16 comments

  • hermitcrab2 hours ago
    Author of the post here. Github finally took the offending page down approximately 10 minutes after the post appeared on the front page of HN. Total coincidence. I&#x27;m sure!<p>Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.<p>And it seems they are able to do things very quickly, when they want to. Bastards.
    • koolba2 hours ago
      &gt; Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.<p>This also works for Google support.<p>&gt; And it seems they are able to do things very quickly, when they want to. Bastards.<p>I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.<p>It was already a problem before agents could automatically perform these actions.<p>And it’s not something you can really automate on their end either. At least not the judgement call on the removal. Imagine if there was a fully automated process and it inadvertently took down a legit project.
      • debugnik2 hours ago
        &gt; I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.<p>Stalling in the hope that reporters won&#x27;t escalate, instead of allocating a tiny bit of their billions in profit to hiring for this, is malicious in my book.
        • amdsn2 hours ago
          I had several small requests for moderation (deleting and banning spammers posting spam&#x2F;crypto scam issues&#x2F;PRs in my repos and ones I contribute to) answered within a day earlier this year after more than a decade of never needing to request moderation. I&#x27;m not defending GH here as it&#x27;s obviously unacceptable that the OP&#x27;s issue took this long, but they definitely do or at least did have mods. I would guess they need a lot more of them if something this serious went unaddressed, or maybe the ones I interacted with are now gone and have not been backfilled.
        • ktm5j58 minutes ago
          I mean.. for better or worse, this is how corporate America works. Hiring to solve a problem that&#x27;s not costing them money (and solving it doesn&#x27;t make money) is probably not going to happen, especially with the current state of the economy. They have more of an obligation to make money for their investors than they do anything else, that&#x27;s just how it works.
          • Paracompact23 minutes ago
            &gt; They have more of an obligation to make money for their investors than they do anything else, that&#x27;s just how it works<p>Where does this myth come from, and how does it survive? It&#x27;s either an excuse for parasitic corporatism, or an expression of learned helplessness. Nobody has been successfully sued for prioritizing the long-term health and reputation of a company over self-starving quarterly profit.<p>Is there a perverse incentive toward the latter anyway? Yes. But it mostly serves current leadership, who are evaluated and paid on short horizons, <i>at the expense of</i> the long-term investors who own most of the equity.
            • ktm5j20 minutes ago
              Definitely not a myth, friend. Read this article from Harvard Business School: <a href="https:&#x2F;&#x2F;online.hbs.edu&#x2F;blog&#x2F;post&#x2F;fiduciary-duty-to-investors" rel="nofollow">https:&#x2F;&#x2F;online.hbs.edu&#x2F;blog&#x2F;post&#x2F;fiduciary-duty-to-investors</a><p>&quot;Accepting funding from investors puts you in a fiduciary role in which you’re responsible for managing their money and putting their needs above your own&quot;
            • mistrial91 minute ago
              many readers here have not experienced a standard of customer support that was common decades ago. Google in particular created a new standard for ignoring the customer on a large scale, in my own experiences. Secondly, the customer paid money to a company for service, while an emergent business form does not take money from the customer directly, blurring the definition of customer.<p>I strongly agree that failure to stand for consumer rights is both learned helplessness and an apologist cooperator psychology. CA Voter here.
          • hyperhello55 minutes ago
            If we have no way to strike back, they will simply suck every drop of blood out the way you use every part of the buffalo. There is no way to escape Microsoft when they just buy everything and turn it into part of their garbage moat.
          • ruined56 minutes ago
            how does anyone expect to solve AI alignment when we can&#x27;t even solve corporate alignment
            • ktm5j51 minutes ago
              Life sure ain&#x27;t perfect.. not much you can do about that sometimes.
        • majorchord2 hours ago
          Can you provide evidence of these claims?
          • csomar2 hours ago
            I mean we are in the thread of evidence right now?
            • veverkap1 hour ago
              GitHub support is full of amazing, hard working people.<p>It is also comically understaffed. This is not because they can&#x27;t find people to work - it&#x27;s not given the budget necessary.
              • nikanj1 hour ago
                They might be amazing and hard working, but that doesn’t free them from the yoke of policy and script
      • elAhmo1 hour ago
        It is a problem they could solve if they want to. They have billions of profits per quarter.<p>They just don&#x27;t want to. Not malicious, just ignorant and disrespectful of their users.
      • rkagerer1 hour ago
        <i>I’m sure they are swamped with such requests</i><p>Then maybe they should be growing their customer support capacity along with their business. It drives me crazy how big companies have normalized cutting those departments down to anemic proportions. Especially those where you&#x27;re a paying customer.
        • someonebaggy20 minutes ago
          Remember when Google lost a lawsuit for defaming a business in their AI search results?
      • alightsoul1 hour ago
        YouTube already does it autonomously with seemingly no legal consequences for them because you agree to it in their tos
      • dogleash1 hour ago
        &gt;I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.<p>It&#x27;s malice from whoever is responsible for under-staffing. It&#x27;s also malice to prioritize the squeaky wheel for optics; it&#x27;s intentional to reduce the spread of the knowledge of how unresponsive they are.
      • vkou52 minutes ago
        &gt; I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.<p>Handling these requests at whatever scale they operate is their responsibility.<p>Nobody held a gun to their head and forced them to take on all of their customers.
    • elAhmo1 hour ago
      Describes pretty much any of the big companies. For example, I have seen numerous times people got their account locked on Google, or their app stuck in limbo at Apple, and then after post becomes viral all problems get solved.
      • latexr1 hour ago
        Apple in particular is mocked because they explicitly say (used to say?) “going to the press doesn’t help”, but they’ve shown time and again that it’s the most effective way to get them to take action.
    • a13n26 minutes ago
      How did you report this to GitHub? Your post shows an automated response from GitHub support. Did you follow GitHub&#x27;s documented instructions on reporting abuse? <a href="https:&#x2F;&#x2F;docs.github.com&#x2F;en&#x2F;communities&#x2F;maintaining-your-safety-on-github&#x2F;reporting-abuse-or-spam" rel="nofollow">https:&#x2F;&#x2F;docs.github.com&#x2F;en&#x2F;communities&#x2F;maintaining-your-safe...</a>
    • zamalek55 minutes ago
      For this specific case, a DMCA would have gotten you a much faster take down. As far as I can tell it&#x27;s automated. Sure, they could appeal it but then the malware nature of it would be in the crosshairs of the reviewer.<p>Not excusing their slow response, though.
    • ajmurmann2 hours ago
      It might not be a willingness issue as much as a bandwidth issue.
      • post-it2 hours ago
        Bandwidth can be bought with money, of which Microsoft made an extra $133.7 billion this year.
        • ajmurmann2 hours ago
          We know that coding agents have been pushing GH to its limits. Scaling is hard - especially staff. Maybe they aren&#x27;t trying to scale support but I think it&#x27;s reasonable to give them the benefit of doubt here, given what we know publicly
          • cwillu2 hours ago
            Microsoft is not some plucky upstart company with 12 employees and an unexpectedly popular product. We do not, in fact, need to give them the benefit of the doubt here.
          • dualvariable1 hour ago
            Having &quot;hackers&quot; on this site giving the benefit of doubt to companies clearing hundreds of billions of dollars in revenue per year will never cease to stop being ironic to me...
            • ChickeNES35 minutes ago
              On the site run by a VC firm? Why is that a shock? Besides, hacker does not mean being a kneejerking reactionary against corporations.
          • veverkap1 hour ago
            They aren&#x27;t trying to scale support. If anything, they are trying to throw AI at the problem. The support team is understaffed and overwhelmed.
          • iAMkenough2 hours ago
            That’s a self-inflicted issue they should have properly planned for.
          • cj2 hours ago
            You’re saying this is a problem money can’t solve?<p>There’s no need for benefit of the doubt when it comes to the level of support provided by tech companies.<p>Bad support by tech companies is a conscious profit-preserving choice.
        • whateveracct1 hour ago
          They have to dump all that free cash into data centers, sorry
        • kstrauser2 hours ago
          Never thought I&#x27;d see the day when Microsoft is elite.
        • NobodyNada2 hours ago
          Sounds like they can afford elite customer support.
      • iAMkenough2 hours ago
        Good thing HN provided them some bandwidth to do their jobs.
      • cyanydeez2 hours ago
        unwilling to provide proper support?<p>Just seems like a silly rational response to the same problem.
      • locknitpicker2 hours ago
        Yes,evidently bandwidth from HN unblocks takedown requests of malicious content.
        • ajmurmann2 hours ago
          Prioritization and escalation exists in most companies. I guarantee you that once an issue hits the HN front page, even engineers who might have totally different talks will get involved. (Never worked at GH or have talked to anyone there in years but this is how everything works pretty much everywhere)
          • toomuchtodo2 hours ago
            The public shaming will continue until the internal incentives improve. Make sure to drop that HN thread link into the internal task tracker y&#x27;all. Don&#x27;t forget to report to journalists if the severity warrants it (Brian Krebs, 404media, etc).<p>&quot;Show me the incentive and I&#x27;ll show you the outcome.&quot;
    • monster_truck1 hour ago
      They&#x27;re generally extremely quick about this if you ping ~anyone on the security team with the offending url and a link to the real repo. There is a long ongoing game of cat &amp; mouse against malware in repackaged things like first party windows utilities to leverage the signed binaries.
    • alightsoul1 hour ago
      This was not my experience at all. Someone on the bitchat android commented with a virus, reported it and was taken down 2 hours later
    • kachnuv_ocasek1 hour ago
      Hacker News saves the day once again!
    • ButlerianJihad1 hour ago
      &gt; need to get on the front page of HN<p>&gt; ping ~anyone on the security team<p>&gt; HN provided them some bandwidth<p>&gt; also works for Google support<p>&gt; answered within a day earlier this year<p>&gt; no reaction otherwise. It&#x27;s still online.<p>&gt; app stuck in limbo at Apple<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Cargo_cult_programming" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Cargo_cult_programming</a><p>&gt; given what we know publicly<p>&gt; thread of evidence<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Anecdotal_evidence" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Anecdotal_evidence</a>
    • nikanj1 hour ago
      Same goes for all companies bigger than a startup. The first line of support is AI, the second line is clueless, and the third level is powerless. HN is the only way to reach a human with both ability and willingness to help
    • hsuduebc22 hours ago
      Just send DMCA if you want their attention, they act harshly and quickly. Even when it&#x27;s false one.
      • ButlerianJihad52 minutes ago
        <a href="https:&#x2F;&#x2F;marksgray.com&#x2F;intellectual-property-law&#x2F;how-fraudulent-copyright-claims-are-censoring-free-speech-and-political-reporting&#x2F;" rel="nofollow">https:&#x2F;&#x2F;marksgray.com&#x2F;intellectual-property-law&#x2F;how-fraudule...</a><p>Fraud<p>Do the ends justify the means?<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Consequentialism" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Consequentialism</a>
  • wingerlang1 hour ago
    If GitHub staff is still reading this thread, maybe you can take down <a href="https:&#x2F;&#x2F;screenmemory.github.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;screenmemory.github.io&#x2F;</a> as well. I reported it 4 weeks ago, ticket ID 4703161
  • OCTAGRAM2 hours ago
    I recently found &quot;free&quot; version of Lossless Scaling on GitHub. The release installer is definitely malware. It took GitHub 3 days to shutdown malware distribution. Category of my ticket was malware report, not copyright infringe
    • hermitcrab1 hour ago
      Author here. I initially reported it as an imitation. A few days later I added evidence that it was malware.
  • nixgeek1 hour ago
    I see OP edited their post claiming getting to HN&#x27;s front helped.<p>I think the likelihood GitHub did something within 10 minutes of a post appearing on HN&#x27;s front page is approximately zero.<p>Nobody in GitHub Trust &amp; Safety is sat there watching HN.<p>An executive or communications professional who might have heard it got on HN, or seen it appear in a tool monitoring Microsoft and GitHub&#x27;s mentions across the internet, and who then flagged the post, Trust &amp; Safety would probably spend *more than 10 minutes* noticing the email or Teams message, then trying to find the right ticket internally. Then after locating the ticket you still have to investigate the facts, discuss, and click buttons to ban&#x2F;delete the user.<p>It&#x27;s (much) more likely this sat in a queue until someone got to it and the timing of it being on HN is a complete coincidence.
    • Sebguer7 minutes ago
      I think you wildly underestimate how much more empowered the people monitoring social media escalations are versus the standard front-line support. In a clear-cut case like this I can absolutely imagine someone getting pinged and pressing the &#x27;kill bad thing&#x27; button immediately after the post hitting the front page, because I&#x27;ve seen this happen many times.
    • hermitcrab1 hour ago
      It&#x27;s a hell of a coincidence.
    • hyperhello52 minutes ago
      It’s not a coincidence if they had already found the problem, wrote up the solution, primed it for action, and then it sat in some “management queue” for essentially forever, until someone called someone with a go.
  • Havoc2 hours ago
    They’re presumably too busy with keeping availability above nine sixes
  • icemanvault47 minutes ago
    These kinds of imitation attacks seem to be getting more common. It’s not just random malware anymore — some of them are getting surprisingly polished and even use the real product name and logo. Interesting (and a bit sad) how visibility on HN seems to speed things up on GitHub’s side.
  • bananamogul1 hour ago
    Three weeks? Try almost three years:<p><a href="https:&#x2F;&#x2F;lowendbox.com&#x2F;blog&#x2F;will-github-ever-remove-this-nulled-whmcs-repo&#x2F;" rel="nofollow">https:&#x2F;&#x2F;lowendbox.com&#x2F;blog&#x2F;will-github-ever-remove-this-null...</a>
  • joshuat2 hours ago
    Not exactly the same, but I&#x27;ve noticed a pretty sizable uptick in the number of spam&#x2F;scam PR comments being left on GitHub (and a longer delay before they&#x27;re removed after report).<p>Not the worst thing in the world, they&#x27;re easy to spot, but I&#x27;d like to see GitHub invest more time in protecting their users from falling victim to these bad actors.
  • msalihb1 hour ago
    I found a page that serving e-books I&#x27;ve purchased on github. It is a bit bad feeling
  • MBCook1 hour ago
    What do you know. Apple’s “never run to the media it never helps anything” rule works just as well with GitHub.
  • kg2 hours ago
    In the future just issue a DMCA takedown right away for cases like this, IMO.
  • revexos1 hour ago
    Seems like they don&#x27;t even care
  • hannob1 hour ago
    Welcome to the club!<p>There&#x27;s an impersonation profile of me on Github (username happyhannob). I&#x27;ve reported it a while ago, received the same automated message, and no reaction otherwise. It&#x27;s still online.<p>I guess you can&#x27;t expect basic fraud prevention from a company currently building the future with AI...
  • josefritzishere2 hours ago
    [dead]
  • jay737632 hours ago
    why would anyone host commercial binary software on github or any other third party domain?
    • hermitcrab2 hours ago
      Pirates and crackers generally don&#x27;t host stuff on their own domains. They don&#x27;t want to pay for the bandwidth and they don&#x27;t want to be traced.
      • sgskinner2 hours ago
        I think they’re alluding to OP not hosting their own downloads.
        • hermitcrab1 hour ago
          I am the OP. I host my own downloads on my own domain and nowhere else. Only the malicious imitation is hosted on Github.
  • someonebaggy2 hours ago
    If it&#x27;s your software send a DMCA. They have a legally required timeframe to process those. If it&#x27;s open source, however, then you don&#x27;t have any valid DMCA claim.
    • hnlmorg2 hours ago
      That’s not how open source works.<p>Open source code is still copyrighted. What the license defines is rights that people have in distributing that code. If an unofficial repository is using open source code to ship malware, and the license that software had didn’t allow that, then the unofficial repository is still breaking copyright law despite the code being open source.
      • someonebaggy1 hour ago
        There&#x27;s no open source license that prohibits derivative works that are malware.
        • whateveracct1 hour ago
          i think it&#x27;s in the spirit of it, which is enough for a DMCA lol
          • someonebaggy1 hour ago
            Um no, you have to send it about an actual copyright violation, not just because you don&#x27;t like something.<p>It&#x27;s not illegal to send an incorrect one by mistake but GitHub probably won&#x27;t process it. It&#x27;s illegal to send an incorrect one intentionally. Now that it&#x27;s been pointed out to you that making malware isn&#x27;t a copyright violation, it&#x27;s intentional if you send a DMCA anyway.
      • NewJazz2 hours ago
        Also open source license doesn&#x27;t grant use of trademarks, but I&#x27;m not sure that means DMCA applies.
    • 93po2 hours ago
      Code can be open source while the name and logos are copyrighted and still enforceable via DMCA
      • rpdillon1 hour ago
        You&#x27;re thinking of trademarks. Different body of law.<p>EDIT: e.g. <a href="https:&#x2F;&#x2F;www.mozilla.org&#x2F;en-US&#x2F;foundation&#x2F;trademarks&#x2F;policy&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.mozilla.org&#x2F;en-US&#x2F;foundation&#x2F;trademarks&#x2F;policy&#x2F;</a>
      • nomel37 minutes ago
        You can have copyright open source code, which is what allows open source licenses to enforce their terms. Open source doesn&#x27;t mean &quot;free to do whatever you want&quot;. There are very restrictive open source licenses, and you can deviate from the <i>common</i> open source licenses.<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Software_copyright" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Software_copyright</a>
      • someonebaggy1 hour ago
        Which project copyrighted its name and logo?