Earlier quoted context omitted.
> Ironically, Git is a decentralized version control system. And Git is open source. Github is a US-registered company under MS. The US has a history of weaponizing its economic power. Stallman (RMS) was right once again.
This particular case was overreach by Github and not the US Lawmakers. https://home.treasury.gov/policy-issues/financial-sanctions/... 118. I have a client that is in Iran to visit a relative. Do I need to restrict the account? A: No. As long as you are satisfied that the client is not ordinarily resident in Iran, then the account does not need to be restricted. See FAQ 37. Source: https://twitter.com/Hamed/status/13…
GitHub blocks entire company because one employee was in Iran
201–210 of 515 posts
Re: GitHub blocks entire company because one employee was in Iran
#202Earlier quoted context omitted.
The US embargo prevents doing business with Iran. Providing service in Iran would be a violation of the embargo. Blocking a whole European company not conducting business with Iran because one of its employee tried to login while there is not respecting the embargo, it's just overreach. GitHub should get flak for that in the same way Paypal regularly get flak for randomly freezing accounts.
> GitHub should get flak for that in the same way Paypal regularly get flak for randomly freezing accounts. Random? I think the problem with Paypal was that they do not warn or provide reasons for freezing. GH's reasons are clear. > Blocking a whole European company not conducting business with Iran because one of its employee tried to login while there is not respecting the embargo, it's just overreach. Says who? Th…
The same law you're stating.
https://home.treasury.gov/policy-issues/financial-sanctions/...
Re: GitHub blocks entire company because one employee was in Iran
#203Earlier quoted context omitted.
> Ironically, Git is a decentralized version control system. And Git is open source. Github is a US-registered company under MS. The US has a history of weaponizing its economic power. Stallman (RMS) was right once again.
I would go quite a step further than that. If this was not an unfortunate incident/mistake, then GitHub/Microsoft has become quite the active enforcer of US (legal) foreign policy. If they do that within the US market, that might be justifiable. But in this particular case, GitHub appears to enforce US foreign policy on what appears to be a company on the EU market. Also in what to me appears to be a rather ruthless,…
Isn’t that what YouTube and FaceBook do day in day out when their influencers run afoul of policy?
Re: GitHub blocks entire company because one employee was in Iran
#204So many dimensions come to play here. 1. There's the obvious legal aspect i.e. how these laws are framed and interpreted. 2. Then there's the geopolitical aspect. Is it fair to impose sanctions on Iran. 3. There's another aspect around GitHub policy that asks if an entire organization be banned for the location of one team member. 4. Finally, there's the aspect of relinquishing control. Your app development is on the…
> Ironically, Git is a decentralized version control system. And Git is open source. Github is a US-registered company under MS. The US has a history of weaponizing its economic power. Stallman (RMS) was right once again.
Re: GitHub blocks entire company because one employee was in Iran
#205I'm on GitHub/Microsoft's side here. They are not responsible for the content of US export control laws, and they have an incredible amount to lose if they are found to be in violation of US export control laws. Presumably GitHub needs some automated tool to prevent inbound traffic from sanctioned countries, and it's hard to be certain that they are complying with US law if such automated tools have some wiggle room…
Companies routinely engage in activism. I’ve seen more than one software company cut off Trump campaign from their services, which was politically motivated. Now, US sanctions against Iran are clearly illegal. Yet, everyone is just fine with that, no activism whatsoever. I say people should revolt.
To me, it means "against a law", and laws are made by countries (sure, parliaments of those countries or dictators or...), and generally apply only to that particular country (some things attempt to get a wider reach, but they are usually unenforceable unless there's a local company to pursue, most famous example being GDPR).
There are international conventions and the UN, but countries do not have to be signatories or members to any of them. And I've never heard anyone use the term "illegal" in that sense before.
So what do you mean with "clearly illegal"?
(fwiw, I am very much against the US acting as the "policeman of the world", but sanctions are a political tool to make someone less powerful comply; beats an invasion and bombing that USA has frequently resorted to)
Re: GitHub blocks entire company because one employee was in Iran
#206Github refused to help me regain access to an 11 year old account when I changed jobs so lost access to 2FA and email account at the same time. We lost access to tens of thousands of dollars worth of project code which we had to rewrite. The customer service support was Google style brick wall. I wish this guy luck in getting access.
Using a company email to sign up for services and expecting to have access after you leave the company is 100% entirely your fault. Even with the positive spin you're trying to put on it, it still sounds like you are trying to steal data from your former employer. The situation would probably also be easily resolvable with your former employer's help, and there is likely a reason they aren't helping you.
I’ve had really positive experiences with GitHub support, but you can’t ask them impossible things.
There’s a GitHub user with my org name, they’ve had it for a long time and aren’t active. I asked GitHub support to see if they were active and if they’d be willing to transfer the account. GitHub confirmed they were active but just with no public activity and they passed along the request.
I like that they were human and didn’t try to force the user to give up their account.
I’ve had multiple colleagues say that we should try to force the user and I don’t support that line of reasoning. The user has a legitimate use of the name.I like that GitHub took the high road,
Re: GitHub blocks entire company because one employee was in Iran
#207Entrusting your business to an american entity is the stupidest idea you could have thought about. Especially us europeans should not rely on American services at all.It's not worth it. American corporations are just as much a liability as their counterparts in China.
>Especially us europeans should not rely on American services at all.It's not worth it. Sure, please let me know how the EU plans to build Office 365, AWS, GitHub competitors of similar scale, quality and success. We have no private investors that would pony up enough money to go against US tech titans and fat chance the EU would ever fund such initiatives and if they would, the money would evaporate over night to co…
However, if you cannot trust those products then you cannot use them.
Remember, this thread is about Github blocking an entire company due to one employee due to American politics. If a non-US company risks to lose it project management/code management (Github), its infrastructure (AWS) or its documents (Office 365) on a whim due to American policies then they cannot use those products.
If a big enough chunk of the world can't use the American offerings, then there is a market for alternatives.
Re: GitHub blocks entire company because one employee was in Iran
#208"twitter blocks entire company because one employee is conservative"
Who cares?
Re: GitHub blocks entire company because one employee was in Iran
#209Earlier quoted context omitted.
2FA should be bypassable after some longish lockout period. For example, someone has lost their password, email access, phone number, and 2FA app. Make them wait a month to regain account access. If any time during that month, the account is used or logged into, cancel the takeover request. During the month, every day send an email to all points of contact on the account letting them know what will happen. It's a tra…
> 2FA should be bypassable after some longish lockout period. Nope. No backups, no sympathy, simple as that. 2FA is worthless if you start to put holes in it like that. So if you value your data, make backups - preferably locally the old-fashioned way, e.g. HDDs stored in at least two different locations or at least using several different cloud providers (which have their own infrastructure and aren't just relying o…
There are always trade-offs. No security is absolute, but that doesn't mean all security is worthless. And as a rule all security measures come with some associated cost/inconvenience. What trade-offs make sense will depend on many factors, such as the value of your data (both to you and to a potential attacker), the threat models you're concerned about, the people who need access to your "secure" data, etc.
Re: GitHub blocks entire company because one employee was in Iran
#210So many dimensions come to play here. 1. There's the obvious legal aspect i.e. how these laws are framed and interpreted. 2. Then there's the geopolitical aspect. Is it fair to impose sanctions on Iran. 3. There's another aspect around GitHub policy that asks if an entire organization be banned for the location of one team member. 4. Finally, there's the aspect of relinquishing control. Your app development is on the…
So there are Cloud services that make more sense to use in the long run, in this case Gitlab is one of them.