Live data from Hacker News

GitHub blocks entire company because one employee was in Iran

twitter.com

421–430 of 515 posts

Re: GitHub blocks entire company because one employee was in Iran

#421

Earlier quoted context omitted.

(Controversial comment) I am not condoning the actions of the United States government, but arguably the Iranian Islamic theocratic regime has unleashed more horrors on the Iranian people in the last 50 years than any other foreign government.

Imagine the horror US has unleashed "invading" almost every country in the world (except 3) with formal or hidden missions.

You replied to a troll trap. It doesn't matter what the Iranian gov does or did, nor what the US gov did all these years.

The argument is that the US sanctions are wrong. It's totally against what America and the West at large stands for. Those sanctions, as always punish innocent citizens the most. The strategy of course is to make those citizens revolt. But it ain't even working. See with Iraq and Libya, they litterally ended up bombing these countries and ensured the death penatly to those leaders, and now see how worse it has become over there (interestingly the news outlet don't report much of the situation now).

I have been clearly and firmly reminded by my employer about sanctions on Iran and to not engage in any business with Iranian as clients. The US government, like said in another comment is using its country's private economical powers for the service of its (absurd) geopolitics, not far from what China has been doing, but with far more hypocrisy and somehow less success.

Re: GitHub blocks entire company because one employee was in Iran

#422

Earlier quoted context omitted.

You have a point ( and Mnuchin to his credit ,based on reports, does care about regulatory burden and its impact ). So you are right, one is not like the other. To address your point directly, if OFAC tomorrow added MOHAMMAD JIHAD with no other information ( no DOB, no address, and so on ), you would be surprised how quickly the banks would respond. Now note that that we are discussing a name, a commmon, but somewhat…

Banks typically would react overnight to OFAC list updates, through a sanctions list service. If no DOB or similar is also provided, though, scoring should not be too high - and if a match with Mohammad is enough to trigger an alert, the overnight alert delta would be either manually processed by Compliance, or bulk closed as false positives, depending on how much time you need to unblock the clients and similar risk…

I am not sure if you realize it, but you are proving my point. Banks found a way to address the issue without adversely affecting the customers. Github appears to have only recently started to do the same, but they opted for a blanket approach as opposed to a more targeted one.

Re: GitHub blocks entire company because one employee was in Iran

#423
post #71

Earlier quoted context omitted.

> Ironically, Git is a decentralized version control system. And Git is open source. Github is a US-registered company under MS. The US has a history of weaponizing its economic power. Stallman (RMS) was right once again.

I would go quite a step further than that. If this was not an unfortunate incident/mistake, then GitHub/Microsoft has become quite the active enforcer of US (legal) foreign policy. If they do that within the US market, that might be justifiable. But in this particular case, GitHub appears to enforce US foreign policy on what appears to be a company on the EU market. Also in what to me appears to be a rather ruthless,…

[deleted]

Re: GitHub blocks entire company because one employee was in Iran

#424

Earlier quoted context omitted.

The alternatives: 1. Bomb them back into the stone age. That would kill a whole bunch of people, who as you point out are basically held hostage by their government and don't get much choice in the matter. It'd also permanently wreck their economy and infrastructure, cost lives on both sides, and usually has follow on effects. 2. Do nothing and allow things like funding terrorism, selling arms, committing atrocities,…

These are not the only options. Funding of terrorism is still happening now , and their support is being funnelled through countries that are not under any economic restrictions, some even have good relations with US, like KSA. For example, most official fundamental/terroristic TV channels/groups are based there. Most shell companies used by oppressing regimes in MidEast are in the UAE.

I don't understand your comment as the countries you list are not under sanctions like the ones described.

"doing this to entity X stop that from entity X" "no, look, here is another entity Y where didn't do this, and it still does that"

If anything your comment implies we should sanction all of these countries too.

Re: GitHub blocks entire company because one employee was in Iran

#425

Earlier quoted context omitted.

>Especially us europeans should not rely on American services at all.It's not worth it. Sure, please let me know how the EU plans to build Office 365, AWS, GitHub competitors of similar scale, quality and success. We have no private investors that would pony up enough money to go against US tech titans and fat chance the EU would ever fund such initiatives and if they would, the money would evaporate over night to co…

I think it's important to frame it correctly: US companies have been persistently acting illegally in Europe. Avoiding taxes (e.g. Amazon's Project Goldcrest) to undercut competitors, mishandling data for profit, and then abusing market dominant positions to prevent European competitors from rising up; forcing those potential competitors to sell to US firms. You're right that it's probably too late to reverse all of…

Ah yes, poor innocent Europe that is so distraught over the economic damage US companies did that checks notes Ireland sued the EU on behalf of Apple to prevent it from having to pay taxes.

You're right. You should frame it correctly and take ownership over the complete and utter regulatory failures of European countries to support and nurture local businesses.

Re: GitHub blocks entire company because one employee was in Iran

#426

Earlier quoted context omitted.

> Says who? There is a law, the law is unclear and IHMO a bad law. Says the US Department of the Treasury, as mentioned in the Twitter thread further down: > 118. I have a client that is in Iran to visit a relative. Do I need to restrict the account? > No. As long as you are satisfied that the client is not ordinarily resident in Iran, then the account does not need to be restricted. from their "FAQs: Iran sanctions"…

GitHub didn't decide in their actions blindly. They have lawyers who review the laws, look at their services and write the rules to follow internally. The lawyers obviously have a reason to disagree with the Treasury and GitHub under Microsoft aren't exactly going to be using cheap lawyers either.

They have since restored the account, so your argument is invalid.

Keep in mind that US Government agencies that administer sanctions laws (the Treasury, in this case) are the ones interpreting what these laws mean. See https://en.m.wikipedia.org/wiki/Chevron_U.S.A.,_Inc._v._Natu....

Re: GitHub blocks entire company because one employee was in Iran

#427

Entrusting your business to an american entity is the stupidest idea you could have thought about. Especially us europeans should not rely on American services at all.It's not worth it. American corporations are just as much a liability as their counterparts in China.

I gotta agree with you. I understand GitHub doing that, they fear repercussions (remember that Huawei employee being arrested?). But, these things are too serious for a company to ignore. Chinese and USA services should be avoided...

I assume this will be your last post on HN then...

Re: GitHub blocks entire company because one employee was in Iran

#428

Earlier quoted context omitted.

They probably did not want to have their CEO nabbed by police in the Vancouver airport for extradition on sanctions violations. You might want to see what happened with Huawei, who aren’t even a US company.

If Huawei wants to do business in the US economy, they can do so but have to abide by the rules. They can also choose to do business with Iran instead, but not both.

It appears that you are pretty much the only one who gets it. At least from anyone who responded.

I find it rather shameful, that apparently everyone who responded to my question, did so by explaining that a US company has to abide by US law. You don't say!

That was never the question, but apparently even reading is even too much to ask from people these days.

Of course US companies have to follow US laws. But if that conflicts with law in wherever their services are offered, they no longer have any business operating there. They should consequently stop offering their services in that territory.

Since that's unlikely going to happen on their own initiative, maybe the EU should simply declare companies like these as illegal on their market.

Actually, that might even help to finally get rid of the stranglehold which many US have had for a long time on any emerging potential competition from EU companies. Something for which US companies have regularly used and abused differences in law and economy (between the US and EU), in order to obtain an (unfair) edge.

Maybe it's about time that comes to and end, so US companies can prove that they can compete on equal grounds. I personally doubt that, because for most of the last century this competition has been dominated by the US exploiting artificially created advantages.

Politics aside, it's rather sad that this aspect of legality is even a discussion topic. It should be a no-brainer that US companies should abide by whatever laws exist on a foreign market they operate on (of course on top of US law).

If they can't, the only (legal) option is to stop operating. Either that, or the company is a criminally operating organization. That is, the violations are systemic and not just a few unintended incidences, of course.

Re: GitHub blocks entire company because one employee was in Iran

#429
post #132

Earlier quoted context omitted.

> 2FA should be bypassable after some longish lockout period. Nope. No backups, no sympathy, simple as that. 2FA is worthless if you start to put holes in it like that. So if you value your data, make backups - preferably locally the old-fashioned way, e.g. HDDs stored in at least two different locations or at least using several different cloud providers (which have their own infrastructure and aren't just relying o…

> Nope. No backups, no sympathy, simple as that. This is a really garbage opinion. Long tail reliability situations like this is a major blocking point to large scale adoption of many things. No one wants to use something where the consequence of making a mistake is "well I guess you're f*cked now". You're ignoring the entire usability side of computing and innovation. > 2FA is worthless if you start to put holes in…

> No one wants to use something where the consequence of making a mistake is "well I guess you're f_cked now". You're ignoring the entire usability side of computing and innovation.

Wow wow wow, so you're basically saying that users who are capable enough to even need/use decentralised version control systems are too dumb and incompetent to setup Time Machine, Timeshift, or File History? Really?

> There are other ways to verify identity (especially within a social network, where real life people know other real life people), but these companies simply do not want to put the effort it.

So you are suggesting that instead of keeping one piece of information (e.g. a second e-mail address or just a token generator, which can be an app), you instead share your entire private life with these companies? Oh, and by the way - how would you even protect your social media accounts then? 2FA all the way down?

> Trust me, if Nat Friedman somehow loses his email and 2fac at the same time, I can bet you that they would someone find a way to verify his identity and let him back in to his Github account (or honestly any other account).

Trust me, the CEO running the show is in an entirely different category than most of the 50 million other accounts and you (in this case GH) don't even want to have all this sensitive personal information.

The less info you have, the less impact a data leak on the provider's side can have. Why would anyone trust GH with their personal information more than any other tech company?

Mission critical data belongs in multiple location. Full stop. Losing access to a GH account should never be more than an inconvenience if your livelihood depends on it or you value your personal data.

> This is false. Almost every part of cyber-security is a trade-off between security and usability. If you want the most secure system, just turn everything off. Totally secure. But also totally un-useable.

I'm not talking about security in general. I'm specifically talking about deliberately weakening a security measure (here: 2FA) for no reason at all.

Do you leave your house key under the doormat? Do you keep a post-it note with all your passwords taped to the back of your phone - you know, just in case you forget one and for convenience?

> Not everyone has the privilege to spend a "few hundred bucks on a NAS" and pay for it to be securely stored somewhere.

A USB drive is not a privilege and if you can't afford a data storage solution I seriously wonder why you have a need for a distributed version control system in a (semi-)professional environment.

Data has become more important than ever, yet people still fail to understand to treat it like they would other valuables. 20 bucks for a protective case for your phone - no problem. 50 bucks for a half decent 1TB portable USB HDD to backup their most important and irreplaceable data - only the privileged and tech gurus can afford that...

Nah mate, think again. It just doesn't make sense to put all your eggs in one basket (allegedly 10s of thousands of proverbial eggs in this case) and then whine about forgetting to change 2FA, having no backups whatsoever, and mixing private and work accounts all at the same time.

This is one of those things that you should learn from and the least you can do is to have a cheap external HDD and a recent backup of your most important stuff.

Re: GitHub blocks entire company because one employee was in Iran

#430

The US sanctions on Iran has such a massive impact on Iranians that most of us don't realise. All US companies have to comply and majority of the tech companies are unfortunately in the US. I know you can use a VPN and configure it on a router level to make sure that you are always connected via a VPN but just the fact that 1 slip-up can result in account level blocks (which google is notoriously good at and can esse…

Imagine being a programmer in Israel and hearing that the leader of a neighboring country wants to kill you and everybody you know.

We're not unaware of the impact of sanctions. Fundamentally, starving a generation of Iranians of information and experience is worth it if leads to civil unrest and regime change, therefore preventing Iran's current leaders from committing the genocide they've said they want to commit so many times.

Post reply on HN