On the Characteristics and Impacts of Protestware Libraries
Tanner Finken, Jesse Chen, Sazzadur Rahaman
摘要
Protests are public expressions of personal or collective discontent with the current state of affairs. Although traditional protests involve in-person events, the ubiquity of computers and software opened up a new avenue for activism: protestware. Recent events in the Russo-Ukrainian war have sparked a wave of protestware, especially in the open-source community. While news and media heavily report individual protestware as discovered, an in-depth understanding of how they impact the open-source software supply chain is largely missing. In particular, we do not have a detailed understanding of their characteristics and impact on the open-source community who rely on free contributions. To address this gap, we first collect 163 samples of libraries that are either modified (protestware) or created (which we call protestware enablers) with a clear intention to protest. In addition, we analyze the aftermath of the protestware, which has the potential to affect the software supply chain in terms of community sentiment and usage. We report that: (1) protestware has three notable characteristics, namely, i) the way protests are induced is diverse, ii) the altered functionality can be discriminatory, and iii) the transparency (i.e. reporting the change for protest) is not always respected;
(2) disruptive protestware may cause a substantial adverse impact on downstream users; (3) developers of protestware may not shift their beliefs even with pushback; (4) the usage of protestware from JavaScript libraries has been seen to generally increase over time.
[Content Warning: This paper contains aggressive and derogatory language in the form of examples from GitHub user comments, which some might find unsettling.] CCS Concepts: • Software and its engineering → Risk management; • Security and privacy → Social aspects of security and privacy; • Social and professional topics → Political speech; • General and reference → Surveys and overviews.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper7
- Small World with High Risks: A Study of Security Threats in the npm EcosystemMarkus Zimmermann, Cristian-Alexandru Staicu, Cam Tenny, Michael PradelUSENIX Security 2019 · 被引用 281 次
- "Did You Miss My Comment or What?" Understanding Toxicity in Open Source DiscussionsCourtney Miller, Sophie Cohen, Daniel Klug, Bogdan Vasilescu 等ICSE 2022 · 被引用 54 次
- Specious Sites: Tracking the Spread and Sway of Spurious News Stories at ScaleHans W. A. Hanley, Deepak Kumar, Zakir DurumericS&P 2024 · 被引用 18 次
- On the Contents and Utility of IoT Cybersecurity GuidelinesJesse Chen, Dharun Anandayuvaraj, James C. Davis, Sazzadur RahamanFSE 2024 · 被引用 1 次
- "Always Contribute Back": A Qualitative Study on Security Challenges of the Open Source Supply ChainDominik Wermke, Jan H. Klemmer, Noah Wöhler, Juliane Schmüser 等S&P 2023
相关 Paper
- Towards Measuring Supply Chain Attacks on Package Managers for Interpreted LanguagesRuian Duan, Omar Alrawi, Ranjita Pai Kasturi, Ryan Elder 等NDSS 2021
- An Empirical Study of Malicious Code In PyPI EcosystemWenbo Guo, Zhengzi Xu, Chengwei Liu, Cheng Huang 等ASE 2023 · 被引用 31 次
- ProfMal: Detecting Malicious NPM Packages by the Synergy between Static and Dynamic AnalysisYiheng Huang, Wen Zheng, Susheng Wu, Bihuan Chen 等ASE 2025 · 被引用 2 次
- SoK: Taxonomy of Attacks on Open-Source Software Supply ChainsPiergiorgio Ladisa, Henrik Plate, Matias Martinez, Olivier BaraisS&P 2023
- The "Shut the f**k up" Phenomenon: Characterizing Incivility in Open Source Code Review DiscussionsIsabella Ferreira, Jinghui Cheng, Bram AdamsCSCW 2021 · 被引用 51 次
