Live data from Hacker News

GitHub blocks entire company because one employee was in Iran

twitter.com

221–230 of 515 posts

Re: GitHub blocks entire company because one employee was in Iran

#221
post #97

Earlier quoted context omitted.

Do you have Gmail account? Nothing beats free service.

Nothing? Really? Nothing? Nothing in the entire existence of the universe ever beats a free service? OK then...

It's a phrase, a commonly used one in English, obviously not nothing in the entire universe.

Re: GitHub blocks entire company because one employee was in Iran

#222
post #132

Earlier quoted context omitted.

2FA should be bypassable after some longish lockout period. For example, someone has lost their password, email access, phone number, and 2FA app. Make them wait a month to regain account access. If any time during that month, the account is used or logged into, cancel the takeover request. During the month, every day send an email to all points of contact on the account letting them know what will happen. It's a tra…

> 2FA should be bypassable after some longish lockout period. Nope. No backups, no sympathy, simple as that. 2FA is worthless if you start to put holes in it like that. So if you value your data, make backups - preferably locally the old-fashioned way, e.g. HDDs stored in at least two different locations or at least using several different cloud providers (which have their own infrastructure and aren't just relying o…

> Nope. No backups, no sympathy, simple as that.

For your personal stuff, sure. But when engineering a service, you should care about everyones stuff, not just those who are careful.

You should design your service to try to help those users who use the same password they did on myspace in 2004 and write it on a sticky note on their desk. Engineer for those who shared their password with their now-hated ex.

Even if the user takes massive security risks, the service should still try to maximize the users ability to use the service, while minimizing an attackers use/access to the service.

Re: GitHub blocks entire company because one employee was in Iran

#223

Entrusting your business to an american entity is the stupidest idea you could have thought about. Especially us europeans should not rely on American services at all.It's not worth it. American corporations are just as much a liability as their counterparts in China.

The top 33 "software and programming" companies by revenue in the world can be found below [0]. 28 of them are American. Two are in the EU. One is in the UK. One is in Australia. The last is Russian. One of the companies in the EU produces enterprise software almost no one on this website uses (SAP). The other is Dassault. In the US the top five companies are Microsoft, Oracle, ADP, Adobe, and Salesforce. If you incl…

I think you are conflating marked share with quality of offering.

Indeed there are viable local options for many of these things. Heck, the reason why European companies have so little relative marked share, is because they serve smaller, domestic, markets.

A Danish webshop provider probably has a better offering for a webshop for servicing the Danish market. It probably has better support for Danish accounting, better locale support etc.

Re: GitHub blocks entire company because one employee was in Iran

#225
post #154

Earlier quoted context omitted.

I doubt it.

There's definitely an argument that GitHub is one of the primary reasons that Git beat Mercurial.

Anecdotally, I started using git because of projects on Github I wanted to contribute to. A number of others I know where in a similar boat. Before that, we used subversion, bazaar or mercurial. I personally am happy with having been pushed to using git and if it was winning anyway (not clear) I'm sure I would have eventually ended there anyway, but GitHub is the reason I started using it when I did.

Re: GitHub blocks entire company because one employee was in Iran

#226

Please please PLEASE add at least one other provider to your remotes if you're going all in on cloud. Consider also doing a regular local backup of all your repos. A quick Google search will yield you tools that will automate this entire process on platforms such as GitHub , BitBucket and GitLab. I personally delegated this to a Cron job. I check the backups manually once a month to check all is in order.

While this is good advice of course, it is not clear to me if the problem is just the source code. The twitter message says "We are completely blocked from deploying!." Maybe they already have the source code elsewhere but use GitHub actions?

Heroku, maybe?

Re: GitHub blocks entire company because one employee was in Iran

#227

So many dimensions come to play here. 1. There's the obvious legal aspect i.e. how these laws are framed and interpreted. 2. Then there's the geopolitical aspect. Is it fair to impose sanctions on Iran. 3. There's another aspect around GitHub policy that asks if an entire organization be banned for the location of one team member. 4. Finally, there's the aspect of relinquishing control. Your app development is on the…

> Ironically, Git is a decentralized version control system. GitHub is simultaneously not the be-all-and-end-all of Git[1] and more than Git[2]. If they have good backups of everything (if not they should consider this a beating with the ol' clue stick (I'm assuming everything on github can be backed up away from it?)) this should only be a bump in the road, though a considerably inconvenient bump as there is nothing…

> pick a new location for the "source of truth" repo for your team, push everything to that, and you're golden again

Its also pretty easy to mirror your repo to other remotes. I've had projects that were in Gitlab, Github and Sourcehut at the same time. Sure, depending on how you sync them, there may be some steps (eg getting people to push their local branches to another remote) when your main one becomes inaccessible, but overall its really easy to work across multiple remotes. Its something git was designed for, after all.

Re: GitHub blocks entire company because one employee was in Iran

#228

So many dimensions come to play here. 1. There's the obvious legal aspect i.e. how these laws are framed and interpreted. 2. Then there's the geopolitical aspect. Is it fair to impose sanctions on Iran. 3. There's another aspect around GitHub policy that asks if an entire organization be banned for the location of one team member. 4. Finally, there's the aspect of relinquishing control. Your app development is on the…

>2. Then there's the geopolitical aspect. Is it fair to impose sanctions on Iran.

Yeah. Nobody else should be allowed to have nukes, or else the U.S. is gonna take his ball and go home.

Re: GitHub blocks entire company because one employee was in Iran

#229

I'm an iranian-american and this saddens me deeply. When you travel to Iran you need to make sure you don't get arrested by iranian regime because they have a history of taking dual nationals as hostage. Then you open your laptop and suddenly you have taken down your company and potentially lost your job.

> When you travel to Iran you need to make sure you don't get arrested by iranian regime because they have a history of taking dual nationals as hostage.

Isn't it trivial for them to catch you at the border if they wanted to do it?

Re: GitHub blocks entire company because one employee was in Iran

#230

Earlier quoted context omitted.

> It's common sense that most people are from the same country their parents are from, given what we know about immigration. The legal concept you're referring to is called "ius soli". The legal concept which serves as a basis to determine someone's allegiance by their ancestry is called "ius sanguinis". [1][2] [1] https://en.wikipedia.org/wiki/Jus_soli [2] https://en.wikipedia.org/wiki/Jus_sanguinis So, no, it's not…

Those two rights deal with determining citizenship at birth. The common sense idea deals with the probability of someone (already born) being of a certain citizenship given their parents' location. Different ideas. > The legal concept which serves as a basis to determine someone's allegiance by their ancestry is called "ius sanguinis" Not allegiance, citizenship. Different, but similar concept again.

> Those two rights deal with determining citizenship at birth.

Citizenship is always first determined at birth. This isn't relevant to the discussion.

> The common sense idea deals with the probability of someone (already born) being of a certain citizenship given their parents' location.

That would be "ius soli". As opposed to "ius sanguinis".

It's also not a "probability". These are principles which are formally enshrined in nationality laws and very much determine travel, migration and national security policies in different nations. Including the United States.

These are not "common sense" either.

These are laws which come with a long historical pedigree which includes identity politics, economic policies, moral and ideological values, and so on.

They are also very much subject to change through the dominant politics of the day.

> Not allegiance, citizenship. Different, but similar concept again.

I'm not willing to engage in a semantic discussion.

Post reply on HN