Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

oh geez.... welcome to trademark law

Google.

(why is this getting frontpage HN coverage?)

a trademark is a globally enforceable right (madrid agreement) and one has an obligation to protect ones mark from "dilution" from others in the same category:

i.e. if you are selling "apple" garden shovels, you needn't worry about crossing into "apple" computer land, but I guarantee you that they already registered that mark for "home electronics" etc.

Most countries require formal registration of the trademark (they are searchable in online databases) and most will go on a "first filing" basis. but several, including the USA, go by a "first usage" basis and require you to prove your use of the mark in public...

it's a long shot, but you can always look of that company has, in fact, registered that mark, and in which country/territory are they claiming usage rights.

(for example, they can't be a local computer shop named "apple computers" that only sold to locals since 1854, that suddenly sells computers on the global market, as there is already a global entity with that name registered)



The trademark issue is actually of minor importance here. What is being highlighted is that a publisher of a large number of npm modules removed all of his modules. This broke some people's builds, but, more importantly, drew attention to 2 HUGE security issues:

1.) NPM arbitrarily gave control of a package to a 3rd party, who can then do all manner of evil with it, if they so prefer.

2.) The namespaces of all of these somewhat widely-used packages are now up for grabs. That is, you could make your own malicious version, upload it to NPM, and now all of those builds in all of those different projects will now use your malicious code.

The issue isn't trademark, it's security. That's why it's on the front page of HN.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: