hckrnws
GitHub has not removed malicious imitation software after 3 weeks
by hermitcrab
by hermitcrab
Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.
And it seems they are able to do things very quickly, when they want to. Bastards.
This also works for Google support.
> And it seems they are able to do things very quickly, when they want to. Bastards.
I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
It was already a problem before agents could automatically perform these actions.
And it’s not something you can really automate on their end either. At least not the judgement call on the removal. Imagine if there was a fully automated process and it inadvertently took down a legit project.
Stalling in the hope that reporters won't escalate, instead of allocating a tiny bit of their billions in profit to hiring for this, is malicious in my book.
Not excusing their slow response, though.
Unfortunately drawing attention to it would likely invoke the Streissand effect and be counter productive so I can only wait until the frabjous day that github goes dark at last.
And how I am supposed to know who they are or how to reach them?
> ping ~anyone on the security team
> HN provided them some bandwidth
> also works for Google support
> answered within a day earlier this year
> no reaction otherwise. It's still online.
> app stuck in limbo at Apple
https://en.wikipedia.org/wiki/Cargo_cult_programming
> given what we know publicly
> thread of evidence
https://lowendbox.com/blog/will-github-ever-remove-this-null...
Booking.com kept a clearly fraudulent listing (images clearly stolen from another Booking.com listing with mirroring + some filters) fully online for at least two days (I got distracted and stopped taking daily screenshots after that). I just got a response that they've taken it down almost 10 days after I had initially reported it (although I think they marked it as not bookable some time before that).
Not the worst thing in the world, they're easy to spot, but I'd like to see GitHub invest more time in protecting their users from falling victim to these bad actors.
There's an impersonation profile of me on Github (username happyhannob). I've reported it a while ago, received the same automated message, and no reaction otherwise. It's still online.
I guess you can't expect basic fraud prevention from a company currently building the future with AI...
[deleted]
[dead]
Open source code is still copyrighted. What the license defines is rights that people have in distributing that code. If an unofficial repository is using open source code to ship malware, and the license that software had didn’t allow that, then the unofficial repository is still breaking copyright law despite the code being open source.
I think the likelihood GitHub did something within 10 minutes of a post appearing on HN's front page is approximately zero.
Nobody in GitHub Trust & Safety is sat there watching HN.
An executive or communications professional who might have heard it got on HN, or seen it appear in a tool monitoring Microsoft and GitHub's mentions across the internet, and who then flagged the post, Trust & Safety would probably spend *more than 10 minutes* noticing the email or Teams message, then trying to find the right ticket internally. Then after locating the ticket you still have to investigate the facts, discuss, and click buttons to ban/delete the user.
It's (much) more likely this sat in a queue until someone got to it and the timing of it being on HN is a complete coincidence.
It is also comically understaffed. This is not because they can't find people to work - it's not given the budget necessary.
Where does this myth come from, and how does it survive? It's either an excuse for parasitic corporatism, or an expression of learned helplessness. Nobody has been successfully sued for prioritizing the long-term health and reputation of a company over self-starving quarterly profit.
Is there a perverse incentive toward the latter anyway? Yes. But it mostly serves current leadership, who are evaluated and paid on short horizons, at the expense of the long-term investors who own most of the equity.
"Accepting funding from investors puts you in a fiduciary role in which you’re responsible for managing their money and putting their needs above your own"
Then maybe they should be growing their customer support capacity along with their business. It drives me crazy how big companies have normalized cutting those departments down to anemic proportions. Especially those where you're a paying customer.
I don't see that changing for any of the large companies unfortunately, anytime soon.
They just don't want to. Not malicious, just ignorant and disrespectful of their users.
It's malice from whoever is responsible for under-staffing. It's also malice to prioritize the squeaky wheel for optics; it's intentional to reduce the spread of the knowledge of how unresponsive they are.
Handling these requests at whatever scale they operate is their responsibility.
Nobody held a gun to their head and forced them to take on all of their customers.
There’s no need for benefit of the doubt when it comes to the level of support provided by tech companies.
Bad support by tech companies is a conscious profit-preserving choice.
[deleted]
For example (simplified), if a user makes a call, a person with sufficient privileges to handle 90% of the cases should answer on the other end within 2 minutes. If the case cannot be handled, the higher-up with privileges to handle 99% of the cases should be reached within 5 minutes. And to be fair, it should be mandated for all companies, not only FAANG-like.
But a company like Meta (for example) with a billion customers would then have to decide whether they want to work on quality improvements for their services or whether they would like to hire a million technical support staff.
Just seems like a silly rational response to the same problem.
Yes, indeed public awareness of a problem affects how an issue is reprioritized. Some companies even employ web scrapers to do sentiment analysis at each release, and visible issues do get bumped to high priority.
It's amusing how some people in this thread try to pretend this doesn't happen, and make these bold assertions with a straight face in replies to people who were in actual meetings where issues were escalated because of this.
[deleted]
[dead]
It's not illegal to send an incorrect one by mistake but GitHub probably won't process it. It's illegal to send an incorrect one intentionally. Now that it's been pointed out to you that making malware isn't a copyright violation, it's intentional if you send a DMCA anyway.
EDIT: e.g. https://www.mozilla.org/en-US/foundation/trademarks/policy/
You're correct I was overly broad about the actual name use being DMCA-able though.
[deleted]
Now, projects might choose to license their logo permissively, but that's an active choice.
Please, any competent software dev business has eyes on this page on an hourly basis.
I'm in aerospace and we're crawling on this site, all the way at the top levels.
The lengths people will go to "never attribute to malice..." are pretty impressive in these days of baldly stated or visible malice from the top.
https://corpgov.law.harvard.edu/2012/06/26/the-shareholder-v...
https://www.legislate.ai/blog/does-the-law-require-public-co...
https://lawreview.law.ucdavis.edu/archives/56/5/end-sharehol...
https://news.ycombinator.com/item?id=20325023
https://en.wikipedia.org/wiki/Shareholder_value
So yeah, "fiduciary duty" is a real thing, but that's not quite the same thing as saying that every single decision has to be focused on nothing but profit maximization.
[deleted]
I didn't say anything remotely like that, so I'm going to assume you're not trying to have a good faith discussion here, and decline to participate any further. Have a nice day.
And this neglecting all duties besides profits thing is real, it is institutionalized by decisions of investors, by managers hired by investors, by regulators "captured" by investors and so-forth. It is the norm. But that doesn't it's a legal or ethical that a given manager or employee has, at least not currently.
> To quote the U.S. Supreme Court opinion in the recent Hobby Lobby case: “Modern corporate law does not require for-profit corporations to pursue profit at the expense of everything else, and many do not.”
https://www.nytimes.com/roomfordebate/2015/04/16/what-are-co...
Executives are free to pursue near-term profit at the expense of everything else if they choose, and the shareholders are free to replace them if they don't. That's a choice by those executives or shareholders though, not an obligation.
Is there an incentive to do that? Yes, or at least it's obviously quite possible. But is there an obligation? No.
Relative to the comment you were responding to, it sounded like you were defending the idea that an obligation exists.
The distinction matters because if such an obligation did exist it would effectively excuse a lot of bad behavior.
This behavior is a matter of incentives, not obligations. No need to apologize for them.
"Fiduciary duty" does not mean "pursue profit to the exclusion of all other considerations".
I strongly agree that failure to stand for consumer rights is both learned helplessness and an apologist cooperator psychology. CA Voter here.
"Obligation" is the wrong word. Should be "incentive".
"Show me the incentive and I'll show you the outcome."
If you look at the case law for fiduciary responsibility, then you'll find that executives have a strong obligation against self-dealing (decisions that clearly benefit them at the expense of the shareholder), but not much else. The "business judgment rule" makes it generally lawful for executives to make decisions that you, the shareholders, the judge, or anyone else might consider to be bad business judgment. It couldn't really be otherwise, since the difference between wasteful spending and a wise investment in the company's reputation might be unclear even decades later.
If shareholders disagree with an executive's business judgment, then their remedy is to fire that executive. That remedy has nothing specific to "making money"--the shareholders are just as free to fire a CEO for excessive attention to profit as insufficient.
You linked an article about fiduciary responsibility, and that's also a legal obligation. If I'm an executive and I route contracts to a vendor that I own for personal gain, then the shareholders can sue me and I will lose. The state will likewise enforce that judgment, if necessary with physical force.
If I'm an executive and I choose to spend too much money (in someone's opinion) auditing a git hosting site for malware, then the possibility that I'll get sued for that and lose is zero. That's the "business judgment rule", which is a legal term of art that you can search. The shareholders might fire me, but only in the same way they could fire me for anything.
The financial incentives are obviously as you say, but the difference between "things I do because the state will physically punish me if I don't" and "things I do because I want a high-paying job" is valuable to me. I could probably make more money than I do now if I worked for a payday lender or an online casino, but I don't think that obligates me to do so.