Umm. I’d say that the Russian-disk-erasing changes are definitely malware.
Software that deliberately deletes the user’s data for no reason related to its immediate purpose, when the user in no way expects that to happen, is malware, open-source or not. And deploying it is an attack. Those are completely orthogonal. (Surely if I put an open-source Metasploit shell on your laptop you’ll have every reason to complain.) The Russian-desktop-file-creating changes are much milder but still on the PUA spectrum, somewhere around the ad-toolbar checkbox in the installer. (Better because not ads, worse because no checkbox.)
Should we object to an open-source maintainer abruptly making their program into malware? In court, per the license terms, no. In general? Probably. At least I can’t find a logical justification to simultaneously object to the Stylish sellout[1] and not object to the surprise anti-Russian changes. (Browser-extension distribution terms of service notwithstanding—I’m sure the NPM terms of service prohibit malware distribution somewhere.)
(Let’s agree not to talk about this as warfare, because acts of war by private, non-military actors—from countries other than those directly participating in the conflict—against a population that is certain to include civilian targets to an extent serving no direct military purpose... I could see that, but obviously it’s a huge can of worms, and besides that’s not the argument the “protestware” authors made.)
Should we object to an open-source maintainer sabotaging their own software, like in the left-pad case? Presumably we shouldn’t to them just giving up or abandoning their website, so this becomes a bit trickier. I still lean towards “yes”. If I am a jerk, I don’t cease being one even if I stick a note with MAY SCREAM OBSCENITIES AT YOU FOR NO REASON on my forehead, at all, let alone in a world where most people walk around with those. But I can imagine being convinced otherwise.
Software that deliberately deletes the user’s data for no reason related to its immediate purpose, when the user in no way expects that to happen, is malware, open-source or not. And deploying it is an attack. Those are completely orthogonal. (Surely if I put an open-source Metasploit shell on your laptop you’ll have every reason to complain.) The Russian-desktop-file-creating changes are much milder but still on the PUA spectrum, somewhere around the ad-toolbar checkbox in the installer. (Better because not ads, worse because no checkbox.)
Should we object to an open-source maintainer abruptly making their program into malware? In court, per the license terms, no. In general? Probably. At least I can’t find a logical justification to simultaneously object to the Stylish sellout[1] and not object to the surprise anti-Russian changes. (Browser-extension distribution terms of service notwithstanding—I’m sure the NPM terms of service prohibit malware distribution somewhere.)
(Let’s agree not to talk about this as warfare, because acts of war by private, non-military actors—from countries other than those directly participating in the conflict—against a population that is certain to include civilian targets to an extent serving no direct military purpose... I could see that, but obviously it’s a huge can of worms, and besides that’s not the argument the “protestware” authors made.)
Should we object to an open-source maintainer sabotaging their own software, like in the left-pad case? Presumably we shouldn’t to them just giving up or abandoning their website, so this becomes a bit trickier. I still lean towards “yes”. If I am a jerk, I don’t cease being one even if I stick a note with MAY SCREAM OBSCENITIES AT YOU FOR NO REASON on my forehead, at all, let alone in a world where most people walk around with those. But I can imagine being convinced otherwise.
(I want such a note now.)
[1] https://robertheaton.com/2018/08/16/stylish-is-back-and-you-...