Updated as GitHub Community is moving to GitHub Discussions
Overview
Since what has been going on in the past decade, especially with the Russo-Ukraine war, I've been noticing more cyber attacks lately on the news. If you all don't believe me, check out monitor.firefox.com/breaches to see how much damage has been caused by data breaches alone. I saw an even bigger loophole in the world of open source: a library/framework (ex. Angular, Lodash, Laravel, etc.) can be (ab)used not only by large organizations like Facebook, but individuals/groups as well. Essentially a developer's library/framework can be - and is probably being - used to cause massive collateral damage. For a library developer, knowing that they are enabling a hacker to cause more harm can be demoralizing.
Proposed Resolution
There's not much I can do here as I am not a legal expert, but I can tell you that there probably needs to be a way to make the vague concept of "no hacking/phishing[/...] allowed" into a less ambiguous phrase. However, I did post topics on Mozilla Discourse and GitHub Community (old) (new) that go deeper into the subject; these should help clarify the subject further.
Remarks
I would like to thank the group/organization behind this project for making a license for the greater good! I am hoping to make a few repos public, but I don't want to use current licenses that will allow harm.
Updated as GitHub Community is moving to GitHub Discussions
Overview
Since what has been going on in the past decade, especially with the Russo-Ukraine war, I've been noticing more cyber attacks lately on the news. If you all don't believe me, check out monitor.firefox.com/breaches to see how much damage has been caused by data breaches alone. I saw an even bigger loophole in the world of open source: a library/framework (ex. Angular, Lodash, Laravel, etc.) can be (ab)used not only by large organizations like Facebook, but individuals/groups as well. Essentially a developer's library/framework can be - and is probably being - used to cause massive collateral damage. For a library developer, knowing that they are enabling a hacker to cause more harm can be demoralizing.
Proposed Resolution
There's not much I can do here as I am not a legal expert, but I can tell you that there probably needs to be a way to make the vague concept of "no hacking/phishing[/...] allowed" into a less ambiguous phrase. However, I did post topics on Mozilla Discourse and GitHub Community (old) (new) that go deeper into the subject; these should help clarify the subject further.
Remarks
I would like to thank the group/organization behind this project for making a license for the greater good! I am hoping to make a few repos public, but I don't want to use current licenses that will allow harm.