Live data from Hacker News

GitHub blocks entire company because one employee was in Iran

twitter.com

361–370 of 515 posts

Re: GitHub blocks entire company because one employee was in Iran

#361

Earlier quoted context omitted.

> companies are private entities. Private entities chartered and regulated by the government, of course.

Businesses have the right to refuse service.

By that logic, so do governments have the right to exercise their prerogatives...

Re: GitHub blocks entire company because one employee was in Iran

#362
post #318

Earlier quoted context omitted.

Two kind of sanctions: - sanction the leaders responsible and their buddies, the most common (that's what we do with russia, turkey, ...), hurt their wallet but ultimately is a soft sanction, and also your populace sees it as ineffective / nothing is done - sanction the country directly, embargo, complete block, kick out of swift, that sort of stuff is what was done to Iran. Can only be done if you're part of the big…

> Massive effect, causes lots of poverty and pain for the populace but that's on purpose This is what I'm talking about. Even if I'm to agree with the purpose of the requested change, does it justify the means by which it's being procured? Trump may have screwed it up even more, but sanctions of the second kind have been introduced on countries like Iran or Syria since the mid-80s afaik. No major change happened, but…

The alternatives:

1. Bomb them back into the stone age. That would kill a whole bunch of people, who as you point out are basically held hostage by their government and don't get much choice in the matter. It'd also permanently wreck their economy and infrastructure, cost lives on both sides, and usually has follow on effects.

2. Do nothing and allow things like funding terrorism, selling arms, committing atrocities, etc. You would know these things are going on, and therefore be allowing them to happen, and these things would probably be happening to your own people and allies.

Which one would you rather take?

Re: GitHub blocks entire company because one employee was in Iran

#364
post #128

Earlier quoted context omitted.

> They are not responsible for the content of US export control law But they are responsible for understanding what's required under those laws. If they're going beyond what's required to comply with the law, then those further actions are entirely on them.

Yes, so Github has to take on the assumption that they are visiting relatives, not resident in Iran. Or you get the alternate headline "Github facilitates Iran sanction evasion by allowing Iranian developers to mark themselves as 'visiting a relative'" and the associated charges.

There's nothing in the law that says that Github must block an entire company from accessing their company org because one member of that company logged into a separate account that happened to be a member of the company org. At most, the account that was accessed should be suspended.

Re: GitHub blocks entire company because one employee was in Iran

#365
post #245

Earlier quoted context omitted.

WRT self hosting, GitLab could be painful, but Gitea is really easy to host and keep up to date.

I've been self-hosting gitlab for few years now in my company and never had a problem.

You should clone your environment and then inject faults into the clone to cause yourself some simulated problems.

Re: GitHub blocks entire company because one employee was in Iran

#366

Earlier quoted context omitted.

> Massive effect, causes lots of poverty and pain for the populace but that's on purpose This is what I'm talking about. Even if I'm to agree with the purpose of the requested change, does it justify the means by which it's being procured? Trump may have screwed it up even more, but sanctions of the second kind have been introduced on countries like Iran or Syria since the mid-80s afaik. No major change happened, but…

The alternatives: 1. Bomb them back into the stone age. That would kill a whole bunch of people, who as you point out are basically held hostage by their government and don't get much choice in the matter. It'd also permanently wreck their economy and infrastructure, cost lives on both sides, and usually has follow on effects. 2. Do nothing and allow things like funding terrorism, selling arms, committing atrocities,…

These are not the only options.

Funding of terrorism is still happening now, and their support is being funnelled through countries that are not under any economic restrictions, some even have good relations with US, like KSA. For example, most official fundamental/terroristic TV channels/groups are based there. Most shell companies used by oppressing regimes in MidEast are in the UAE.

Re: GitHub blocks entire company because one employee was in Iran

#368

Earlier quoted context omitted.

So look at (one one hand) a customer worth... well, PureLabs is "10 incredible FTEs," let's give them the $21/user/mo Enterprise plan at $210/month in revenue. On the other hand, a sanctions violation could be a $65,000 fine (Trading with the Enemy Act) or $250,000 (International Emergency Economic Powers Act) for each offense. (I leave aside the million-dollar narcotics-kingpin act). On top of this we also see the r…

It is hard to discuss hypothetical violations so I won't do that. It absolutely is a safe course of action to do a blanket ban. That said, is it reasonable to assume violation based on IP address ( and that is what seems to have happened here )? Banks don't automatically (typically ) block MUHAMMAD JIHAD even if they may end up questioning it.

> It absolutely is a safe course of action to do a blanket ban.

Except when you make a mistake and ruin someone’s morning.

Re: GitHub blocks entire company because one employee was in Iran

#369
post #153

Earlier quoted context omitted.

This particular case was overreach by Github and not the US Lawmakers. https://home.treasury.gov/policy-issues/financial-sanctions/... 118. I have a client that is in Iran to visit a relative. Do I need to restrict the account? A: No. As long as you are satisfied that the client is not ordinarily resident in Iran, then the account does not need to be restricted. See FAQ 37. Source: https://twitter.com/Hamed/status/13…

If you read this literally, you could get away with leaking state secrets as long as you're visiting a relative while doing it. Github cannot be expected to reliably differentiate between the coworker who just checked the status of a PR on a webapp versus the employee who opened a crucial piece of encryption code to leak it to the Iranian military or whatever.

A spy could also just clone the repo and travel to Iran, too.

Re: GitHub blocks entire company because one employee was in Iran

#370

If the Iranian employee logged into the Github account, isn't blocking the account exactly what the law says they should do? If all they did was apply a merge request in one of the repos then would reverting the merge and blocking the account would be enough to comply? Is there some alternative way to comply with US export restrictions? The real question here is why people even consider using US cloud companies when…

>If the Iranian employee logged into the Github account, isn't blocking the account exactly what the law says they should do?

Does everyone in the world need to subscribe to "a list of countries US jurisdiction doesn't like" just so we will be able to work, check email or review opensource code while being on holiday in an exotic country?

Post reply on HN