Live data from Hacker News

GitHub blocks entire company because one employee was in Iran

twitter.com

281–290 of 515 posts

Re: GitHub blocks entire company because one employee was in Iran

#281
post #112
post #96

Earlier quoted context omitted.

The US embargo prevents doing business with Iran. Providing service in Iran would be a violation of the embargo. Blocking a whole European company not conducting business with Iran because one of its employee tried to login while there is not respecting the embargo, it's just overreach. GitHub should get flak for that in the same way Paypal regularly get flak for randomly freezing accounts.

> GitHub should get flak for that in the same way Paypal regularly get flak for randomly freezing accounts. Random? I think the problem with Paypal was that they do not warn or provide reasons for freezing. GH's reasons are clear. > Blocking a whole European company not conducting business with Iran because one of its employee tried to login while there is not respecting the embargo, it's just overreach. Says who? Th…

> I think the problem with Paypal was that they do not warn or provide reasons for freezing

Which is par for the course for financial companies.

Re: GitHub blocks entire company because one employee was in Iran

#282
post #243

Earlier quoted context omitted.

I would go quite a step further than that. If this was not an unfortunate incident/mistake, then GitHub/Microsoft has become quite the active enforcer of US (legal) foreign policy. If they do that within the US market, that might be justifiable. But in this particular case, GitHub appears to enforce US foreign policy on what appears to be a company on the EU market. Also in what to me appears to be a rather ruthless,…

Given the pressure by the EU and China on US companies to enforce local laws globally (GDPR, RTBF, Taiwan), I don't see how Github, operating in the US, as a US company, has any chance absolving itself of enforcing US laws and regulations (though in this specific case they appear to have overreacted, likely due to regulatory enforcement via algorithm and not common sense). If you expect US companies to respect GDPR a…

I think you may have either misunderstood me, or maybe have gotten the logic backwards.

I'm not saying that US companies should not enforce US law. I think they should. That is: strictly within the US market.

When they operate outside the US market, they have to (also) adhere to whatever law exists for that market. If that creates a conflict, the company has a choice to either open up show elsewhere, outside of US jurisdiction (if that's the only way to comply with local market rules), or stay in the US and leave the foreign market alone.

Either way, being a US company should never be a valid excuse to violate laws (and/or legal protections) somewhere abroad.

It ultimately is up to a company to choose what they do and where they do it. To me, the current status quo appears to be that many US companies have been (illegally) enforcing US laws outside of US jurisdiction. Aside from that, and maybe even on a far worse level, they have been essentially been making up de facto "private laws", in their TOP/EULA "contracts".

Last time I checked, law should be left to governments. Preferable through democratic due process. Certainly not to commercial companies, who are either privately owned, or publicly by a select few rather undemocratic entities.

Re: GitHub blocks entire company because one employee was in Iran

#283

I had similar issue visiting Crimea. I was simply looking through my issues, while in holidays over there.

How can one even reliably detect if one is loging in from crimea? There is no Ukranian/Russian ISP operating exclusively in crimea, is there?

Re: GitHub blocks entire company because one employee was in Iran

#284
post #203

Earlier quoted context omitted.

I would go quite a step further than that. If this was not an unfortunate incident/mistake, then GitHub/Microsoft has become quite the active enforcer of US (legal) foreign policy. If they do that within the US market, that might be justifiable. But in this particular case, GitHub appears to enforce US foreign policy on what appears to be a company on the EU market. Also in what to me appears to be a rather ruthless,…

...” , this action is arbitrarily discriminatory, and very likely constitutes inflicting serious damage on another company without a legal basis...” Isn’t that what YouTube and FaceBook do day in day out when their influencers run afoul of policy?

Those other companies certainly do too, yes. Or at least that is what I am convinced of. I would say that what I wrote about GitHub should equally apply to these companies too, or any company for that matter. Not just US companies, but any company that operates internationally.

Re: GitHub blocks entire company because one employee was in Iran

#285
post #280

To be fair Nat Friedman replied: > Hi Sebastian, sorry to hear about this. I will check into it right away and get your org unblocked. https://twitter.com/natfriedman/status/1346452935924846593?s... Pretty messed up that they built this kill switch in the first place though, if you ask me.

This behavior shouldn't be praised. Having to go on twitter, get on the front page of HN, and make Github look bad seems like the only way to get help these days.

Re: GitHub blocks entire company because one employee was in Iran

#286

Earlier quoted context omitted.

The top 33 "software and programming" companies by revenue in the world can be found below [0]. 28 of them are American. Two are in the EU. One is in the UK. One is in Australia. The last is Russian. One of the companies in the EU produces enterprise software almost no one on this website uses (SAP). The other is Dassault. In the US the top five companies are Microsoft, Oracle, ADP, Adobe, and Salesforce. If you incl…

While the US sure is dominant, there are dozens of software companies larger than those in that list, e.g. Zoho has about $5B revenue, Baidu $11B, Tencent $23B, Accenture $41B, ... The list employs some particular filters (e.g. SaaS seems to be excluded) and heavily emphasizes market cap over revenue.

I wouldn't consider Accenture a large software company. They do a lot of software "consultancy" (ie bodyshopping), but the nature of the consulting game plus their decentralized architecture (I've worked with Accenture, and the relationship between their different offices seems to be closer to co-franchisees than colleagues) means I wouldn't consider it a "big software company" (as in lots of people working on the same system/architecture

Re: GitHub blocks entire company because one employee was in Iran

#287
post #153

Earlier quoted context omitted.

This particular case was overreach by Github and not the US Lawmakers. https://home.treasury.gov/policy-issues/financial-sanctions/... 118. I have a client that is in Iran to visit a relative. Do I need to restrict the account? A: No. As long as you are satisfied that the client is not ordinarily resident in Iran, then the account does not need to be restricted. See FAQ 37. Source: https://twitter.com/Hamed/status/13…

It may be overreach by GitHub, but given the severity of the sanctions lawmakers have set for if they happen to get it wrong, I'd like to at least blame lawmakers for creating such a risky situation.

I work with sanctions. I think both can be easily blamed. Similarly to DMCA notices, most companies opt to for the path of least resistance ( it is cheaper to blanket ban than to investigate ). Yes, politicians are to blame for creating the environment, but companies deserve flak for taking the path that is bad for the customer ( unless they are sufficiently well-heeled ).

My thoughts are my own. I do not represent anyone other than myself.

Re: GitHub blocks entire company because one employee was in Iran

#288

Earlier quoted context omitted.

I would go quite a step further than that. If this was not an unfortunate incident/mistake, then GitHub/Microsoft has become quite the active enforcer of US (legal) foreign policy. If they do that within the US market, that might be justifiable. But in this particular case, GitHub appears to enforce US foreign policy on what appears to be a company on the EU market. Also in what to me appears to be a rather ruthless,…

> But in this particular case, GitHub appears to enforce US foreign policy on what appears to be a company on the EU market. Surely enforcing your politics outside of your jurisdiction is the whole point of an embargo?

As a government, yes. As a commercial company, operating on a market outside of US jurisdiction, please explain me the legal basis for that (if you can).

Re: GitHub blocks entire company because one employee was in Iran

#289
post #280

To be fair Nat Friedman replied: > Hi Sebastian, sorry to hear about this. I will check into it right away and get your org unblocked. https://twitter.com/natfriedman/status/1346452935924846593?s... Pretty messed up that they built this kill switch in the first place though, if you ask me.

This behavior shouldn't be praised. Having to go on twitter, get on the front page of HN, and make Github look bad seems like the only way to get help these days.

Yeah I mean, I completely agree.

Re: GitHub blocks entire company because one employee was in Iran

#290
post #228

Earlier quoted context omitted.

>2. Then there's the geopolitical aspect. Is it fair to impose sanctions on Iran. Yeah. Nobody else should be allowed to have nukes, or else the U.S. is gonna take his ball and go home.

Iran is a signatory to the Nuclear Nonproliferation Treaty. According to the treaty, they agreed to not pursue nuclear weapons and to allow IAEA oversight. Making it difficult for the IAEA to provide oversight is enough of a treaty violation, and that goes double when there is credible evidence that unauthorized enrichment was occurring.

Why do non-US companies care about US foreign policy goals? EU companies can benefit from doing business with Iran, on the other hand using US based SaaS only makes them hostages of the US government and provides zero additional benefit. It would seem that using US based SaaS is simply bad risk management on the buyer's part.
Post reply on HN