Author of the post here. Github finally took the offending page down approximately 10 minutes after the post appeared on the front page of HN. Total coincidence. I'm sure!
Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.
And it seems they are able to do things very quickly, when they want to. Bastards.
> Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.
This also works for Google support.
> And it seems they are able to do things very quickly, when they want to. Bastards.
I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
It was already a problem before agents could automatically perform these actions.
And it’s not something you can really automate on their end either. At least not the judgement call on the removal. Imagine if there was a fully automated process and it inadvertently took down a legit project.
> I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
Stalling in the hope that reporters won't escalate, instead of allocating a tiny bit of their billions in profit to hiring for this, is malicious in my book.
>I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
It's malice from whoever is responsible for under-staffing. It's also malice to prioritize the squeaky wheel for optics; it's intentional to reduce the spread of the knowledge of how unresponsive they are.
Then maybe they should be growing their customer support capacity along with their business. It drives me crazy how big companies have normalized cutting those departments down to anemic proportions. Especially those where you're a paying customer.
Unfortunately this is very true. It often takes someone pretty high up on the food chain to see it on HN, X, or get an email/LinkedIn message asking about something for it to become a priority.
I don't see that changing for any of the large companies unfortunately, anytime soon.
Describes pretty much any of the big companies. For example, I have seen numerous times people got their account locked on Google, or their app stuck in limbo at Apple, and then after post becomes viral all problems get solved.
Apple in particular is mocked because they explicitly say (used to say?) “going to the press doesn’t help”, but they’ve shown time and again that it’s the most effective way to get them to take action.
For this specific case, a DMCA would have gotten you a much faster take down. As far as I can tell it's automated. Sure, they could appeal it but then the malware nature of it would be in the crosshairs of the reviewer.
I have for a long time said that the way to regulate these huge companies would be to have government-mandated SLOs for live support.
For example (simplified), if a user makes a call, a person with sufficient privileges to handle 90% of the cases should answer on the other end within 2 minutes. If the case cannot be handled, the higher-up with privileges to handle 99% of the cases should be reached within 5 minutes. And to be fair, it should be mandated for all companies, not only FAANG-like.
But a company like Meta (for example) with a billion customers would then have to decide whether they want to work on quality improvements for their services or whether they would like to hire a million technical support staff.
They're generally extremely quick about this if you ping ~anyone on the security team with the offending url and a link to the real repo. There is a long ongoing game of cat & mouse against malware in repackaged things like first party windows utilities to leverage the signed binaries.
In violation of their own name-squatting policy, Github has refused to rename or remove an account that is squatting my legal name even after I sent them a scan of my ID proving that it is my legal name.
Unfortunately drawing attention to it would likely invoke the Streissand effect and be counter productive so I can only wait until the frabjous day that github goes dark at last.
Same goes for all companies bigger than a startup. The first line of support is AI, the second line is clueless, and the third level is powerless. HN is the only way to reach a human with both ability and willingness to help
what is surprising that's most big companies, post on social media and they start caring. probably because they get a bunch of spam in their reports and it's hard to filter through.
If GitHub staff is still reading this thread, maybe you can take down https://screenmemory.github.io/ as well. I reported it 4 weeks ago, ticket ID 4703161
Please give GitHub some slack, just check out the massive number of copilot changes they've had to release over the last 3 weeks (https://github.blog/changelog/). There's clearly little time left for security, maintenance, or reliability work.
I recently found "free" version of Lossless Scaling on GitHub. The release installer is definitely malware. It took GitHub 3 days to shutdown malware distribution. Category of my ticket was malware report, not copyright infringe
Lack of moderation is an issue everywhere, because there are few consequences for the platforms.
Booking.com kept a clearly fraudulent listing (images clearly stolen from another Booking.com listing with mirroring + some filters) fully online for at least two days (I got distracted and stopped taking daily screenshots after that). I just got a response that they've taken it down almost 10 days after I had initially reported it (although I think they marked it as not bookable some time before that).
Not exactly the same, but I've noticed a pretty sizable uptick in the number of spam/scam PR comments being left on GitHub (and a longer delay before they're removed after report).
Not the worst thing in the world, they're easy to spot, but I'd like to see GitHub invest more time in protecting their users from falling victim to these bad actors.
These kinds of imitation attacks seem to be getting more common. It’s not just random malware anymore — some of them are getting surprisingly polished and even use the real product name and logo.
Interesting (and a bit sad) how visibility on HN seems to speed things up on GitHub’s side.
There's an impersonation profile of me on Github (username happyhannob). I've reported it a while ago, received the same automated message, and no reaction otherwise. It's still online.
I guess you can't expect basic fraud prevention from a company currently building the future with AI...
grindr has been dishing out popup virus and phishing ads for two years and multiple support requests to Google play and Grindr support are like it's a third party ad provider
If it's your software send a DMCA. They have a legally required timeframe to process those. If it's open source, however, then you don't have any valid DMCA claim.
Open source code is still copyrighted. What the license defines is rights that people have in distributing that code. If an unofficial repository is using open source code to ship malware, and the license that software had didn’t allow that, then the unofficial repository is still breaking copyright law despite the code being open source.
You can have copyright open source code, which is what allows open source licenses to enforce their terms. Open source doesn't mean "free to do whatever you want". There are very restrictive open source licenses, and you can deviate from the common open source licenses.
I see OP edited their post claiming getting to HN's front helped.
I think the likelihood GitHub did something within 10 minutes of a post appearing on HN's front page is approximately zero.
Nobody in GitHub Trust & Safety is sat there watching HN.
An executive or communications professional who might have heard it got on HN, or seen it appear in a tool monitoring Microsoft and GitHub's mentions across the internet, and who then flagged the post, Trust & Safety would probably spend *more than 10 minutes* noticing the email or Teams message, then trying to find the right ticket internally. Then after locating the ticket you still have to investigate the facts, discuss, and click buttons to ban/delete the user.
It's (much) more likely this sat in a queue until someone got to it and the timing of it being on HN is a complete coincidence.
I think you wildly underestimate how much more empowered the people monitoring social media escalations are versus the standard front-line support. In a clear-cut case like this I can absolutely imagine someone getting pinged and pressing the 'kill bad thing' button immediately after the post hitting the front page, because I've seen this happen many times.
It’s not a coincidence if they had already found the problem, wrote up the solution, primed it for action, and then it sat in some “management queue” for essentially forever, until someone called someone with a go.
Author of the post here. Github finally took the offending page down approximately 10 minutes after the post appeared on the front page of HN. Total coincidence. I'm sure!
Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.
And it seems they are able to do things very quickly, when they want to. Bastards.
> Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.
This also works for Google support.
> And it seems they are able to do things very quickly, when they want to. Bastards.
I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
It was already a problem before agents could automatically perform these actions.
And it’s not something you can really automate on their end either. At least not the judgement call on the removal. Imagine if there was a fully automated process and it inadvertently took down a legit project.
> I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
Stalling in the hope that reporters won't escalate, instead of allocating a tiny bit of their billions in profit to hiring for this, is malicious in my book.
28 replies →
>I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
It's malice from whoever is responsible for under-staffing. It's also malice to prioritize the squeaky wheel for optics; it's intentional to reduce the spread of the knowledge of how unresponsive they are.
I’m sure they are swamped with such requests
Then maybe they should be growing their customer support capacity along with their business. It drives me crazy how big companies have normalized cutting those departments down to anemic proportions. Especially those where you're a paying customer.
1 reply →
Unfortunately this is very true. It often takes someone pretty high up on the food chain to see it on HN, X, or get an email/LinkedIn message asking about something for it to become a priority.
I don't see that changing for any of the large companies unfortunately, anytime soon.
YouTube already does it autonomously with seemingly no legal consequences for them because you agree to it in their tos
1 reply →
> I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
Handling these requests at whatever scale they operate is their responsibility.
Nobody held a gun to their head and forced them to take on all of their customers.
It is a problem they could solve if they want to. They have billions of profits per quarter.
They just don't want to. Not malicious, just ignorant and disrespectful of their users.
Describes pretty much any of the big companies. For example, I have seen numerous times people got their account locked on Google, or their app stuck in limbo at Apple, and then after post becomes viral all problems get solved.
Apple in particular is mocked because they explicitly say (used to say?) “going to the press doesn’t help”, but they’ve shown time and again that it’s the most effective way to get them to take action.
For this specific case, a DMCA would have gotten you a much faster take down. As far as I can tell it's automated. Sure, they could appeal it but then the malware nature of it would be in the crosshairs of the reviewer.
Not excusing their slow response, though.
It might not be a willingness issue as much as a bandwidth issue.
Bandwidth can be bought with money, of which Microsoft made an extra $133.7 billion this year.
15 replies →
I have for a long time said that the way to regulate these huge companies would be to have government-mandated SLOs for live support.
For example (simplified), if a user makes a call, a person with sufficient privileges to handle 90% of the cases should answer on the other end within 2 minutes. If the case cannot be handled, the higher-up with privileges to handle 99% of the cases should be reached within 5 minutes. And to be fair, it should be mandated for all companies, not only FAANG-like.
But a company like Meta (for example) with a billion customers would then have to decide whether they want to work on quality improvements for their services or whether they would like to hire a million technical support staff.
3 replies →
Good thing HN provided them some bandwidth to do their jobs.
unwilling to provide proper support?
Just seems like a silly rational response to the same problem.
Yes,evidently bandwidth from HN unblocks takedown requests of malicious content.
3 replies →
They're generally extremely quick about this if you ping ~anyone on the security team with the offending url and a link to the real repo. There is a long ongoing game of cat & mouse against malware in repackaged things like first party windows utilities to leverage the signed binaries.
>if you ping ~anyone on the security team
And how I am supposed to know who they are or how to reach them?
1 reply →
In violation of their own name-squatting policy, Github has refused to rename or remove an account that is squatting my legal name even after I sent them a scan of my ID proving that it is my legal name.
Unfortunately drawing attention to it would likely invoke the Streissand effect and be counter productive so I can only wait until the frabjous day that github goes dark at last.
How did you report this to GitHub? Your post shows an automated response from GitHub support. Did you follow GitHub's documented instructions on reporting abuse? https://docs.github.com/en/communities/maintaining-your-safe...
Same goes for all companies bigger than a startup. The first line of support is AI, the second line is clueless, and the third level is powerless. HN is the only way to reach a human with both ability and willingness to help
This was not my experience at all. Someone on the bitchat android commented with a virus, reported it and was taken down 2 hours later
Love the conclusion at the end, because it summarizes GitHub leadership pretty well.
Just send DMCA if you want their attention, they act harshly and quickly. Even when it's false one.
https://marksgray.com/intellectual-property-law/how-fraudule...
Fraud
Do the ends justify the means?
https://en.wikipedia.org/wiki/Consequentialism
2 replies →
what is surprising that's most big companies, post on social media and they start caring. probably because they get a bunch of spam in their reports and it's hard to filter through.
Hacker News saves the day once again!
> need to get on the front page of HN
> ping ~anyone on the security team
> HN provided them some bandwidth
> also works for Google support
> answered within a day earlier this year
> no reaction otherwise. It's still online.
> app stuck in limbo at Apple
https://en.wikipedia.org/wiki/Cargo_cult_programming
> given what we know publicly
> thread of evidence
https://en.wikipedia.org/wiki/Anecdotal_evidence
If GitHub staff is still reading this thread, maybe you can take down https://screenmemory.github.io/ as well. I reported it 4 weeks ago, ticket ID 4703161
Please give GitHub some slack, just check out the massive number of copilot changes they've had to release over the last 3 weeks (https://github.blog/changelog/). There's clearly little time left for security, maintenance, or reliability work.
I recently found "free" version of Lossless Scaling on GitHub. The release installer is definitely malware. It took GitHub 3 days to shutdown malware distribution. Category of my ticket was malware report, not copyright infringe
Author here. I initially reported it as an imitation. A few days later I added evidence that it was malware.
They’re presumably too busy with keeping availability above nine sixes
Three weeks? Try almost three years:
https://lowendbox.com/blog/will-github-ever-remove-this-null...
Lack of moderation is an issue everywhere, because there are few consequences for the platforms.
Booking.com kept a clearly fraudulent listing (images clearly stolen from another Booking.com listing with mirroring + some filters) fully online for at least two days (I got distracted and stopped taking daily screenshots after that). I just got a response that they've taken it down almost 10 days after I had initially reported it (although I think they marked it as not bookable some time before that).
Not exactly the same, but I've noticed a pretty sizable uptick in the number of spam/scam PR comments being left on GitHub (and a longer delay before they're removed after report).
Not the worst thing in the world, they're easy to spot, but I'd like to see GitHub invest more time in protecting their users from falling victim to these bad actors.
In the future just issue a DMCA takedown right away for cases like this, IMO.
These kinds of imitation attacks seem to be getting more common. It’s not just random malware anymore — some of them are getting surprisingly polished and even use the real product name and logo. Interesting (and a bit sad) how visibility on HN seems to speed things up on GitHub’s side.
I found a page that serving e-books I've purchased on github. It is a bit bad feeling
If they were using your logo, you could have sent a DMCA takedown notice. That would have likely gotten a faster, more serious response.
Welcome to the club!
There's an impersonation profile of me on Github (username happyhannob). I've reported it a while ago, received the same automated message, and no reaction otherwise. It's still online.
I guess you can't expect basic fraud prevention from a company currently building the future with AI...
What do you know. Apple’s “never run to the media it never helps anything” rule works just as well with GitHub.
grindr has been dishing out popup virus and phishing ads for two years and multiple support requests to Google play and Grindr support are like it's a third party ad provider
Seems like they don't even care
[dead]
why would anyone host commercial binary software on github or any other third party domain?
Pirates and crackers generally don't host stuff on their own domains. They don't want to pay for the bandwidth and they don't want to be traced.
I think they’re alluding to OP not hosting their own downloads.
1 reply →
If it's your software send a DMCA. They have a legally required timeframe to process those. If it's open source, however, then you don't have any valid DMCA claim.
That’s not how open source works.
Open source code is still copyrighted. What the license defines is rights that people have in distributing that code. If an unofficial repository is using open source code to ship malware, and the license that software had didn’t allow that, then the unofficial repository is still breaking copyright law despite the code being open source.
There's no open source license that prohibits derivative works that are malware.
2 replies →
Also open source license doesn't grant use of trademarks, but I'm not sure that means DMCA applies.
Code can be open source while the name and logos are copyrighted and still enforceable via DMCA
You're thinking of trademarks. Different body of law.
EDIT: e.g. https://www.mozilla.org/en-US/foundation/trademarks/policy/
1 reply →
You can have copyright open source code, which is what allows open source licenses to enforce their terms. Open source doesn't mean "free to do whatever you want". There are very restrictive open source licenses, and you can deviate from the common open source licenses.
https://en.wikipedia.org/wiki/Software_copyright
Which project copyrighted its name and logo?
1 reply →
I see OP edited their post claiming getting to HN's front helped.
I think the likelihood GitHub did something within 10 minutes of a post appearing on HN's front page is approximately zero.
Nobody in GitHub Trust & Safety is sat there watching HN.
An executive or communications professional who might have heard it got on HN, or seen it appear in a tool monitoring Microsoft and GitHub's mentions across the internet, and who then flagged the post, Trust & Safety would probably spend *more than 10 minutes* noticing the email or Teams message, then trying to find the right ticket internally. Then after locating the ticket you still have to investigate the facts, discuss, and click buttons to ban/delete the user.
It's (much) more likely this sat in a queue until someone got to it and the timing of it being on HN is a complete coincidence.
I think you wildly underestimate how much more empowered the people monitoring social media escalations are versus the standard front-line support. In a clear-cut case like this I can absolutely imagine someone getting pinged and pressing the 'kill bad thing' button immediately after the post hitting the front page, because I've seen this happen many times.
It’s not a coincidence if they had already found the problem, wrote up the solution, primed it for action, and then it sat in some “management queue” for essentially forever, until someone called someone with a go.
It's a hell of a coincidence.
"Nobody in GitHub Trust & Safety is sat there watching HN"
Please, any competent software dev business has eyes on this page on an hourly basis.
I'm in aerospace and we're crawling on this site, all the way at the top levels.
the timing of it being on HN is a complete coincidence.
The lengths people will go to "never attribute to malice..." are pretty impressive in these days of baldly stated or visible malice from the top.
The last decade has taken the edge off Hanlon's razor.