Live data from Hacker News

GitHub censored my research data

gwillem.gitlab.io

71–80 of 206 posts

Re: GitHub censored my research data

#71
post #40

GL sent me this statement. For the record, I didn't publish vulnerable systems, I published stores that have malware. --- Willem, GitLab has opted to remove the list of servers that you posted in your snippet. GitLab views the exposure of the vulnerable systems as egregious and will not abide it. While GiLab reserves the right take further action, up to and including termination ( https://about.gitlab.com/terms/ ), w…

And even if it were (a list of vulnerable systems, that is), why the fuck do they think that they should censor serious journalism? If you operate a public venue, then it is an important societal role of journalism to report on it if that public venue poses a risk to the public, whether that might also have negative consequences for the people operating it is completely irrelevant.

Are they in the business of journalism?

Lots of people are saying "But the sites are already exploited" ... they are probably still exploitable further also, and GH/GL don't want to be at that party.

Re: GitHub censored my research data

#72
post #67

Earlier quoted context omitted.

What about the consumers who are being put at risk of being defrauded? Do they not have a right to protection? Malware infected ecommerce sites could be stealing credit card info and robbing consumers. Merchants who endanger consumers by failing to provide a secure platform for digital transactions do not have any right to be protected from having their negligence exposed.

A 'normal consumer' won't be helped by such a technical list on github/gitlab. Do you really believe they would look there? If they wanted protection they could have installed Ad-blockers etc. long time ago already. (Or use more reputable shops)

a lot of non-normal consumers can end up making a lot of noise, sometimes its enough to cause change to happen

as was noted, 600 sites have already cleaned up their act

> Update Oct 14: 631 stores have been fixed, good work everybody!

So is it really as useless as you claim?

Re: GitHub censored my research data

#73
post #40

GL sent me this statement. For the record, I didn't publish vulnerable systems, I published stores that have malware. --- Willem, GitLab has opted to remove the list of servers that you posted in your snippet. GitLab views the exposure of the vulnerable systems as egregious and will not abide it. While GiLab reserves the right take further action, up to and including termination ( https://about.gitlab.com/terms/ ), w…

And even if it were (a list of vulnerable systems, that is), why the fuck do they think that they should censor serious journalism? If you operate a public venue, then it is an important societal role of journalism to report on it if that public venue poses a risk to the public, whether that might also have negative consequences for the people operating it is completely irrelevant.

You mistook "free and accessible" with "public".

You may exercise freedom of speech but not on server that belongs to a private company - it is their right to limit what kind of content they like.

But in an essence you are right - companies should exist to benefit society, but it is not how it exactly works right now.

Re: GitHub censored my research data

#74
post #63
post #39

We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service ( https://about.gitlab.com/terms/ ). The author says that he contacted "about 30 merchants directly", but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely…

This is completely unacceptable. You're treating this as though the author was publishing a list of vulnerabilities about sites. That's not what the author did. The author published a list of sites that are already infected with malware and thus are dangerous for users to visit. This is a public service and there is zero expectation of "responsible disclosure" to the sites. The only thing that disclosing to the sites…

Couldn't agree more.

I'm not sure if GL is trying to protect themselves against something and are making up some excuse to justify it but the reasons given for taken down the list don't hold water.

GL would be far better stating the real reason for taking the info down (surely there must be one).

So far what they've done is seemingly to protect the merchants reputation and perhaps protect GL from some imagined legal backlash? The backlash would have no basis is court or other services like Google's own SafeBrowing would not be viable.

Are we to assume the GL cares more about that than users/visitors to these sites?

The statement from GP is frankly pathetic.

Re: GitHub censored my research data

#75
post #67

Earlier quoted context omitted.

What about the consumers who are being put at risk of being defrauded? Do they not have a right to protection? Malware infected ecommerce sites could be stealing credit card info and robbing consumers. Merchants who endanger consumers by failing to provide a secure platform for digital transactions do not have any right to be protected from having their negligence exposed.

A 'normal consumer' won't be helped by such a technical list on github/gitlab. Do you really believe they would look there? If they wanted protection they could have installed Ad-blockers etc. long time ago already. (Or use more reputable shops)

You're saying that because normal consumers wont be helped by a "technical" list on github/gitlab, we shouldn't bother?

What about "technical" users?

Re: GitHub censored my research data

#76

Earlier quoted context omitted.

So, you don't think that if you operate something that is a risk to other people, it's your obligation to reduce the risk? You can just say that you are incompetent at what you are doing, and therefore you shouldn't be shamed for putting other people at risk?

I edited my post, but I don't think that's really fair. The business most likely outsourced the development of their site to someone who probably assured them that they would build a secure site. The business probably trusted them (maybe the developer was even recommended) yet here we are. The business didn't know enough about building a secure website, so hired someone they assumed did. Edit - Poor analogy removed.

What's even your analogy here? Because sometimes people have bad luck and you can make up a completely unrealistic scenario of how bad luck someone possibly could have, we should not hold anyone responsible for anything?

To give you an idea of how unrealistic your scenario is: In reality, yes, the owner of the damaged property could force you to pay for the repair, but also, you could force the plumber to reimburse you for that, and they in turn probably will have insurance for that sort of thing that will reimburse them in turn. Noone would be kicked out of anything, except for the plumber by the insurer if they had that happen a bit too often.

Re: GitHub censored my research data

#77
post #66

I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. Most of the owners probably barely know the Googles from the Facebooks, so even if you email them saying 'you have this JavaScript thing that's bad' they won't understand and will blow you off. OP doesn't go into details of how they check the stores, but I'd assume they have some sort of script as they chec…

> I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. So the malware should be allowed to continue stealing credit card numbers just because the site owners don't know any better? Is that really a position you wish to defend?

No I don't agree that it should be allowed to continue, but how is naming&shaming people going to fix anything? Nothing is going to come of this, other than maybe some other hackers will see them as weak targets. Do you expect this list to be read on prime time CNN or something? People who want to buy something online aren't going to search through GitLab to check if the site has been hacked (maybe they should though), they just look for the green padlock and assume it's safe.

As I said, and GitLab suggested, OP should at least contact them. If you contact them and they say they won't do anything, now that's a different story...

Re: GitHub censored my research data

#78

Earlier quoted context omitted.

So, you don't think that if you operate something that is a risk to other people, it's your obligation to reduce the risk? You can just say that you are incompetent at what you are doing, and therefore you shouldn't be shamed for putting other people at risk?

I edited my post, but I don't think that's really fair. The business most likely outsourced the development of their site to someone who probably assured them that they would build a secure site. The business probably trusted them (maybe the developer was even recommended) yet here we are. The business didn't know enough about building a secure website, so hired someone they assumed did. Edit - Poor analogy removed.

A solution to this is to hire a pentester for your site. You can find them for ~$5k, with followup tests for new features being around $2k. A professional, world-class pentest runs around $50k, but a lot of smaller sites can't afford that.

You can't really hire someone with the expectation that they'll develop secure code. Finding flaws in code people thought was secure is a pentester's job, and it's a completely different skillset.

Re: GitHub censored my research data

#79
post #66

I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. Most of the owners probably barely know the Googles from the Facebooks, so even if you email them saying 'you have this JavaScript thing that's bad' they won't understand and will blow you off. OP doesn't go into details of how they check the stores, but I'd assume they have some sort of script as they chec…

> I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. So the malware should be allowed to continue stealing credit card numbers just because the site owners don't know any better? Is that really a position you wish to defend?

Sites will always continue to carry malware. Naming and shaming without looking at all the parties involved is a crude and ineffective way of changing things.

Change the browser, change the payment system, educate the user by using plugins, propose enhanced security methods in ECMAscript. Write about how easy it is to make missteps on the net. These are all alternatives which might help in a more permanent fashion.

Re: GitHub censored my research data

#80

And just like that, we discover how helpless the average Joe is against corporate money. Let's crowdfund an AWS s3+CloudFront hosted site. DDosing that is no easy feat, and if corps do try it, the logs can prove their complicity, which has legal implications I presume

[deleted]
Post reply on HN