Live data from Hacker News

GitHub censored my research data

gwillem.gitlab.io

181–190 of 206 posts

Re: GitHub censored my research data

#181
Definitely feels like a bad interpretation on Gitlab's part, but not done out of malice.

The person was not exposing sites that nobody previously knew about -- the sites were already compromised, there is nothing to compromise again except maybe having more than one attacker in your compromised account. The damage is already done, though.

These are likely web applications that were not kept up to date so the responsible security disclosure already happened when it was reported for WordPress/Drupal/Joomla. It is the site owners responsibility to pay attention to those security disclosures, which they likely failed to do.

And those compromised sites, in my experience, are usually attacking and infecting other sites and servers on the Internet. That makes them a public nuisance and so public disclosure is necessary so they can be appropriately blocked/isolated.

Re: GitHub censored my research data

#182
post #96
post #67

Earlier quoted context omitted.

A 'normal consumer' won't be helped by such a technical list on github/gitlab. Do you really believe they would look there? If they wanted protection they could have installed Ad-blockers etc. long time ago already. (Or use more reputable shops)

Lots of people google the name of a webshop to check if it's legit. Not all, but some non-tech people do that.. And lots of webshop owners google their own shop. Shaming sites that are hosting malware seems perfectly reasonable. On topic: I assume github/gitlab both completely misunderstood what is going on, and thought this was a disclosure of security holes that could be exploited. I wouldn't be surprised if they d…

Not many do and they're even less likely to be on the first page of google hits.

Re: GitHub censored my research data

#183
post #43

Earlier quoted context omitted.

> Compilations can be copyrighted. There's a long legal history on the topic. This is true, but totally irrelevant as it misses the point of the question.

Actually, you're wrong. The DMCA was used as a premise for takedown on the basis of purported copyright infringement. I was pointing out that such a claim, however spurious you may think it is, would likely hinge on the claimant's exclusive rights in the compilation. I can't see any other theory that would support a DMCA takedown. Again, it's irrelevant to the question whether or not you think the claim had merit. Al…

> I was pointing out that such a claim, however spurious you may think it is, would likely hinge on the claimant's exclusive rights in the compilation.

I don't think it is that simple. Yes, you may claim a copyright on whole compilation. But you could as well claim a copyright on some parts within that compilation. Since the compilation is a single document, claiming copyright on some part of it would also be sufficient for a takedown.

Re: GitHub censored my research data

#184
post #178

Earlier quoted context omitted.

And that's why no one is talking about forcing GitHub and Gitlab to do anything. They're merely complaining. Just because someone complains about something doesn't mean they think it is illegal or ought to be illegal.

Yes, but one by one the word "censorship" loses it's meaning. It used to mean preventing people from publishing their work. Now all it means is disagreeing about what should get shown prominently on social networks.

Anyone suppressing a work based on ethical judgments is practicing censorship. They could be acting on the authority of a state or religious institution, they could be removing immodest young adult fiction from the shelves at a children's library, or they could be moderating the content of a web site. Web sites are new, but the concept is the same as it's always been.

Re: GitHub censored my research data

#186
post #63

Earlier quoted context omitted.

This is completely unacceptable. You're treating this as though the author was publishing a list of vulnerabilities about sites. That's not what the author did. The author published a list of sites that are already infected with malware and thus are dangerous for users to visit. This is a public service and there is zero expectation of "responsible disclosure" to the sites. The only thing that disclosing to the sites…

Is it possible that gitlab's position is that the presence of malware is proof that the site is vulnerable, not that the malware is the vulnerability?

I addressed that in the second half of my comment.

Re: GitHub censored my research data

#187
Gitlab CEO just called me and apologized, will restore data shortly.

I am personally very sorry that GL got in a bad light here. They had misinterpreted my data and have acknowledged that. For comparison, I have heard nothing from GH over the last two days.

Gitlab, you rock.

Re: GitHub censored my research data

#188

Gitlab CEO just called me and apologized, will restore data shortly. I am personally very sorry that GL got in a bad light here. They had misinterpreted my data and have acknowledged that. For comparison, I have heard nothing from GH over the last two days. Gitlab, you rock.

They should be much more careful in how these types of reportings are done.

You were doing a public service of already-explited machines that are snarfing credit card numbers. And that is of great importance for anyone who buys stuff online (Like... all of us).

It also goes to show, that we need to further develop P2P type technologies like IPFS and similar stacks, to rid ourselves from monolithic companies dictatorial hands. Because what they find "unsuitable", you are no longer welcome. That's a problem, for all of us.

I had a similar problem with a VPS provider 2 weeks ago. I run IPFS on all my nodes, and comply with good netizen and compsec principles. They ToSsed me, because "my machine was scanning :4001 and they received a complaint". Bullshit. That is the chatter IPFS uses when maintaining the DHT. However, I was actually using a machine and what I paid for... and they didn't like it.

Fortunately, since all my data is via IPFS (and /ipfs and /ipns thanks to filesystem mounting), my data was already backed up and distributed. Filing a dispute with Paypal and purchasing another VPS provider was simple.

Re: GitHub censored my research data

#189

Gitlab CEO just called me and apologized, will restore data shortly. I am personally very sorry that GL got in a bad light here. They had misinterpreted my data and have acknowledged that. For comparison, I have heard nothing from GH over the last two days. Gitlab, you rock.

FWIW, if GitLab sees this: Well done. We were planning on buying their hosted service (GitHost) for my employer next week and after this story initially broke I was going to table that and use something else. This has restored our faith in GitLab as a company.

Re: GitHub censored my research data

#190
post #40

GL sent me this statement. For the record, I didn't publish vulnerable systems, I published stores that have malware. --- Willem, GitLab has opted to remove the list of servers that you posted in your snippet. GitLab views the exposure of the vulnerable systems as egregious and will not abide it. While GiLab reserves the right take further action, up to and including termination ( https://about.gitlab.com/terms/ ), w…

Sorry for our mistake Willem, we reinstated the snippet. Also see our blog post about this on https://about.gitlab.com/2016/10/15/gitlab-reinstates-list-o... TLDR; The owners of web stores have a responsibility to their users. And it is in the users interest to have the list published so owners. We currently think that the interest of the user weights heavier.
Post reply on HN