Live data from Hacker News

GitHub censored my research data

gwillem.gitlab.io

91–100 of 206 posts

Re: GitHub censored my research data

#91
As soon as I read this I assumed it was as a libel prevention method.

I'd be curious whether Gitlab/hub could be held responsible for proving the accuracy of the claims? (That was my initial assumption as to the reason they were taken down.)

Re: GitHub censored my research data

#92

I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. Most of the owners probably barely know the Googles from the Facebooks, so even if you email them saying 'you have this JavaScript thing that's bad' they won't understand and will blow you off. OP doesn't go into details of how they check the stores, but I'd assume they have some sort of script as they chec…

Whenever a business hires a contractor to do something for them, the customers will blame the business first if anything is wrong in their product or service. It is up to the business to take the damages in reputation and lost business opportunities to the contractor. Why should we handle this differently for software running online shops?

Re: GitHub censored my research data

#94
post #39

We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service ( https://about.gitlab.com/terms/ ). The author says that he contacted "about 30 merchants directly", but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely…

I'm not sure if responsible disclosure applies here. This isn't an unannounced 0-day that could in theory be in the hands of criminal elements. Responsible disclosure only works because there is a reasonable chance that an exploit is not already widespread.

> an open invitation for malicious users to exploit.

Malicious entities have already exploited these websites. This problem is widespread - over 1000 merchants. The author has not put the cart before the horse.

If I wanted to protect my family against this by installing uBlock Origin on their machines, could uBlock possibly be hosted somewhere where they wouldn't face this censorship? They have in the past temporarily blocked websites (e.g. Sourceforge adware) but have rapidly unblocked them when the issue is resolved; this has saved my bacon on numerous occasions.

I really appreciate the transparency here - kudos. You have your facts wrong.

Re: GitHub censored my research data

#95
post #67

Earlier quoted context omitted.

A 'normal consumer' won't be helped by such a technical list on github/gitlab. Do you really believe they would look there? If they wanted protection they could have installed Ad-blockers etc. long time ago already. (Or use more reputable shops)

a lot of non-normal consumers can end up making a lot of noise, sometimes its enough to cause change to happen as was noted, 600 sites have already cleaned up their act > Update Oct 14: 631 stores have been fixed, good work everybody! So is it really as useless as you claim?

[deleted]

Re: GitHub censored my research data

#96
post #67

Earlier quoted context omitted.

What about the consumers who are being put at risk of being defrauded? Do they not have a right to protection? Malware infected ecommerce sites could be stealing credit card info and robbing consumers. Merchants who endanger consumers by failing to provide a secure platform for digital transactions do not have any right to be protected from having their negligence exposed.

A 'normal consumer' won't be helped by such a technical list on github/gitlab. Do you really believe they would look there? If they wanted protection they could have installed Ad-blockers etc. long time ago already. (Or use more reputable shops)

Lots of people google the name of a webshop to check if it's legit.

Not all, but some non-tech people do that.. And lots of webshop owners google their own shop. Shaming sites that are hosting malware seems perfectly reasonable.

On topic: I assume github/gitlab both completely misunderstood what is going on, and thought this was a disclosure of security holes that could be exploited. I wouldn't be surprised if they do a lot of these.

Perhaps try to throw it up on a few different CDNs where you pay for the service and can contact support. Like S3 or dreamhost (they have decent support too). Arguably github/gitlab isn't the best hosting platform for misunderstood journalists.

Re: GitHub censored my research data

#98
post #65
post #40

GL sent me this statement. For the record, I didn't publish vulnerable systems, I published stores that have malware. --- Willem, GitLab has opted to remove the list of servers that you posted in your snippet. GitLab views the exposure of the vulnerable systems as egregious and will not abide it. While GiLab reserves the right take further action, up to and including termination ( https://about.gitlab.com/terms/ ), w…

Did you ask them for permission to publish a private communication? Probably not, bad of you! - Github/-lab is for projects imho and not a publishing platform. Why don't you publish it on your blog or something? All power to Github/-lab, kick out such stuff!

Github/-lab is for files.

Re: GitHub censored my research data

#99
post #97

I wonder how google acts, if you dump the list here: https://www.google.com/safebrowsing/report_badware/

That's covered in the article:

> I have, prior to publication, submitted all URLs and malware samples to Google’s Safe Browsing team. They have since only acted upon a small portion of the sites.

Post reply on HN