Live data from Hacker News

GitHub blocks entire company because one employee was in Iran

twitter.com

471–480 of 515 posts

Re: GitHub blocks entire company because one employee was in Iran

#471
post #394

Earlier quoted context omitted.

I'm in the U.S. and I still have to click all those super annoying "Accept using a cookie" popups everywhere. So that EU law certainly does affect me a U.S. citizen interacting with U.S. companies.

That is because it is cheaper to show it to everybody. Not because EU would demand it to be shown for Americans. Also, law do not require it to be shown for all cookies. Only for tracking ones.

To nitpick, while for non-EU companies GDPR applies to individuals in EU (and their data) as per GDPR article 3.2, any EU companies have to apply this for all personal data as per GDPR article 3.1.

So while foreign companies can decide whether they want to apply their GDPR policies (which generally should not require "cookie banners", though it is a popular choice) only to people in EU or all their users, an EU company does not have a choice, they have the obligation to treat personal data of Americans and Iranians and everyone else in a GDPR-appropriate manner.

Re: GitHub blocks entire company because one employee was in Iran

#472
post #449

Earlier quoted context omitted.

I wouldn't consider Accenture a large software company. They do a lot of software "consultancy" (ie bodyshopping), but the nature of the consulting game plus their decentralized architecture (I've worked with Accenture, and the relationship between their different offices seems to be closer to co-franchisees than colleagues) means I wouldn't consider it a "big software company" (as in lots of people working on the sa…

Yup they're not a big software company if you arbitrarily constrain the definition of software company. I could argue Google is not a big software company (as in lots of people working with mismatching socks and propeller hats). But that would be just as stupid.

What I mean is that the overwhelming majority of Accenture (or TCS, or Deloitte, or IBM Consulting, or Infosys, or any other bodyshop) employees aren’t building software for Accenture, they’re being hired out. So that’s why I don’t consider Accenture a “software” company

Would you consider Randstad to be a building company? They loan out hundreds of thousands of building contractors across the world

Re: GitHub blocks entire company because one employee was in Iran

#473
post #204
post #71

Earlier quoted context omitted.

> Ironically, Git is a decentralized version control system. And Git is open source. Github is a US-registered company under MS. The US has a history of weaponizing its economic power. Stallman (RMS) was right once again.

I'm not a pro dev by any means but what is stopping orgs from simply self hosting such a thing? Git is merely version control which supposedly does not take a lot of resources so you can go ahead and buy a dedicated server and host it in your office. Is the question more so about expanded services like CI/CD that may take up more computational resources to continuously build binaries and other deliverables?

Self-Hosting is a similar tradeoff to running your own hardware, imo. You can increase control and overall cost effectiveness for additional scaling, but these choices have a certain base cost you can't reduce. Thus, they only work beyond a certain initial scale, or because you have some specialized requirements.

For example, the source code as well as the tickets around a software tend to be the most critical assets of a company. As such, you need one or better 2 systems to host the source host and ticketing. However, such a system needs backups, so suddenly you need to maintain a backup solution, you need to implement and monitor the backups being created, you need restore tests. You end up needing some kind of monitoring as well. As well as 2-3 dudes at least part-time maintaining all of this capable of replacing each other during sickness and vacation.

That's a lot of stuff as well as a lot of manpower as your base cost. Of course, once you have that, you can self-host a lot of things easily and maintain excellent uptime at minimal risk, because these base services scale very well in complexity. For us it makes sense to do this, because unplanned outages at 100+ developers are seriously expensive and risky.

However, if you have 3 developers and a clock ticking to find product market fit, you don't have that budget - or spending it this way does not make sense. So you buy.

Re: GitHub blocks entire company because one employee was in Iran

#474
post #71

Earlier quoted context omitted.

> Ironically, Git is a decentralized version control system. And Git is open source. Github is a US-registered company under MS. The US has a history of weaponizing its economic power. Stallman (RMS) was right once again.

I would go quite a step further than that. If this was not an unfortunate incident/mistake, then GitHub/Microsoft has become quite the active enforcer of US (legal) foreign policy. If they do that within the US market, that might be justifiable. But in this particular case, GitHub appears to enforce US foreign policy on what appears to be a company on the EU market. Also in what to me appears to be a rather ruthless,…

"this action is arbitrarily discriminatory" - if so, this action is permitted. While there often are restrictions on specific, enumerated types of discrimination (e.g. religion, ethnicity, gender, etc - though almost universally they apply to discrimination of people, not companies), those are exceptions to the general principle of "freedom of association" where people and companies are free to arbitrarily decide with whom they want to do business and whom they want to exclude - as far as they don't violate some of the specific restrictions listed in law. If a supplier does not want to sell to your company for an arbitrary reason, it's their right to do so.

"constitutes inflicting serious damage on another company without a legal basis" - again, that does not indicate any wrongdoing. Inflicting serious damage on another company is, by default, permitted (matching the core principle of "everything which is not forbidden is allowed") and is regularly done in the course of normal competition, winning over some other company in bids, recruiting key employees by offering them lots of money, targeting their customers with specific discounts, etc, etc.

If you're inflicting serious damage on another company, then both the intent and result is by itself legal, the only question is about the means. If you're inflicting serious damage on another company by legally prohibited means (e.g. theft or arson or illegal access to computer systems) or violating some established legal duty (e.g. "duty of care" as required by law in various service relationships), then the other company would be entitled compensation. But in the absence of that, if there's no specific legal prohibition to your action (for example, laws on anti-competitive actions tend to impose various restrictions), if your action is legally permitted, then if some company suffers because of that, it's not your problem. There are restrictions on what actions are legally permitted (law on tortious interference might apply here, and if there's some fraud, injurious falsehood etc then it matters) but if they do have the right to arbitrarily end the contract, then that's it, they are not responsible for the damages.

Re: GitHub blocks entire company because one employee was in Iran

#475
post #295

Earlier quoted context omitted.

I'd imagine Github/Microsoft has extremely strict rules about not taking company resources to, or performing any work at, or accessing any company resources from countries that are embargoed. This simply wouldn't happen at my company because special permission is needed to take any company assets out of the country. If anyone at my company casually took a company laptop to Iran that would be instant termination. It a…

This is not the case at most large companies (FAANG) - no special permission is required to take a laptop with you across borders. They'd generally rather you have your laptop with you so you can get work done. Regardless, this person logged into GitHub, which could have been from any device including a phone.

1) In this case the laptop was taken to Iran, so that's what we are talking about here.

2) I can assure you there's policies at Microsoft that include performing work abroad and accessing any company resources from abroad. Obviously nobody will be approved to access any company resources from Iran, especially not source code.

3) I can say there is policies at MS this with a very high degree of confidence because I personally have done work with Microsoft involving code and data that is export restricted.

4) Companies should have policies in place in order to avoid situations like this. Taking your company laptop to, say, Germany probably isn't a big deal for most companies, but any "exporting" company assets should at least be pre-approved/documented.

Re: GitHub blocks entire company because one employee was in Iran

#476

The US sanctions on Iran has such a massive impact on Iranians that most of us don't realise. All US companies have to comply and majority of the tech companies are unfortunately in the US. I know you can use a VPN and configure it on a router level to make sure that you are always connected via a VPN but just the fact that 1 slip-up can result in account level blocks (which google is notoriously good at and can esse…

Imagine being a programmer in Israel and hearing that the leader of a neighboring country wants to kill you and everybody you know. We're not unaware of the impact of sanctions. Fundamentally, starving a generation of Iranians of information and experience is worth it if leads to civil unrest and regime change, therefore preventing Iran's current leaders from committing the genocide they've said they want to commit s…

> starving a generation of Iranians of information and experience is worth it if leads to civil unrest and regime change

I'm afraid you're mistaken, and that removing knowledge from people just makes the regime stronger.

Instead, providing the people in Iran with more knowledge and education would make even more people oppose the dictatorship, I'd think.

Not nuclear physics though, but GitHub yes sure.

Re: GitHub blocks entire company because one employee was in Iran

#477
post #442

Earlier quoted context omitted.

I think you may have either misunderstood me, or maybe have gotten the logic backwards. I'm not saying that US companies should not enforce US law. I think they should. That is: strictly within the US market. When they operate outside the US market, they have to (also) adhere to whatever law exists for that market. If that creates a conflict, the company has a choice to either open up show elsewhere, outside of US ju…

It’s been my personal experience that the US government does not distinguish between a US company offering products and services in the US and a US company offering those products and services outside the US. Even foreign subsidiaries are held accountable to US laws and regulations if the US parent has sufficient control of the company. Bigger companies get a little bit more leeway to negotiate with the US Federal go…

You are correct, on each and every count. However, none of that is related to what I tried to highlight.

Sure, the US is (rightfully so) subjecting every company within its jurisdiction to US law, no matter on which market they operate. Sometimes they go even further and say non-US companies can be held liable, when they somehow interact with the USA or its citizens. That can sometimes become a bit dicey with jurisdictions, but even that is not the point here.

The point is that a US-based company is operating on a market outside the US and (most likely) is operating in a way that is within the law of that market.

To put bluntly: I don't give a #### about how the US treats companies on their territory, regardless where those operate. I care about US-based companies abiding to law wherever they do business. If they can not do that, they should cease to operate there. Whether it's the US government or something else that is to blame for the situation is irrelevant.

Re: GitHub blocks entire company because one employee was in Iran

#478
post #359

Earlier quoted context omitted.

Do Danes have unique server needs compared to the rest of the world?

Yes, they speak Danish.

And Danish laws and Danish accounting systems and Danish gov agencies to maybe integrate with, etc

(Maybe more relevant for SaaS than servers though)

Re: GitHub blocks entire company because one employee was in Iran

#479
post #66

Earlier quoted context omitted.

There are countries in which being gay will still cause you serious trouble. Or not agreeing with the political leadership. We are quite privileged to just assume that following the law as written (AND interpreted by the judiciary) will mostly work out alright and doesn't cause us moral dilemma. And companies consist of people, too. Is it then all of a sudden morally acceptable to build spying software so your countr…

We can all cite harmful laws, does that mean companies (and people) should be free to ignore all law? Should US companies be free to ignore laws related to sanctions because the UAE has made being gay illegal or because political opposition in China could land you in jail? Where do you draw the line? Specifically - for a US company as is being discussed.

Where did I say "all"?

Re: GitHub blocks entire company because one employee was in Iran

#480
post #424

Earlier quoted context omitted.

These are not the only options. Funding of terrorism is still happening now , and their support is being funnelled through countries that are not under any economic restrictions, some even have good relations with US, like KSA. For example, most official fundamental/terroristic TV channels/groups are based there. Most shell companies used by oppressing regimes in MidEast are in the UAE.

I don't understand your comment as the countries you list are not under sanctions like the ones described. "doing this to entity X stop that from entity X" "no, look, here is another entity Y where didn't do this, and it still does that" If anything your comment implies we should sanction all of these countries too.

It's pretty simple really:

- Sanctions don't achieve the goal of stopping funding terrorism as evident by it still happening.

- IF the point of sanctions was to _actually_ stop terrorism funding, you'd start at the origin of where these ideas start, which is known to be Wahhabism/Salafism.

- At least, you'd start at the origin of how people holding these ideas were supported and given weapons and training to achieve regime change goals and to fight against Russians in Afghanistan.

Post reply on HN