Comment by hermitcrab
3 days ago
Author of the post here. Github finally took the offending page down approximately 10 minutes after the post appeared on the front page of HN. Total coincidence. I'm sure!
Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.
And it seems they are able to do things very quickly, when they want to. Bastards.
> Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.
This also works for Google support.
> And it seems they are able to do things very quickly, when they want to. Bastards.
I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
It was already a problem before agents could automatically perform these actions.
And it’s not something you can really automate on their end either. At least not the judgement call on the removal. Imagine if there was a fully automated process and it inadvertently took down a legit project.
> I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
Stalling in the hope that reporters won't escalate, instead of allocating a tiny bit of their billions in profit to hiring for this, is malicious in my book.
I had several small requests for moderation (deleting and banning spammers posting spam/crypto scam issues/PRs in my repos and ones I contribute to) answered within a day earlier this year after more than a decade of never needing to request moderation. I'm not defending GH here as it's obviously unacceptable that the OP's issue took this long, but they definitely do or at least did have mods. I would guess they need a lot more of them if something this serious went unaddressed, or maybe the ones I interacted with are now gone and have not been backfilled.
Can you provide evidence of these claims?
3 replies →
I mean.. for better or worse, this is how corporate America works. Hiring to solve a problem that's not costing them money (and solving it doesn't make money) is probably not going to happen, especially with the current state of the economy. They have more of an obligation to make money for their investors than they do anything else, that's just how it works.
22 replies →
>I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
It's malice from whoever is responsible for under-staffing. It's also malice to prioritize the squeaky wheel for optics; it's intentional to reduce the spread of the knowledge of how unresponsive they are.
I’m sure they are swamped with such requests
Then maybe they should be growing their customer support capacity along with their business. It drives me crazy how big companies have normalized cutting those departments down to anemic proportions. Especially those where you're a paying customer.
Remember when Google lost a lawsuit for defaming a business in their AI search results?
Unfortunately this is very true. It often takes someone pretty high up on the food chain to see it on HN, X, or get an email/LinkedIn message asking about something for it to become a priority.
I don't see that changing for any of the large companies unfortunately, anytime soon.
YouTube already does it autonomously with seemingly no legal consequences for them because you agree to it in their tos
YouTube also totally fails to remove obvious fraud videos, even ones they mark verified. (If someone takes over a verified channel and renames it, they keep the verified flag). -- also with no legal consequences.
> I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
Handling these requests at whatever scale they operate is their responsibility.
Nobody held a gun to their head and forced them to take on all of their customers.
It is a problem they could solve if they want to. They have billions of profits per quarter.
They just don't want to. Not malicious, just ignorant and disrespectful of their users.
Describes pretty much any of the big companies. For example, I have seen numerous times people got their account locked on Google, or their app stuck in limbo at Apple, and then after post becomes viral all problems get solved.
Apple in particular is mocked because they explicitly say (used to say?) “going to the press doesn’t help”, but they’ve shown time and again that it’s the most effective way to get them to take action.
For this specific case, a DMCA would have gotten you a much faster take down. As far as I can tell it's automated. Sure, they could appeal it but then the malware nature of it would be in the crosshairs of the reviewer.
Not excusing their slow response, though.
It might not be a willingness issue as much as a bandwidth issue.
Bandwidth can be bought with money, of which Microsoft made an extra $133.7 billion this year.
We know that coding agents have been pushing GH to its limits. Scaling is hard - especially staff. Maybe they aren't trying to scale support but I think it's reasonable to give them the benefit of doubt here, given what we know publicly
10 replies →
They have to dump all that free cash into data centers, sorry
Never thought I'd see the day when Microsoft is elite.
Sounds like they can afford elite customer support.
1 reply →
I have for a long time said that the way to regulate these huge companies would be to have government-mandated SLOs for live support.
For example (simplified), if a user makes a call, a person with sufficient privileges to handle 90% of the cases should answer on the other end within 2 minutes. If the case cannot be handled, the higher-up with privileges to handle 99% of the cases should be reached within 5 minutes. And to be fair, it should be mandated for all companies, not only FAANG-like.
But a company like Meta (for example) with a billion customers would then have to decide whether they want to work on quality improvements for their services or whether they would like to hire a million technical support staff.
If users value support so much, you should start a competitor with excellent support. I suspect though that very few users are willing to pay the additional cost.
2 replies →
Good thing HN provided them some bandwidth to do their jobs.
unwilling to provide proper support?
Just seems like a silly rational response to the same problem.
Yes,evidently bandwidth from HN unblocks takedown requests of malicious content.
Prioritization and escalation exists in most companies. I guarantee you that once an issue hits the HN front page, even engineers who might have totally different talks will get involved. (Never worked at GH or have talked to anyone there in years but this is how everything works pretty much everywhere)
2 replies →
They're generally extremely quick about this if you ping ~anyone on the security team with the offending url and a link to the real repo. There is a long ongoing game of cat & mouse against malware in repackaged things like first party windows utilities to leverage the signed binaries.
>if you ping ~anyone on the security team
And how I am supposed to know who they are or how to reach them?
In violation of their own name-squatting policy, Github has refused to rename or remove an account that is squatting my legal name even after I sent them a scan of my ID proving that it is my legal name.
Unfortunately drawing attention to it would likely invoke the Streissand effect and be counter productive so I can only wait until the frabjous day that github goes dark at last.
How did you report this to GitHub? Your post shows an automated response from GitHub support. Did you follow GitHub's documented instructions on reporting abuse? https://docs.github.com/en/communities/maintaining-your-safe...
Same goes for all companies bigger than a startup. The first line of support is AI, the second line is clueless, and the third level is powerless. HN is the only way to reach a human with both ability and willingness to help
This was not my experience at all. Someone on the bitchat android commented with a virus, reported it and was taken down 2 hours later
Love the conclusion at the end, because it summarizes GitHub leadership pretty well.
Just send DMCA if you want their attention, they act harshly and quickly. Even when it's false one.
https://marksgray.com/intellectual-property-law/how-fraudule...
Fraud
Do the ends justify the means?
https://en.wikipedia.org/wiki/Consequentialism
What? This is what the DMCA was designed for. How would it be fraud?
[dead]
what is surprising that's most big companies, post on social media and they start caring. probably because they get a bunch of spam in their reports and it's hard to filter through.
Hacker News saves the day once again!
> need to get on the front page of HN
> ping ~anyone on the security team
> HN provided them some bandwidth
> also works for Google support
> answered within a day earlier this year
> no reaction otherwise. It's still online.
> app stuck in limbo at Apple
https://en.wikipedia.org/wiki/Cargo_cult_programming
> given what we know publicly
> thread of evidence
https://en.wikipedia.org/wiki/Anecdotal_evidence