TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

SourceForge: Third party offers will be presented with Opt-In projects only

43 pointsby Xylemonalmost 10 years ago

15 comments

captaindiegoalmost 10 years ago
&quot;As a company, we at SourceForge pride ourselves on being highly responsive to our community members and, with that in mind, do our best to respond to all communications and address all concerns in a timely manner.&quot;<p>&quot;Comments are closed.&quot;
评论 #9644484 未加载
gcb0almost 10 years ago
i use one program with frequent updates which distributes from sourceforge.<p>the installer is a piece of work.<p>first, it is a fake-installer (that installs nothing) with the actual installer inside. that program first offers you &quot;standard&quot; and &quot;advanced&quot; fake-install options (remember, it install nothing)... when you click &quot;advanced&quot; it now shows 3 checkboxes, checked, that will 1. install a browser toolbar, 2. set your default homepage, 3. set your default search engine. You uncheck them all and click accept (it is also showing a terms and conditions). now it will show something like &quot;also install this tracking or browser or i don&#x27;t even know what it was?&quot; and there is only the same buttons as before on the fake-installer: &quot;decline&quot; and &quot;accept&quot;. Now you have to remember to go against all your knowledge of install wizards and click the left button &quot;decline&quot; to proceed with your desired program only. now you click accept or finish, don&#x27;t remember, one last time, and the fake-installer forks to the actual installer that you wanted from the beginning.
评论 #9643876 未加载
评论 #9643917 未加载
SwellJoealmost 10 years ago
This is nice and all, but...the mere fact that SourceForge, an <i>Open Source community site</i>, ever thought it was even close to OK to intentionally distribute malware to anyone under any circumstances (whether with the permission of the developer, or not). AFAIK, by calling themselves and Open Source community site, SourceForge has opted into an ethical obligation not just to their developers who build the software but the entirety of the Open Source software community to protect their users from malicious code.<p>This episode was indicative of a severe loss of direction and guiding principles.
评论 #9644413 未加载
评论 #9644442 未加载
greenyodaalmost 10 years ago
Some context, for those who haven&#x27;t been following this story:<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9612152" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=9612152</a>
jacquesmalmost 10 years ago
Sourceforge has killed itself by completely breaking the trust with their developers and their end-users.
评论 #9644398 未加载
mindcrashalmost 10 years ago
Oh right, like a project such as the GIMP (<i>GNU</i> Image Manipulation Program) would &quot;opt in&quot; with having &quot;third party offers&quot; (e.g. spyware) in their distribution packages. Just pull the plug, SourceForge. You are done.
bobwaycottalmost 10 years ago
&gt;&gt;&gt; &quot;At this time, we present third party offers only with a few projects where it is explicitly approved by the project developer, <i>or if the project is already bundling third party offers</i>.&quot;<p>Uhhhh ... I&#x27;m undoubtedly being way too cynical, but that sure sounds like a back-handed way of saying they&#x27;re going to &quot;present&quot; these third-party &quot;offers&quot; <i>on top of</i> any projects that are already bundling such &quot;offers&quot;.<p>Also, &quot;present&quot; ... really? What a horrible word choice, given the UX patterns involved here. Total bullshit.<p>And furthermore, how exactly will SourceForge gain this explicit approval by the project developer? I&#x27;d like to hear more on that note. Do they modify their terms &amp; conditions to make this an auto-opt-in for all new accounts? Are existing accounts grandfathered into this by a default opt-in, on account of having been notified by email of newly updated Terms, the way various companies like to engage in wrong patterns for implied approvals by-means-of-using-our-service that benefit the bottom-line first, and preference typical user sentiment second?<p>[EDIT: wording correction]
hliyanalmost 10 years ago
In my mind, the damage is already done. And as damage control goes, this leaves something to be desired:<p><pre><code> While we had recently tested presenting easy-to-decline third party offers... </code></pre> That sounds almost like &quot;you should have read the fine print&quot;. They could have at least started the announcement with &quot;We&#x27;re very sorry for the problems caused by our recent...&quot;
simplexionalmost 10 years ago
On top of this &#x2F;. is burying articles critical of this: <a href="http:&#x2F;&#x2F;danluu.com&#x2F;slashdot-sourceforge&#x2F;" rel="nofollow">http:&#x2F;&#x2F;danluu.com&#x2F;slashdot-sourceforge&#x2F;</a>
评论 #9644378 未加载
评论 #9644765 未加载
sudeepjalmost 10 years ago
With the likes of github around and offering much better experience, sourceforge seems outdated anyway. The damage is already done.
t_fatusalmost 10 years ago
Oh thank you SF, that&#x27;s really nice.
zeruchalmost 10 years ago
SF.net died years ago. This remnant that continues is a farce.
ratfacemcgeealmost 10 years ago
damage is already done, its a real shame too.
neuromutealmost 10 years ago
The death throes of a company.
bobwaycottalmost 10 years ago
Why is it so hard for many online companies&#x2F;services that desire to monetize their product(s) to accept that, given the choice, <i>nobody</i> opts-in to ads, marketing, privacy invasion, and other shit that turns them into a product? I&#x27;ve been reading HN for years, and this news cycle of OMG-Custom-Whizbang-Inc-has-opted-you-in-to-Shady-Feature-Fizzbuzz seems to break on the regular.<p>Want to monetize your product? Start on Day Fucking One, with User Number One. Make them pay.<p>Want to start off free, and worry about monetizing your product later? Don&#x27;t fucking automatically opt your users into being the product you sell to advertisers. Don&#x27;t snoop on them, or otherwise invade their privacy. Don&#x27;t be an asshole to them and force something on them they haven&#x27;t already agreed to. Default to every new &amp; existing user being opted <i>out</i> of any of these things. Make it an organizational principal that explicit opt-in behavior is The Right Way™ -- such as signing up for a paid tier of service, like Github and many other good actors do in this regard.<p>I seriously cannot think of many things that happen in the lifecycle of an online service in which automatically opting users into some process is the best and most honest experience, and the thing most people want. That people accept this crap is beyond me.<p>Nobody would allow this to happen in their non-digital lives:<p>&quot;Hey, John, Jerk Pest Control here. You&#x27;ve been using our quarterly service for a while now. We&#x27;re rolling out a new service that visits every month, and we&#x27;re going to keep the price the same as before by selling your information to some other local businesses that want you as their customer. We&#x27;ve opted you into the service automatically. Why? Well, we&#x27;re looking to break out of our cyclic dependency on quarterly fees to help hit business growth targets. There was a small note informing you of this opt-in that went out with your last bill.&quot;<p><i>grumbling and swearing commences. phone beeps with another call...</i><p>&quot;Hey, Mary. Dick&#x27;s Accounting Service. You left a message about phone calls received from other companies who say we shared your number. We&#x27;ve been taking care of your taxes for the past few years, and are testing out a new service of presenting easy-to-decline third-party financial services to you, based on how well we think they fit what we know about your annual financial picture. We&#x27;ve carefully chosen our partners, and we only share just enough information to help them verify your viability as a candidate for service. We opted you into this service for your convenience. Why? Well, we&#x27;re trying to maximize the returns of providing excellent service for your needs beyond just the once-yearly tax visits. We sent you an email about new Terms of Service around tax time, and you agreed to them when you used us to file your taxes this year.&quot;<p><i>grumbling and swearing. inquire about opting out of the service.</i><p>&quot;Oh, that&#x27;s <i>easy</i>. To decline the offers, just tell them you&#x27;re not interested in the service. When they ask if you would like to confirm you are sure you&#x27;re not interested in being removed from their call list, or would like to decline being removed from their call list, tell them you&#x27;re not interested and would like to decline. Piece of cake.&quot;<p>Yes, SourceForge are being total assholes with this whole debacle. But let&#x27;s maybe take a minute to ponder where they even got the ideas from, and why we are only offended when a once-free service that markets itself as having something to do with &quot;open source&quot; or &quot;free software&quot; is the bad actor.<p><i>Too many online companies and services think this behavior is perfectly acceptable, and build up their services in a tech culture that accepts it</i>. It&#x27;s a bit ridiculous to draw lines in the sand and have so much outrage only for the likes of SourceForge. None of this ought to be <i>that</i> surprising.<p>&lt;&#x2F;tangentially_related_rant&gt;