net&#x2F;blog&#x2F;gimp-win-project-wasnt-hijacked-...</a><p>It appears they switched the GIMP project on SF back to directly downloading the standard GIMP installer, at least that&#x27;s what I see right now in Firefox at 3:30pm NYC time.
评论 #9613858 未加载
评论 #9615779 未加载
daveloyallabout 10 years ago
As noted in other comments, the GIMP installer on <a href="http:&#x2F;&#x2F;sourceforge.net&#x2F;projects&#x2F;gimp-win&#x2F;files&#x2F;" rel="nofollow">http:&#x2F;&#x2F;sourceforge.net&#x2F;projects&#x2F;gimp-win&#x2F;files&#x2F;</a> is now bit-for-bit identical to the one on <a href="http:&#x2F;&#x2F;download.gimp.org&#x2F;pub&#x2F;gimp&#x2F;v2.8&#x2F;windows&#x2F;" rel="nofollow">http:&#x2F;&#x2F;download.gimp.org&#x2F;pub&#x2F;gimp&#x2F;v2.8&#x2F;windows&#x2F;</a> (let&#x27;s call this one official).<p>Does anybody have a copy of the &quot;value added&quot; installer?<p>How did it work? Was it a wrapper which contained a copy of the official installer? Did it have the same filename? Was there some identifier in the URL? A cookie?<p>In other words, can we programmatically identify other hijacked projects?
评论 #9614420 未加载
评论 #9614320 未加载
Karunamonabout 10 years ago
Wow. Is this legally actionable? Yeah yeah, their server and so forth, but pretending to be somebody is generally seen as a Bad Thing© by the courts.
评论 #9612777 未加载
cillian64about 10 years ago
Is there anything suggesting it&#x27;s SourceForge itself doing this and not just (an improbably widespread, admittedly) set of account breaches? It makes sense -- acquire accounts, enable ads, profit.
评论 #9612601 未加载
kierankabout 10 years ago
The number of people casually suggesting github for large binaries on HN is incredible and funny. They should try downloading something from github in Asia and they&#x27;ll learn why local mirrors are useful.
ajohnclarkabout 10 years ago
I think this pretty much explains why this happened, a quote from their parent company here: &quot;2005 - IN AUGUST, WE ARE ACQUIRED BY DICE HOLDINGS, INC., WHICH IS OWNED EQUALLY BY GENERAL ATLANTIC LLC AND QUADRANGLE LLC, PRIVATE EQUITY FIRMS IN NEW YORK CITY.&quot; via: <a href="http:&#x2F;&#x2F;www.dhigroupinc.com&#x2F;our-company&#x2F;default.aspx" rel="nofollow">http:&#x2F;&#x2F;www.dhigroupinc.com&#x2F;our-company&#x2F;default.aspx</a>
评论 #9619404 未加载
subudeepakabout 10 years ago
Any other projects affected ? Would be nice to start a list of all affected projects. This could also be a case of targeted attack on the gimp account.
评论 #9612277 未加载
评论 #9612290 未加载
评论 #9612390 未加载
评论 #9612245 未加载
j_sabout 10 years ago
Reviewing the meager amount of Twitter chatter it appears SourceForge had cemented its irrelevance before this craziness.
hobarreraabout 10 years ago
In this age of GitHub being huge, and GitLab being the purely open-source choice, this can&#x27;t really end well for SF.<p>They really really need to up their game if they want to stay relevant. Most of the stuff I find pointing me to SF these days is usually abandoned (GIMP and Pidgin are probably notable exception).
SamWhitedabout 10 years ago
I&#x27;ll still never understand why people don&#x27;t move off of SourceForge; GitHub and Bitbucket (among others) are almost feature complete, and for the things that they&#x27;re missing (mailing lists) there are plenty of free alternatives out there that are fairly easy to port.
unhammerabout 10 years ago
More details: <a href="http:&#x2F;&#x2F;libregraphicsworld.org&#x2F;blog&#x2F;entry&#x2F;anatomy-of-sourceforge-gimp-controversy" rel="nofollow">http:&#x2F;&#x2F;libregraphicsworld.org&#x2F;blog&#x2F;entry&#x2F;anatomy-of-sourcefo...</a>
yuhongabout 10 years ago
I wonder what would happen if Google or Yahoo! acquired them.
dm2about 10 years ago
Is that enough to qualify SourceForge as malicious and ask that it be removed from Google&#x27;s search results?
naveen99about 10 years ago
Pywin32 also should find a new home or maybe a reimplementation in golang.