Live data from Hacker News

GitHub censored my research data

gwillem.gitlab.io

161–170 of 206 posts

Re: GitHub censored my research data

#161

And just like that, we discover how helpless the average Joe is against corporate money. Let's crowdfund an AWS s3+CloudFront hosted site. DDosing that is no easy feat, and if corps do try it, the logs can prove their complicity, which has legal implications I presume

It's an endless cycle. The Man keeps you down, so you throw together resources and collaborate to have a crowdfunded solution. It becomes successful, grows, hires some employees to maintain things, keeps growing, and becomes The Man.

Re: GitHub censored my research data

#162
post #61
post #60

Do this kind of thing on your own domain. I have a list of major sites with currently active phishing pages.[1] This is basically a join of PhishTank and DMOZ. Nobody seems to be upset by that. Google is at the top of the list because of their hosting business. It's not just Google Sites. You can put a web site in a Google Spreadsheet cell, which Google doesn't seem to check as a possible phishing site. If you host f…

Okay, so assume he hosted the list himself and is now DDoS'd. Now what? I'll give you a budget of $100 a year.

I wonder how big of a DDoS you can withstand (and remain operational) with Cloudflare Free/Pro.

Re: GitHub censored my research data

#163
post #19

Earlier quoted context omitted.

And get DDoSed by the malware guys who don't want their victims know they are in the list and fix their site. It would be an altruistic offer but I would think twice about it. However it's a problem and we need a solution. A torrent? Yes but Google won't index it. A file on S3 wouldn't work because they could just download it as many times as needed to make the bill skyrocket. Better than a DCMA. Anything that is una…

IPFS?

Not quite. IPNS.

IPFS links are immutable, whereas IPNS links are a mutable pointer to an IPFS hash. They can be updated at will, making them ideal for changing content with a stable hash.

Re: GitHub censored my research data

#164
post #102

Earlier quoted context omitted.

The real reason is almost certainly something along the lines of 'it's possible we could get sued for libel' or 'we have been threatened with a libel suit'. Not that such a case would ever go anywhere, but I imagine they figure that it's more trouble than it's worth.

They have safe harbor protection.

But maybe not any more - since they're now shown to be acting in an editorial capacity...

Re: GitHub censored my research data

#165
post #63
post #39

We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service ( https://about.gitlab.com/terms/ ). The author says that he contacted "about 30 merchants directly", but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely…

This is completely unacceptable. You're treating this as though the author was publishing a list of vulnerabilities about sites. That's not what the author did. The author published a list of sites that are already infected with malware and thus are dangerous for users to visit. This is a public service and there is zero expectation of "responsible disclosure" to the sites. The only thing that disclosing to the sites…

Is it possible that gitlab's position is that the presence of malware is proof that the site is vulnerable, not that the malware is the vulnerability?

Re: GitHub censored my research data

#166

Earlier quoted context omitted.

it falls under the DMCA because the DMCA mandates a takedown-first and check the validity later workflow. To be in compliance, a site must respond to any DMCA takedown notice as quickly as reasonably possible, regardless of how fraudulent it might be. As long as you're okay being found guilty of perjury by a US court, or have no plans to enter a US jurisdiction in the near future, you can get any content you want tak…

DMCA is a copyright law. It requires a takedown for alleged copyright violation. That doesn't apply here. The stores don't have copyright over their domain names on a list.

Yes. So to get something taken down, all you have to do is allege copyright violation. If you're not concerned about perjury in the US courts, the claim doesn't have to have merit.

Service providers have a choice:

a) follow the DMCA takedown process and be shielded from all liability, whether or not the claim has actual merit

b) evaluate each takedown notice to decide if the material falls within the scope of copyright, ignore takedowns where in the service provider's opinion the material is outside the scope of copyright, and should it go to court, be forced to defend that position on its merits instead of having an automatic liability shield

What sensible service provider is going to choose option b?

Re: GitHub censored my research data

#167
post #40

GL sent me this statement. For the record, I didn't publish vulnerable systems, I published stores that have malware. --- Willem, GitLab has opted to remove the list of servers that you posted in your snippet. GitLab views the exposure of the vulnerable systems as egregious and will not abide it. While GiLab reserves the right take further action, up to and including termination ( https://about.gitlab.com/terms/ ), w…

And even if it were (a list of vulnerable systems, that is), why the fuck do they think that they should censor serious journalism? If you operate a public venue, then it is an important societal role of journalism to report on it if that public venue poses a risk to the public, whether that might also have negative consequences for the people operating it is completely irrelevant.

There is a right of free speech in many countries (I assume you are in one of them), but that right does not force anyone else to distribute or publish your speech.

Their servers, and their decision on what data is on them.

Want to make it available for every to read? Run your own server and host it there.

tl;dr - you have the right to say what you want, but you cant force anyone to listen.

Re: GitHub censored my research data

#170
post #43

Earlier quoted context omitted.

> Compilations can be copyrighted. There's a long legal history on the topic. This is true, but totally irrelevant as it misses the point of the question.

Actually, you're wrong. The DMCA was used as a premise for takedown on the basis of purported copyright infringement. I was pointing out that such a claim, however spurious you may think it is, would likely hinge on the claimant's exclusive rights in the compilation. I can't see any other theory that would support a DMCA takedown. Again, it's irrelevant to the question whether or not you think the claim had merit. Al…

That's all well and good if this case ever goes to court, which it almost certainly won't. Most service providers will pull down any content that's included in a takedown notice. The alternative is for each service provider to make a legal decision about each takedown notice. That won't happen. If they don't respond in good time, they risk their safe harbor status.

It's smarter (under the seriously f'ed up DCMA system) to pull it down and wait for a counter notice, at which point they put it back up, and they aren't responsible any more — the person filing the counter notice is responsible because a false counter claim counts as perjury.

At that point, the original issuer of the takedown notice can sue.

Of course, it almost never gets that far when the takedown notices are spurious, as in this case. That's what makes the DMCA such a bad idea — it's a perfect tool for censorship.

Post reply on HN