TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

“It appears that SourceForge took control of the 'GIMP for Windows' account”

166 点作者 patdavid将近 10 年前

18 条评论

scrollaway将近 10 年前
Reposting what I wrote on the Reddit thread:<p>I&#x27;m one of the lead devs of LXQt and an LXDE sysadmin. We use Sourceforge for our mailing lists and some LXDE legacy stuff.<p>I&#x27;m absolutely sick of them. It&#x27;s not the first time this has happened. I&#x27;ve been pushing for us to move off SF for a while and this is a good occasion to push for it harder.<p>I&#x27;ve sent an email [1] detailing plans to move. I am urging everyone who still has projects on Sourceforge to do the same.<p>If you have similar migration problems to solve as the ones I&#x27;ve highlighted in the email, please contact me directly and we can share the workload. My email is available on my Github profile [2].<p>[1] <a href="http:&#x2F;&#x2F;sourceforge.net&#x2F;p&#x2F;lxde&#x2F;mailman&#x2F;message&#x2F;34148903&#x2F;" rel="nofollow">http:&#x2F;&#x2F;sourceforge.net&#x2F;p&#x2F;lxde&#x2F;mailman&#x2F;message&#x2F;34148903&#x2F;</a> [2] <a href="https:&#x2F;&#x2F;github.com&#x2F;jleclanche" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;jleclanche</a>
etix将近 10 年前
This is precisely for these reasons we stopped distributing VLC via SF.net in 2013. I even wrote about it: <a href="https:&#x2F;&#x2F;blog.l0cal.com&#x2F;2013&#x2F;05&#x2F;02&#x2F;rethinking-vlc-mirrors-infrastructure&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.l0cal.com&#x2F;2013&#x2F;05&#x2F;02&#x2F;rethinking-vlc-mirrors-inf...</a>
评论 #9612799 未加载
评论 #9613699 未加载
jbk将近 10 年前
Our VLC account has been taken too by sf-editor-1.<p>Fortunately, we&#x27;ve moved to our mirror infrastructure since quite some time, and it&#x27;s faster and way better.<p>Btw, if any other open source project needs help to distribute their binaries (because of the size), please contact me.<p>PS-EDIT: signing the installer was a good idea, I guess :)
评论 #9617158 未加载
geofft将近 10 年前
What are the reasons for people to use SourceForge today? Why hasn&#x27;t everyone else (<i>especially</i> major projects like GIMP and Audacity) moved off?<p>Here are some possibilities I can think of, but I&#x27;m curious if they&#x27;re correct:<p>- Mailing list hosting<p>- Non-git repository hosting, for projects that prefer CVS or SVN<p>- Shell account (though it doesn&#x27;t seem very useful)<p>- Features GitHub has but few others do (binary hosting, website hosting, etc.) and the project wants to avoid GitHub<p>Are there others?
评论 #9612816 未加载
评论 #9613129 未加载
评论 #9613535 未加载
评论 #9617160 未加载
JohnTHaller将近 10 年前
SourceForge made a blog post about the GIMP project here: <a href="http:&#x2F;&#x2F;sourceforge.net&#x2F;blog&#x2F;gimp-win-project-wasnt-hijacked-just-abandoned&#x2F;" rel="nofollow">http:&#x2F;&#x2F;sourceforge.net&#x2F;blog&#x2F;gimp-win-project-wasnt-hijacked-...</a><p>It appears they switched the GIMP project on SF back to directly downloading the standard GIMP installer, at least that&#x27;s what I see right now in Firefox at 3:30pm NYC time.
评论 #9613858 未加载
评论 #9615779 未加载
daveloyall将近 10 年前
As noted in other comments, the GIMP installer on <a href="http:&#x2F;&#x2F;sourceforge.net&#x2F;projects&#x2F;gimp-win&#x2F;files&#x2F;" rel="nofollow">http:&#x2F;&#x2F;sourceforge.net&#x2F;projects&#x2F;gimp-win&#x2F;files&#x2F;</a> is now bit-for-bit identical to the one on <a href="http:&#x2F;&#x2F;download.gimp.org&#x2F;pub&#x2F;gimp&#x2F;v2.8&#x2F;windows&#x2F;" rel="nofollow">http:&#x2F;&#x2F;download.gimp.org&#x2F;pub&#x2F;gimp&#x2F;v2.8&#x2F;windows&#x2F;</a> (let&#x27;s call this one official).<p>Does anybody have a copy of the &quot;value added&quot; installer?<p>How did it work? Was it a wrapper which contained a copy of the official installer? Did it have the same filename? Was there some identifier in the URL? A cookie?<p>In other words, can we programmatically identify other hijacked projects?
评论 #9614420 未加载
评论 #9614320 未加载
Karunamon将近 10 年前
Wow. Is this legally actionable? Yeah yeah, their server and so forth, but pretending to be somebody is generally seen as a Bad Thing© by the courts.
评论 #9612777 未加载
cillian64将近 10 年前
Is there anything suggesting it&#x27;s SourceForge itself doing this and not just (an improbably widespread, admittedly) set of account breaches? It makes sense -- acquire accounts, enable ads, profit.
评论 #9612601 未加载
kierank将近 10 年前
The number of people casually suggesting github for large binaries on HN is incredible and funny. They should try downloading something from github in Asia and they&#x27;ll learn why local mirrors are useful.
ajohnclark将近 10 年前
I think this pretty much explains why this happened, a quote from their parent company here: &quot;2005 - IN AUGUST, WE ARE ACQUIRED BY DICE HOLDINGS, INC., WHICH IS OWNED EQUALLY BY GENERAL ATLANTIC LLC AND QUADRANGLE LLC, PRIVATE EQUITY FIRMS IN NEW YORK CITY.&quot; via: <a href="http:&#x2F;&#x2F;www.dhigroupinc.com&#x2F;our-company&#x2F;default.aspx" rel="nofollow">http:&#x2F;&#x2F;www.dhigroupinc.com&#x2F;our-company&#x2F;default.aspx</a>
评论 #9619404 未加载
subudeepak将近 10 年前
Any other projects affected ? Would be nice to start a list of all affected projects. This could also be a case of targeted attack on the gimp account.
评论 #9612277 未加载
评论 #9612290 未加载
评论 #9612390 未加载
评论 #9612245 未加载
j_s将近 10 年前
Reviewing the meager amount of Twitter chatter it appears SourceForge had cemented its irrelevance before this craziness.
hobarrera将近 10 年前
In this age of GitHub being huge, and GitLab being the purely open-source choice, this can&#x27;t really end well for SF.<p>They really really need to up their game if they want to stay relevant. Most of the stuff I find pointing me to SF these days is usually abandoned (GIMP and Pidgin are probably notable exception).
SamWhited将近 10 年前
I&#x27;ll still never understand why people don&#x27;t move off of SourceForge; GitHub and Bitbucket (among others) are almost feature complete, and for the things that they&#x27;re missing (mailing lists) there are plenty of free alternatives out there that are fairly easy to port.
unhammer将近 10 年前
More details: <a href="http:&#x2F;&#x2F;libregraphicsworld.org&#x2F;blog&#x2F;entry&#x2F;anatomy-of-sourceforge-gimp-controversy" rel="nofollow">http:&#x2F;&#x2F;libregraphicsworld.org&#x2F;blog&#x2F;entry&#x2F;anatomy-of-sourcefo...</a>
yuhong将近 10 年前
I wonder what would happen if Google or Yahoo! acquired them.
dm2将近 10 年前
Is that enough to qualify SourceForge as malicious and ask that it be removed from Google&#x27;s search results?
naveen99将近 10 年前
Pywin32 also should find a new home or maybe a reimplementation in golang.