Earlier quoted context omitted.
To be fair to GH, I wouldn't trust them if their customer service could be convinced to unlock an account with neither email nor 2FA access. Passwords leak all the time (because people are bad at using unique passwords) and social engineering efforts are quite effective at hijacking high-value accounts in a great deal of companies, so while I sympathise with the loss of your account, your experience actually improves…
They just turned 2FA on for all accounts and that was the moment I found out that mine was pointing to the wrong email address. I wish they would allow you to sign something with your private SSH key to get an inactive account back.
GitHub blocks entire company because one employee was in Iran
441–450 of 515 posts
Re: GitHub blocks entire company because one employee was in Iran
#442Earlier quoted context omitted.
Given the pressure by the EU and China on US companies to enforce local laws globally (GDPR, RTBF, Taiwan), I don't see how Github, operating in the US, as a US company, has any chance absolving itself of enforcing US laws and regulations (though in this specific case they appear to have overreacted, likely due to regulatory enforcement via algorithm and not common sense). If you expect US companies to respect GDPR a…
I think you may have either misunderstood me, or maybe have gotten the logic backwards. I'm not saying that US companies should not enforce US law. I think they should. That is: strictly within the US market. When they operate outside the US market, they have to (also) adhere to whatever law exists for that market. If that creates a conflict, the company has a choice to either open up show elsewhere, outside of US ju…
Bigger companies get a little bit more leeway to negotiate with the US Federal government on this but if the US decides that something is illegal or prohibited, the Justice Department doesn't really care what country the prohibited activity occurred in, it'll walk the executive chain to pick people to prosecute.
The only way a company could complete avoid this scenario is if it licensed its product or service to an independent entity outside the US. And even then the DOJ would likely attempt to force the termination of the license agreement if it results in a product or service being offered in a prohibited jurisdiction.
None of this is new, or due to Trump, or even partisan.
Re: GitHub blocks entire company because one employee was in Iran
#443GitHub: "Lets rename master to main because Inclusion & Equality" Also GitHub: "sorry you're from a wrong country"
> Also GitHub: "sorry you're from a wrong country" GitHub has no choice into the matter short of moving all it's infra in another country. This is a political issue, pressure need to be put on political leaders to change that stupid law.
https://home.treasury.gov/policy-issues/financial-sanctions/... 118. I have a client that is in Iran to visit a relative. Do I need to restrict the account?
Answer
No. As long as you are satisfied that the client is not ordinarily resident in Iran, then the account does not need to be restricted. See FAQ 37
Re: GitHub blocks entire company because one employee was in Iran
#444Earlier quoted context omitted.
> 2FA should be bypassable after some longish lockout period. Nope. No backups, no sympathy, simple as that. 2FA is worthless if you start to put holes in it like that. So if you value your data, make backups - preferably locally the old-fashioned way, e.g. HDDs stored in at least two different locations or at least using several different cloud providers (which have their own infrastructure and aren't just relying o…
>> 2FA should be bypassable after some longish lockout period. > Nope. No backups, no sympathy, simple as that. My two sim-cards were lost at the same time. Impossible, right? Now I cannot access my Github account anymore. Perfect security. Nothing important is lost and backups are there. But what about the account itself?
Re: GitHub blocks entire company because one employee was in Iran
#445Earlier quoted context omitted.
...” , this action is arbitrarily discriminatory, and very likely constitutes inflicting serious damage on another company without a legal basis...” Isn’t that what YouTube and FaceBook do day in day out when their influencers run afoul of policy?
If a user runs afoul of policy, the action was not arbitrarily discriminatory.
That of a commercial company, which does not have a legal mandate (at least not in the EU) to make make rules that violate EU law (including legal protections), or the US government, which does not have legal jurisdiction over the EU market?
Pick your poison
Re: GitHub blocks entire company because one employee was in Iran
#446Just happened: https://github.blog/2021-01-05-advancing-developer-freedom-g...
> we are working with the US government to secure similar licenses for developers in Crimea and Syria as well
That's also super cool to hear!
Related Thread: https://news.ycombinator.com/item?id=25648585
Re: GitHub blocks entire company because one employee was in Iran
#447Earlier quoted context omitted.
I'd imagine Github/Microsoft has extremely strict rules about not taking company resources to, or performing any work at, or accessing any company resources from countries that are embargoed. This simply wouldn't happen at my company because special permission is needed to take any company assets out of the country. If anyone at my company casually took a company laptop to Iran that would be instant termination. It a…
My startup had similar rules when we were only 10 people. Beyond just the Iran issue, it's known that trade secrets on employee laptops are at risk when crossing some international borders, particularly in airports. Border agents can confiscate electronic devices on vague suspicions, compel you to unlock them (or hack them open in some cases), and then leave them in unsupervised settings with yet more border agents w…
All devices are subject to search, seizure, and duplication when crossing international borders and border agents may tamper with devices as well. If assets cross borders there has to be a good reason, it has to be documented, and phones/computers may have to be scrubbed before and after depending on circumstances.
Re: GitHub blocks entire company because one employee was in Iran
#448Earlier quoted context omitted.
Given the pressure by the EU and China on US companies to enforce local laws globally (GDPR, RTBF, Taiwan), I don't see how Github, operating in the US, as a US company, has any chance absolving itself of enforcing US laws and regulations (though in this specific case they appear to have overreacted, likely due to regulatory enforcement via algorithm and not common sense). If you expect US companies to respect GDPR a…
EU is not forcing American companies to enforce their laws for third party companies operating on non-EU market. Also, American company does not have to follow GDPR for Iranian customers. EU wants American companies to follow GDPR when acting in EU market.
I'm not saying it's right, I am saying that these are the logical, practical responses to the way different jurisdictions expect their laws and regulations to be honored, respected, and applied.
Re: GitHub blocks entire company because one employee was in Iran
#449Earlier quoted context omitted.
While the US sure is dominant, there are dozens of software companies larger than those in that list, e.g. Zoho has about $5B revenue, Baidu $11B, Tencent $23B, Accenture $41B, ... The list employs some particular filters (e.g. SaaS seems to be excluded) and heavily emphasizes market cap over revenue.
I wouldn't consider Accenture a large software company. They do a lot of software "consultancy" (ie bodyshopping), but the nature of the consulting game plus their decentralized architecture (I've worked with Accenture, and the relationship between their different offices seems to be closer to co-franchisees than colleagues) means I wouldn't consider it a "big software company" (as in lots of people working on the sa…
I could argue Google is not a big software company (as in lots of people working with mismatching socks and propeller hats).
But that would be just as stupid.
Re: GitHub blocks entire company because one employee was in Iran
#450Earlier quoted context omitted.
EU is not forcing American companies to enforce their laws for third party companies operating on non-EU market. Also, American company does not have to follow GDPR for Iranian customers. EU wants American companies to follow GDPR when acting in EU market.
I'm in the U.S. and I still have to click all those super annoying "Accept using a cookie" popups everywhere. So that EU law certainly does affect me a U.S. citizen interacting with U.S. companies.
Start complaining to those companies and stop pointing your finger in the wrong direction.