Live data from Hacker News

GitHub blocks entire company because one employee was in Iran

twitter.com

341–350 of 515 posts

Re: GitHub blocks entire company because one employee was in Iran

#341
post #45

Earlier quoted context omitted.

It's not an Iranian employee. That's just someone visiting Iran and login to their GitHub account. GitHub reaction is outrageously disproportionate. They should just prevent login from Iran. They had no basis for blocking a legitimate customer in Europe based on this.

> ... one employee opened his laptop while visiting [h]is parents in Iran. I suppose this implies that the employee is Iranian. The U.S. sanctions are pretty aggressive, and I don't think preventing login from Iran is anywhere near enough to comply. The law is the problem here.

Nope, not at all. Thousands of Europeans are travelling to Iran for tourism or conducting business. The trade sanctions don't block visitors to check their work.

"The United States has imposed an arms ban and an almost total economic embargo on Iran, which includes sanctions on companies doing business with Iran, a ban on all Iranian-origin imports, sanctions on Iranian financial institutions, ..."

A private visit is not doing business, so the org cannot be blocked. And most other companies are ignoring the US sanctions, that's why we have the current propaganda push.

The law is ok, because economical sanctions are the only way to get rogue nation states to comply. That's why we have sanctions on Iran, Russia, Crimes, North Korea. Unfortunately not against the US yet.

Re: GitHub blocks entire company because one employee was in Iran

#342
post #320

Earlier quoted context omitted.

It may be overreach by GitHub, but given the severity of the sanctions lawmakers have set for if they happen to get it wrong, I'd like to at least blame lawmakers for creating such a risky situation.

I would blame the automatic sanctioning software triggering such as situation, without checking if the new access from Iran was by a tourist or citizen. Adding an org block for minor access within two weeks is overreach.

I’m unaware of a library that checks citizenship of the user behind an IP address.

Re: GitHub blocks entire company because one employee was in Iran

#343
post #320

Earlier quoted context omitted.

It may be overreach by GitHub, but given the severity of the sanctions lawmakers have set for if they happen to get it wrong, I'd like to at least blame lawmakers for creating such a risky situation.

I would blame the automatic sanctioning software triggering such as situation, without checking if the new access from Iran was by a tourist or citizen. Adding an org block for minor access within two weeks is overreach.

This kind of software is not simply installed with an apt-get one-liner, github can’t be exempted from choosing their business rules on screening matches.

Re: GitHub blocks entire company because one employee was in Iran

#344
post #132

Earlier quoted context omitted.

2FA should be bypassable after some longish lockout period. For example, someone has lost their password, email access, phone number, and 2FA app. Make them wait a month to regain account access. If any time during that month, the account is used or logged into, cancel the takeover request. During the month, every day send an email to all points of contact on the account letting them know what will happen. It's a tra…

> 2FA should be bypassable after some longish lockout period. Nope. No backups, no sympathy, simple as that. 2FA is worthless if you start to put holes in it like that. So if you value your data, make backups - preferably locally the old-fashioned way, e.g. HDDs stored in at least two different locations or at least using several different cloud providers (which have their own infrastructure and aren't just relying o…

> Nope. No backups, no sympathy, simple as that.

This is a really garbage opinion. Long tail reliability situations like this is a major blocking point to large scale adoption of many things. No one wants to use something where the consequence of making a mistake is "well I guess you're f*cked now". You're ignoring the entire usability side of computing and innovation.

> 2FA is worthless if you start to put holes in it like that.

No, it is not. 2FA can still prevent 99% of takeover attempts. There are other ways to verify identity (especially within a social network, where real life people know other real life people), but these companies simply do not want to put the effort it. And I can't really blame them: it would be a large investment to verify the identity of a given, every day person. This could be something that can be paid for in order to regain access in order to cover the elevated review necessary.

Trust me, if Nat Friedman somehow loses his email and 2fac at the same time, I can bet you that they would someone find a way to verify his identity and let him back in to his Github account (or honestly any other account).

> There's no such thing as a "trade-off" when it comes to cyber security

This is false. Almost every part of cyber-security is a trade-off between security and usability. If you want the most secure system, just turn everything off. Totally secure. But also totally un-useable.

> If you can't spare a few hundred bucks on a NAS that you can just put in a storage unit or bank vault if need be, you data can't be that valuable anyway.

Not everyone has the privilege to spend a "few hundred bucks on a NAS" and pay for it to be securely stored somewhere.

Re: GitHub blocks entire company because one employee was in Iran

#345
post #318

So are we not going to talk about how economic sanctions end up as a way to use the people of these countries as a way to pressure their governments for political gains? How these sanctions directly and indirectly cause an increased poverty gap and negatively impact the living standards? How the governments of these sanctioned countries magnify this economic pressure to prevent people from revolting and to entrench t…

Two kind of sanctions: - sanction the leaders responsible and their buddies, the most common (that's what we do with russia, turkey, ...), hurt their wallet but ultimately is a soft sanction, and also your populace sees it as ineffective / nothing is done - sanction the country directly, embargo, complete block, kick out of swift, that sort of stuff is what was done to Iran. Can only be done if you're part of the big…

> Massive effect, causes lots of poverty and pain for the populace but that's on purpose

This is what I'm talking about. Even if I'm to agree with the purpose of the requested change, does it justify the means by which it's being procured?

Trump may have screwed it up even more, but sanctions of the second kind have been introduced on countries like Iran or Syria since the mid-80s afaik. No major change happened, but the idea of knowingly use the population of another country to pressure their government which is known to not be chosen democratically is basically a form of hostage situation, and is immoral imho.

Re: GitHub blocks entire company because one employee was in Iran

#346

Earlier quoted context omitted.

> But in this particular case, GitHub appears to enforce US foreign policy on what appears to be a company on the EU market. Surely enforcing your politics outside of your jurisdiction is the whole point of an embargo?

As a government, yes. As a commercial company, operating on a market outside of US jurisdiction, please explain me the legal basis for that (if you can).

The legal basis is they are using a U.S. company (GitHub) that has to has to follow U.S. laws. And that makes certain things inconvenient for them.

Re: GitHub blocks entire company because one employee was in Iran

#347
post #153

Earlier quoted context omitted.

This particular case was overreach by Github and not the US Lawmakers. https://home.treasury.gov/policy-issues/financial-sanctions/... 118. I have a client that is in Iran to visit a relative. Do I need to restrict the account? A: No. As long as you are satisfied that the client is not ordinarily resident in Iran, then the account does not need to be restricted. See FAQ 37. Source: https://twitter.com/Hamed/status/13…

The problem starts with how to even identify if someone is physically in Iran. Making that asumption based on the IP address is highly questionable.

You think a lot of people are proxyjng their traffic through an Iranian IP address?

Re: GitHub blocks entire company because one employee was in Iran

#348
post #270

Earlier quoted context omitted.

I find your use of "illegal" interesting. To me, it means "against a law", and laws are made by countries (sure, parliaments of those countries or dictators or...), and generally apply only to that particular country (some things attempt to get a wider reach, but they are usually unenforceable unless there's a local company to pursue, most famous example being GDPR). There are international conventions and the UN, bu…

"Illegal" is routinely used when talked about sanctions. In that sense it means "unjustified".

No, you’re practicing Doublespeak. Illegality and illegitimacy are not the same thing.

Re: GitHub blocks entire company because one employee was in Iran

#350

Earlier quoted context omitted.

> But in this particular case, GitHub appears to enforce US foreign policy on what appears to be a company on the EU market. Surely enforcing your politics outside of your jurisdiction is the whole point of an embargo?

As a government, yes. As a commercial company, operating on a market outside of US jurisdiction, please explain me the legal basis for that (if you can).

The government where the commercial company is based expects the company to do so, and will hold that company accountable if they do not.

You may not agree with this situation, but it is how it works. The US government will investigate and penalize companies that violate US sanctions, even if the parts of those companies involved did so entirely outside of the US.

Post reply on HN