And just like that, we discover how helpless the average Joe is against corporate money. Let's crowdfund an AWS s3+CloudFront hosted site. DDosing that is no easy feat, and if corps do try it, the logs can prove their complicity, which has legal implications I presume
GitHub censored my research data
161–170 of 206 posts
Re: GitHub censored my research data
#162Do this kind of thing on your own domain. I have a list of major sites with currently active phishing pages.[1] This is basically a join of PhishTank and DMOZ. Nobody seems to be upset by that. Google is at the top of the list because of their hosting business. It's not just Google Sites. You can put a web site in a Google Spreadsheet cell, which Google doesn't seem to check as a possible phishing site. If you host f…
Okay, so assume he hosted the list himself and is now DDoS'd. Now what? I'll give you a budget of $100 a year.
Re: GitHub censored my research data
#163Earlier quoted context omitted.
And get DDoSed by the malware guys who don't want their victims know they are in the list and fix their site. It would be an altruistic offer but I would think twice about it. However it's a problem and we need a solution. A torrent? Yes but Google won't index it. A file on S3 wouldn't work because they could just download it as many times as needed to make the bill skyrocket. Better than a DCMA. Anything that is una…
IPFS?
IPFS links are immutable, whereas IPNS links are a mutable pointer to an IPFS hash. They can be updated at will, making them ideal for changing content with a stable hash.
Re: GitHub censored my research data
#164Earlier quoted context omitted.
The real reason is almost certainly something along the lines of 'it's possible we could get sued for libel' or 'we have been threatened with a libel suit'. Not that such a case would ever go anywhere, but I imagine they figure that it's more trouble than it's worth.
They have safe harbor protection.
Re: GitHub censored my research data
#165We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service ( https://about.gitlab.com/terms/ ). The author says that he contacted "about 30 merchants directly", but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely…
This is completely unacceptable. You're treating this as though the author was publishing a list of vulnerabilities about sites. That's not what the author did. The author published a list of sites that are already infected with malware and thus are dangerous for users to visit. This is a public service and there is zero expectation of "responsible disclosure" to the sites. The only thing that disclosing to the sites…
Re: GitHub censored my research data
#166Earlier quoted context omitted.
it falls under the DMCA because the DMCA mandates a takedown-first and check the validity later workflow. To be in compliance, a site must respond to any DMCA takedown notice as quickly as reasonably possible, regardless of how fraudulent it might be. As long as you're okay being found guilty of perjury by a US court, or have no plans to enter a US jurisdiction in the near future, you can get any content you want tak…
DMCA is a copyright law. It requires a takedown for alleged copyright violation. That doesn't apply here. The stores don't have copyright over their domain names on a list.
Service providers have a choice:
a) follow the DMCA takedown process and be shielded from all liability, whether or not the claim has actual merit
b) evaluate each takedown notice to decide if the material falls within the scope of copyright, ignore takedowns where in the service provider's opinion the material is outside the scope of copyright, and should it go to court, be forced to defend that position on its merits instead of having an automatic liability shield
What sensible service provider is going to choose option b?
Re: GitHub censored my research data
#167GL sent me this statement. For the record, I didn't publish vulnerable systems, I published stores that have malware. --- Willem, GitLab has opted to remove the list of servers that you posted in your snippet. GitLab views the exposure of the vulnerable systems as egregious and will not abide it. While GiLab reserves the right take further action, up to and including termination ( https://about.gitlab.com/terms/ ), w…
And even if it were (a list of vulnerable systems, that is), why the fuck do they think that they should censor serious journalism? If you operate a public venue, then it is an important societal role of journalism to report on it if that public venue poses a risk to the public, whether that might also have negative consequences for the people operating it is completely irrelevant.
Their servers, and their decision on what data is on them.
Want to make it available for every to read? Run your own server and host it there.
tl;dr - you have the right to say what you want, but you cant force anyone to listen.
Re: GitHub censored my research data
#168Re: GitHub censored my research data
#169Re: GitHub censored my research data
#170Earlier quoted context omitted.
> Compilations can be copyrighted. There's a long legal history on the topic. This is true, but totally irrelevant as it misses the point of the question.
Actually, you're wrong. The DMCA was used as a premise for takedown on the basis of purported copyright infringement. I was pointing out that such a claim, however spurious you may think it is, would likely hinge on the claimant's exclusive rights in the compilation. I can't see any other theory that would support a DMCA takedown. Again, it's irrelevant to the question whether or not you think the claim had merit. Al…
It's smarter (under the seriously f'ed up DCMA system) to pull it down and wait for a counter notice, at which point they put it back up, and they aren't responsible any more — the person filing the counter notice is responsible because a false counter claim counts as perjury.
At that point, the original issuer of the takedown notice can sue.
Of course, it almost never gets that far when the takedown notices are spurious, as in this case. That's what makes the DMCA such a bad idea — it's a perfect tool for censorship.