GitHub blocks entire company because one employee was in Iran
261–270 of 515 posts
Re: GitHub blocks entire company because one employee was in Iran
#262Earlier quoted context omitted.
Seems someone has responded to it. https://twitter.com/natfriedman/status/1346452935924846593
lol someone responded a week later and possibly only because it made the front page on hacker news
It does not condone that it took an HN frontpage to react to a massive issue from a client blocked due to either a badly configured sanctions system, or a badly defined false positive determination workflow, that could not be expedited otherwise by the client, but... it’s something I guess.
Good luck having a 7-day response by your bank, who have the legal obligation to not share with you why did they block you, or having Google’s CEO looking into your issue aired in twitter.
Re: GitHub blocks entire company because one employee was in Iran
#263Earlier quoted context omitted.
I would go quite a step further than that. If this was not an unfortunate incident/mistake, then GitHub/Microsoft has become quite the active enforcer of US (legal) foreign policy. If they do that within the US market, that might be justifiable. But in this particular case, GitHub appears to enforce US foreign policy on what appears to be a company on the EU market. Also in what to me appears to be a rather ruthless,…
Given the pressure by the EU and China on US companies to enforce local laws globally (GDPR, RTBF, Taiwan), I don't see how Github, operating in the US, as a US company, has any chance absolving itself of enforcing US laws and regulations (though in this specific case they appear to have overreacted, likely due to regulatory enforcement via algorithm and not common sense). If you expect US companies to respect GDPR a…
EU wants American companies to follow GDPR when acting in EU market.
Re: GitHub blocks entire company because one employee was in Iran
#264I really wonder why economical penalties enforced to a country through its citizens or people born there or with ancestors like the USA does with all of its embargos aren't considered just as terrorism. You are punishing other people for something they didn't do just to pressure on their governments. Just like terrorists injuring people. (Yeah I know terrorists usually kill people but I'm pretty sure many people died…
> You are punishing other people.. Just like terrorists injuring people. Because terrorism implies violence. What kind of deaths result from economic embargo?
Re: GitHub blocks entire company because one employee was in Iran
#265Earlier quoted context omitted.
I'm in Africa and most companies here host their systems either locally (very expensive and slow) or in America. The other day at work I had a pretty heated argument at work with a colleague when I mentioned it is really not good for us to host any of our stuff in America (all of it is currently in America). He basically freaked out about it. I just wanted to hear his thoughts about it, but he took personal offence (…
Money and skills are ALWAYS problems. Those are "cheap" and "fast" of the "cheap, fast, good, pick two".
Those are not problems, those are trade-offs. OP is right, you could be in a position in which those trade-offs dont apply to you (i.e. by buying a "expensive" but great solution, this happens all the time in all the industries) or you could sacrifice one item (say speed) in your solution if this is not a problem for your workflow ("so what if a open source tool runs 2x as slow as the best proprietary option, our daily batch processing take 2 hours and it is used in weekly buckets")
Re: GitHub blocks entire company because one employee was in Iran
#266Earlier quoted context omitted.
We can all cite harmful laws, does that mean companies (and people) should be free to ignore all law? Should US companies be free to ignore laws related to sanctions because the UAE has made being gay illegal or because political opposition in China could land you in jail? Where do you draw the line? Specifically - for a US company as is being discussed.
> companies (and people) should be free to ignore all law? Yet you continue with your strawmans. Nobody said that. The crucial word in your sentence is "all", with which nobody has agreed here. Of course nobody is above law. But sometimes, in exceptional circumstances, a particular law turns out to be immoral. In that case, and only in that case, it is wrong to follow that particular law, and it is right to do the il…
No, it was rhetorical question. Reading and making an effort to respond to the entirety of the comment would have made that obvious when I specially ask "Where do you draw the line?".
Re: GitHub blocks entire company because one employee was in Iran
#267So many dimensions come to play here. 1. There's the obvious legal aspect i.e. how these laws are framed and interpreted. 2. Then there's the geopolitical aspect. Is it fair to impose sanctions on Iran. 3. There's another aspect around GitHub policy that asks if an entire organization be banned for the location of one team member. 4. Finally, there's the aspect of relinquishing control. Your app development is on the…
>2. Then there's the geopolitical aspect. Is it fair to impose sanctions on Iran. Yeah. Nobody else should be allowed to have nukes, or else the U.S. is gonna take his ball and go home.
Making it difficult for the IAEA to provide oversight is enough of a treaty violation, and that goes double when there is credible evidence that unauthorized enrichment was occurring.
Re: GitHub blocks entire company because one employee was in Iran
#268Earlier quoted context omitted.
> 2FA should be bypassable after some longish lockout period. Nope. No backups, no sympathy, simple as that. 2FA is worthless if you start to put holes in it like that. So if you value your data, make backups - preferably locally the old-fashioned way, e.g. HDDs stored in at least two different locations or at least using several different cloud providers (which have their own infrastructure and aren't just relying o…
> Nope. No backups, no sympathy, simple as that. For your personal stuff, sure. But when engineering a service, you should care about everyones stuff, not just those who are careful. You should design your service to try to help those users who use the same password they did on myspace in 2004 and write it on a sticky note on their desk. Engineer for those who shared their password with their now-hated ex. Even if th…
And as the GP says, what role would 2fa play in that scenario?
Re: GitHub blocks entire company because one employee was in Iran
#269They could simply block network access from Iran to make it easier. Otherwise, blocking without giving warning is wrong. Even banks give warning and deadline to their clients before closing accounts that are linked to sanctions. Why Github blocked the entire organization without proper communication and deadline to fix or clarify the issue?
Re: GitHub blocks entire company because one employee was in Iran
#270Earlier quoted context omitted.
Companies routinely engage in activism. I’ve seen more than one software company cut off Trump campaign from their services, which was politically motivated. Now, US sanctions against Iran are clearly illegal. Yet, everyone is just fine with that, no activism whatsoever. I say people should revolt.
I find your use of "illegal" interesting. To me, it means "against a law", and laws are made by countries (sure, parliaments of those countries or dictators or...), and generally apply only to that particular country (some things attempt to get a wider reach, but they are usually unenforceable unless there's a local company to pursue, most famous example being GDPR). There are international conventions and the UN, bu…