Live data from Hacker News

GitHub censored my research data

gwillem.gitlab.io

41–50 of 206 posts

Re: GitHub censored my research data

#42
post #39

We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service ( https://about.gitlab.com/terms/ ). The author says that he contacted "about 30 merchants directly", but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely…

tptacek makes a good argument that responsible disclosure is not a requirement: https://news.ycombinator.com/item?id=12309035

Re: GitHub censored my research data

#43
post #10
post #7

How exactly does publishing a list of malware-infected stores fall under the DMCA? I always thought DMCA was meant to be for copyright infringement cases. I didn't see the list, but did it by any chance contain the logos of the online stores? If it did, the DMCA notices make sense.

Compilations can be copyrighted. There's a long legal history on the topic. Also, logos are generally a topic for trademark laws, not so much copyright.

> Compilations can be copyrighted. There's a long legal history on the topic.

This is true, but totally irrelevant as it misses the point of the question.

Re: GitHub censored my research data

#44
post #40

GL sent me this statement. For the record, I didn't publish vulnerable systems, I published stores that have malware. --- Willem, GitLab has opted to remove the list of servers that you posted in your snippet. GitLab views the exposure of the vulnerable systems as egregious and will not abide it. While GiLab reserves the right take further action, up to and including termination ( https://about.gitlab.com/terms/ ), w…

And even if it were (a list of vulnerable systems, that is), why the fuck do they think that they should censor serious journalism? If you operate a public venue, then it is an important societal role of journalism to report on it if that public venue poses a risk to the public, whether that might also have negative consequences for the people operating it is completely irrelevant.

Re: GitHub censored my research data

#45
post #39

We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service ( https://about.gitlab.com/terms/ ). The author says that he contacted "about 30 merchants directly", but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely…

Don't you feel uncomfortable in making it harder for users to avoid websites with malicious software? It's definitely worth mentioning and explaining if you do.

Re: GitHub censored my research data

#46
post #39

We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service ( https://about.gitlab.com/terms/ ). The author says that he contacted "about 30 merchants directly", but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely…

[deleted]

Re: GitHub censored my research data

#47
post #12
post #7

How exactly does publishing a list of malware-infected stores fall under the DMCA? I always thought DMCA was meant to be for copyright infringement cases. I didn't see the list, but did it by any chance contain the logos of the online stores? If it did, the DMCA notices make sense.

The claims probably have little to do with DMCA violations themselves, but it has become an easy way to get content removed quickly from sites without very much review from the host service. The claims are probably from the malware perpetrators as a way to censor discussion and keep the gravy train rolling. It's possible also that the embarrassed commerce sites would file a DMCA claim to keep the public in the dark a…

Indeed, this is one of many cases where the DMCA is almost an invitation for abuse - which was, if I remember correctly, also one of the main points of criticism when the DMCA was created.

Re: GitHub censored my research data

#48
post #39

We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service ( https://about.gitlab.com/terms/ ). The author says that he contacted "about 30 merchants directly", but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely…

Why are you putting the interests of merchants before the interest of users (of these merchants)?

Do you think Google should "responsibly" disclose and wait for webmaster's response before putting websites into Safe Browsing list?

Can I host a project which includes a list similar to Google Safe Browsing, or an adware remover where I list software I consider to be adware?

Re: GitHub censored my research data

#49
post #19

Earlier quoted context omitted.

And get DDoSed by the malware guys who don't want their victims know they are in the list and fix their site. It would be an altruistic offer but I would think twice about it. However it's a problem and we need a solution. A torrent? Yes but Google won't index it. A file on S3 wouldn't work because they could just download it as many times as needed to make the bill skyrocket. Better than a DCMA. Anything that is una…

Blogspot/Blogger?

DMCA, again. I forgot that constraint.

Re: GitHub censored my research data

#50
post #39

We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service ( https://about.gitlab.com/terms/ ). The author says that he contacted "about 30 merchants directly", but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely…

These sites are actively participating in harming their users with their negligence. Users should have the ability to know which site is safe and which isn't.
Post reply on HN