this post was submitted on 10 Aug 2023
17 points (100.0% liked)

Fight For Privacy

294 readers
1 users here now

Fight For Privacy

A community to post, discuss and fight for our privacy.

Post Title Rule

Tag what the post is:

Post examples

Language: English

Rules

  1. Keep the topic on privacy
  2. Be respectful and tolerant
  3. When posting link use tools like CleanURL to get rid of trackers
  4. When posting numbers or statements, you need to link the source
  5. Promotion of products/brands are forbidden
  6. Politics not regarding privacy is forbidden, keep it on laws/decisions that concern privacy
  7. If possible post Invidious links instead of YouTube

[email protected]

founded 1 year ago
MODERATORS
 

Open source project Moq (pronounced "Mock") has drawn sharp criticism for quietly including a controversial dependency in its latest release.

Distributed on the NuGet software registry, Moq sees over 100,000 downloads on any given day, and has been downloaded over 476 million times over the course of its lifetime.

Moq's 4.20.0 release from this week quietly included another project, SponsorLink, which caused an uproar among open source software consumers, who likened the move to a breach of trust.

Seemingly an open-source project, SponsorLink is actually shipped on NuGet as closed source and contains obfuscated DLLs that collect hashes of user email addresses and send these to SponsorLink's CDN, raising privacy concerns.

no comments (yet)
sorted by: hot top controversial new old
there doesn't seem to be anything here