Live data from Hacker News

GitHub censored my research data

gwillem.gitlab.io

171–180 of 206 posts

Re: GitHub censored my research data

#172
post #39

We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service ( https://about.gitlab.com/terms/ ). The author says that he contacted "about 30 merchants directly", but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely…

So when GitLab finally bothers to respond they do so from a new account? Any proof this comes from GitLab? Which terms specifically does it violate? The terms page you linked to is 10k words long. As others have mentioned, this is not about responsible disclosure. If those merchants have the good of their customers to heart, they will act to cleanup their sites and disclose the breach themselves. If not they will mov…

> So when GitLab finally bothers to respond they do so from a new account?

That does seem quite odd.

Re: GitHub censored my research data

#173
post #96
post #67

Earlier quoted context omitted.

A 'normal consumer' won't be helped by such a technical list on github/gitlab. Do you really believe they would look there? If they wanted protection they could have installed Ad-blockers etc. long time ago already. (Or use more reputable shops)

Lots of people google the name of a webshop to check if it's legit. Not all, but some non-tech people do that.. And lots of webshop owners google their own shop. Shaming sites that are hosting malware seems perfectly reasonable. On topic: I assume github/gitlab both completely misunderstood what is going on, and thought this was a disclosure of security holes that could be exploited. I wouldn't be surprised if they d…

How long is the author going to check and update that list of compromised websites? Right now they are broken but in 6 months when the site gets upgraded it will be a knock against them unless the author updates the list. This is the real problem.

Re: GitHub censored my research data

#174
post #61
post #60

Do this kind of thing on your own domain. I have a list of major sites with currently active phishing pages.[1] This is basically a join of PhishTank and DMOZ. Nobody seems to be upset by that. Google is at the top of the list because of their hosting business. It's not just Google Sites. You can put a web site in a Google Spreadsheet cell, which Google doesn't seem to check as a possible phishing site. If you host f…

Okay, so assume he hosted the list himself and is now DDoS'd. Now what? I'll give you a budget of $100 a year.

Well, if it's true journalism, you sign up for project shield for free and laugh at the kiddiots banging their collective heads against the immovable mountain that is Google.

https://projectshield.withgoogle.com/public/

Re: GitHub censored my research data

#175
There is a service http://www.cryptograffiti.info/ which can be used for posting sensitive information that should not be removed or hidden. It allows to write a message and store it in Bitcoin blockchain as a transaction. It costs near 0.0015 BTC or $1 per kB. Large files can be posted as magnet links to torrents with them.

Even if the service's site had been shut down, everyone would always be able to obtain the transaction from it's hash using any bitcoin client/blockchain explorer, convert it to ASCII and read the text.

I'd like to note that it is worth to sign with GPG all messages posted that way in order to have ability to post updates and verify authorship.

Re: GitHub censored my research data

#177
post #157
post #39

We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service ( https://about.gitlab.com/terms/ ). The author says that he contacted "about 30 merchants directly", but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely…

This censorship show that you don't even begin to understand the problem. This list could prevent people from getting their card skimmed, and you take it down . I'm moving away from gitlab.

To where?

I have to confess, when GH did something offensive I did cancel my paid account there but I still use it, so I guess I didn't care that strongly about it after all...

Re: GitHub censored my research data

#178

Earlier quoted context omitted.

And even if it were (a list of vulnerable systems, that is), why the fuck do they think that they should censor serious journalism? If you operate a public venue, then it is an important societal role of journalism to report on it if that public venue poses a risk to the public, whether that might also have negative consequences for the people operating it is completely irrelevant.

There is a right of free speech in many countries (I assume you are in one of them), but that right does not force anyone else to distribute or publish your speech. Their servers, and their decision on what data is on them. Want to make it available for every to read? Run your own server and host it there. tl;dr - you have the right to say what you want, but you cant force anyone to listen.

And that's why no one is talking about forcing GitHub and Gitlab to do anything. They're merely complaining. Just because someone complains about something doesn't mean they think it is illegal or ought to be illegal.

Re: GitHub censored my research data

#179
post #40

GL sent me this statement. For the record, I didn't publish vulnerable systems, I published stores that have malware. --- Willem, GitLab has opted to remove the list of servers that you posted in your snippet. GitLab views the exposure of the vulnerable systems as egregious and will not abide it. While GiLab reserves the right take further action, up to and including termination ( https://about.gitlab.com/terms/ ), w…

>For the record, I didn't publish vulnerable systems, I published stores that have malware.

This is a crucial point, because it shows GitLab is basically nonresponsive to the key issue; it's the difference between "Here's how to hack Giant Anchor Retailer" (unethical, possibly illegal) and "Giant Anchor Retailer has been hacked, estimated NNN cards may have been compromised" (of public interest, not illegal). In my case, I want to know if I used any of the retailers on the list!

For GitLab to call this "egregious" and that they "will not abide it" suggests that either GitLab is technically incompetent in security matters, or that they've received legal notices and decided that the shortest path to resolution is to throw their users under the nearest publicly-operated multiwheeled passenger conveyance. In either case, poor show, good reason to seriously consider moving off GH and GL.

Re: GitHub censored my research data

#180
post #178

Earlier quoted context omitted.

There is a right of free speech in many countries (I assume you are in one of them), but that right does not force anyone else to distribute or publish your speech. Their servers, and their decision on what data is on them. Want to make it available for every to read? Run your own server and host it there. tl;dr - you have the right to say what you want, but you cant force anyone to listen.

And that's why no one is talking about forcing GitHub and Gitlab to do anything. They're merely complaining. Just because someone complains about something doesn't mean they think it is illegal or ought to be illegal.

Yes, but one by one the word "censorship" loses it's meaning. It used to mean preventing people from publishing their work. Now all it means is disagreeing about what should get shown prominently on social networks.
Post reply on HN