TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

GitHub censored my research data

361 pointsby doctorshadyover 8 years ago

44 comments

gwillemover 8 years ago
GL sent me this statement. For the record, I didn&#x27;t publish vulnerable systems, I published stores that have malware.<p>---<p>Willem,<p>GitLab has opted to remove the list of servers that you posted in your snippet. GitLab views the exposure of the vulnerable systems as egregious and will not abide it. While GiLab reserves the right take further action, up to and including termination (<a href="https:&#x2F;&#x2F;about.gitlab.com&#x2F;terms&#x2F;" rel="nofollow">https:&#x2F;&#x2F;about.gitlab.com&#x2F;terms&#x2F;</a>), we have chosen not to terminate or lock your account.<p>Please know this decision was not reached lightly and we appreciate your understanding on the matter.<p>Regards, GitLab<p>GitLab Support Team GitLab, Inc.
评论 #12714887 未加载
评论 #12713017 未加载
评论 #12715504 未加载
评论 #12713532 未加载
评论 #12713065 未加载
评论 #12713041 未加载
评论 #12713656 未加载
评论 #12719113 未加载
评论 #12719114 未加载
评论 #12713069 未加载
sh1392over 8 years ago
We at GitLab believe the author did not responsibly disclose this security information in a proper manner, and today we removed the list of hosts in accordance with our terms of service (<a href="https:&#x2F;&#x2F;about.gitlab.com&#x2F;terms&#x2F;" rel="nofollow">https:&#x2F;&#x2F;about.gitlab.com&#x2F;terms&#x2F;</a>).<p>The author says that he contacted &quot;about 30 merchants directly&quot;, but the published list includes over 1000 merchants. Most merchants were neither informed nor given a chance to respond in a timely manner. We did not feel comfortable hosting information that could be construed as an open invitation for malicious users to exploit.
评论 #12713066 未加载
评论 #12713159 未加载
评论 #12713026 未加载
评论 #12713044 未加载
评论 #12713576 未加载
评论 #12713023 未加载
评论 #12713038 未加载
评论 #12713030 未加载
评论 #12713084 未加载
评论 #12713007 未加载
评论 #12713614 未加载
评论 #12714052 未加载
评论 #12713087 未加载
评论 #12713974 未加载
评论 #12713863 未加载
评论 #12714111 未加载
评论 #12713691 未加载
评论 #12713024 未加载
ddeckover 8 years ago
Archive of the list on Gitlab which is now 404:<p><a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20161014133252&#x2F;https:&#x2F;&#x2F;gitlab.com&#x2F;gwillem&#x2F;public-snippets&#x2F;snippets&#x2F;28813" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20161014133252&#x2F;https:&#x2F;&#x2F;gitlab.co...</a>
评论 #12712982 未加载
评论 #12712899 未加载
Animatsover 8 years ago
Do this kind of thing on your own domain.<p>I have a list of major sites with currently active phishing pages.[1] This is basically a join of PhishTank and DMOZ. Nobody seems to be upset by that.<p>Google is at the top of the list because of their hosting business. It&#x27;s not just Google Sites. You can put a web site in a Google Spreadsheet cell, which Google doesn&#x27;t seem to check as a possible phishing site.<p>If you host for others, or offer a URL shortening service, you need automated checking against all available phishing lists or you will be exploited.<p>[1] <a href="http:&#x2F;&#x2F;sitetruth.com&#x2F;reports&#x2F;phishes.html" rel="nofollow">http:&#x2F;&#x2F;sitetruth.com&#x2F;reports&#x2F;phishes.html</a>
评论 #12713063 未加载
jrochkind1over 8 years ago
&gt; I understand that Github doesn’t have the resources to investigate each and every DMCA notice.<p>The DMCA as written really encourages no investigation whatsoever on the part of the service provider, this is pretty much how everyone acts. File a counter-notice with the service provider if you don&#x27;t think your content violates anyone&#x27;s copyright.<p>In this case, if Github took it down because of a DMCA notice, i think Github actually behaved _better_ than Gitlab. Github is simply following DMCA, if you file a counter-notice, they&#x27;ll probably restore it -- if they don&#x27;t, and say it&#x27;s not an issue of copyright, it&#x27;s just that they don&#x27;t want to host your material, then at that point they&#x27;ll be behaving similarly to Gitlab. Gitlab did not take it down because of a DMCA notice, they took it down because they decided it was &#x27;egregious&#x27; and they just didn&#x27;t want to host it.<p><a href="https:&#x2F;&#x2F;help.github.com&#x2F;articles&#x2F;guide-to-submitting-a-dmca-counter-notice&#x2F;" rel="nofollow">https:&#x2F;&#x2F;help.github.com&#x2F;articles&#x2F;guide-to-submitting-a-dmca-...</a><p>I can&#x27;t find any gitlab docs on filing a DMCA counter notice. Their DMCA policy at <a href="https:&#x2F;&#x2F;about.gitlab.com&#x2F;dmca&#x2F;" rel="nofollow">https:&#x2F;&#x2F;about.gitlab.com&#x2F;dmca&#x2F;</a> is short and solely targetted at those claiming infringement, there is no description of how to file a counter-notice.<p>In this case, I think github wins. The terrible parts of github&#x27;s counter-notice policy (10-14 days until your content comes back) is part of the DMCA law. Take it up with your congresspeople. <a href="http:&#x2F;&#x2F;io9.gizmodo.com&#x2F;the-dmca-how-it-works-and-how-its-abused-1616830093" rel="nofollow">http:&#x2F;&#x2F;io9.gizmodo.com&#x2F;the-dmca-how-it-works-and-how-its-abu...</a><p>However, reading OP again -- it&#x27;s not clear to me that Github took it down because of DMCA. They may simply be acting exactly like Gitlab, taking it down because they don&#x27;t want to host it, unrelated to DMCA. But I wanted to clear up some things about the DMCA, since OP mentioned it.
评论 #12716151 未加载
anondonover 8 years ago
How exactly does publishing a list of malware-infected stores fall under the DMCA? I always thought DMCA was meant to be for copyright infringement cases.<p>I didn&#x27;t see the list, but did it by any chance contain the logos of the online stores? If it did, the DMCA notices make sense.
评论 #12712763 未加载
评论 #12712760 未加载
评论 #12712758 未加载
gwillemover 8 years ago
Gitlab CEO just called me and apologized, will restore data shortly.<p>I am personally very sorry that GL got in a bad light here. They had misinterpreted my data and have acknowledged that. For comparison, I have heard nothing from GH over the last two days.<p>Gitlab, you rock.
评论 #12715532 未加载
评论 #12715501 未加载
评论 #12715494 未加载
sqldbaover 8 years ago
GitLab and GitHub are both pretty active on HN. I look forward to their response - where is it already?!<p>I&#x27;m especially disappointed by GL. GH is already too big to care about such things.
inlineintover 8 years ago
There is a service <a href="http:&#x2F;&#x2F;www.cryptograffiti.info&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.cryptograffiti.info&#x2F;</a> which can be used for posting sensitive information that should not be removed or hidden. It allows to write a message and store it in Bitcoin blockchain as a transaction. It costs near 0.0015 BTC or $1 per kB. Large files can be posted as magnet links to torrents with them.<p>Even if the service&#x27;s site had been shut down, everyone would always be able to obtain the transaction from it&#x27;s hash using any bitcoin client&#x2F;blockchain explorer, convert it to ASCII and read the text.<p>I&#x27;d like to note that it is worth to sign with GPG all messages posted that way in order to have ability to post updates and verify authorship.
yincrashover 8 years ago
After briefly looking at <a href="https:&#x2F;&#x2F;github.com&#x2F;github&#x2F;dmca&#x2F;tree&#x2F;master&#x2F;2016" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;github&#x2F;dmca&#x2F;tree&#x2F;master&#x2F;2016</a> there doesn&#x27;t appear to be any DMCA request for gwillem&#x27;s content, so maybe it wasn&#x27;t removed through the DMCA process?
eeeeeeeeeeeeeover 8 years ago
Definitely feels like a bad interpretation on Gitlab&#x27;s part, but not done out of malice.<p>The person was not exposing sites that nobody previously knew about -- the sites were already compromised, there is nothing to compromise again except maybe having more than one attacker in your compromised account. The damage is already done, though.<p>These are likely web applications that were not kept up to date so the responsible security disclosure already happened when it was reported for WordPress&#x2F;Drupal&#x2F;Joomla. It is the site owners responsibility to pay attention to those security disclosures, which they likely failed to do.<p>And those compromised sites, in my experience, are usually attacking and infecting other sites and servers on the Internet. That makes them a public nuisance and so public disclosure is necessary so they can be appropriately blocked&#x2F;isolated.
mattipover 8 years ago
Discussion of origin of the list here<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12707860" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12707860</a>
x1798DEover 8 years ago
Article doesn&#x27;t say that gitlab censored the list, though the gitlab link is a 404.<p>Also, are they actually using DMCA to get these lists taken down? If so, isn&#x27;t there some penalty for filing a false DMCA?
评论 #12712725 未加载
评论 #12712833 未加载
cweiske2over 8 years ago
List is at <a href="http:&#x2F;&#x2F;p.cweiske.de&#x2F;366" rel="nofollow">http:&#x2F;&#x2F;p.cweiske.de&#x2F;366</a>
ptmanover 8 years ago
For once, the Gitlab employees on HN don&#x27;t comment on a Gitlab-related story.
评论 #12713945 未加载
duncan_bayneover 8 years ago
Perhaps distributing this list is a use case for IPFS?<p><a href="https:&#x2F;&#x2F;ipfs.io&#x2F;docs&#x2F;getting-started&#x2F;" rel="nofollow">https:&#x2F;&#x2F;ipfs.io&#x2F;docs&#x2F;getting-started&#x2F;</a>
Pyxl101over 8 years ago
&gt; I understand that Github doesn’t have the resources to investigate each and every DMCA notice. However, it still took me by surprise that Github censors data so easily.<p>Send a counter-notification asserting that the data is not under copyright and have it put back up. Assuming this is really DMCA.
ChuckMcMover 8 years ago
So it seems the real bug here is that a site that is hosting malware is doing so because its actually vulnerable to being hacked, was hacked, and malware was installed. So posting the site name identifies a vulnerable site (which is wrong) and stops informing people that those sites have malware on them (which is an issue as well).<p>That is quite the catch 22. And of course many of the sites owners are clueless and don&#x27;t even know how to patch or fix their systems.<p>My isn&#x27;t that that a mess?
评论 #12713050 未加载
pdqover 8 years ago
Isn&#x27;t pastebin the correct site to post lists like this?
评论 #12712794 未加载
评论 #12712898 未加载
0xmohitover 8 years ago
Would be fun to see if the list is censored on Google docs.
评论 #12713987 未加载
r3blover 8 years ago
Isn&#x27;t it the whole point of GitLab that it&#x27;s decentralized? As in, you can roll your own instance and stop worrying about censorship?<p>I&#x27;m pretty sure someone here has a GitLab instance that is willing to share for this purpose.
评论 #12712832 未加载
评论 #12713966 未加载
ComodoHackerover 8 years ago
Back to the original problem of skimming.<p>I think the fastest way to get sites fixed is to run a script that crawls sites in the list, parses their Twitter and posts a warning there with link to original article.<p>Can someone help with that?
mankash666over 8 years ago
And just like that, we discover how helpless the average Joe is against corporate money.<p>Let&#x27;s crowdfund an AWS s3+CloudFront hosted site. DDosing that is no easy feat, and if corps do try it, the logs can prove their complicity, which has legal implications I presume
评论 #12714144 未加载
评论 #12713106 未加载
epalmerover 8 years ago
@gwillem thanks for doing this important investigative work.
bruce_oneover 8 years ago
As soon as I read this I assumed it was as a libel prevention method.<p>I&#x27;d be curious whether Gitlab&#x2F;hub could be held responsible for proving the accuracy of the claims? (That was my initial assumption as to the reason they were taken down.)
zimbatmover 8 years ago
Why is a third-party required to publish the list, couldn&#x27;t it be hosted on the blog post itself? That would have the advantage of being to archive the whole thing on a single page.
cyanbaneover 8 years ago
To be fair, maybe some automated method that hub&#x2F;lab owners have not vetted the data overall. I hope your list stays up&#x2F;public personally as long as you are willing to take responsibility for its upkeep. I wish there was some format to submit this list (and your responsibility for keeping up with it) to vendors on the lookout for this kinda stuff (up to them to decide inclusion).
blahblah12356over 8 years ago
Please post it to pastebin.com or something like that! put up a torrent I want to know which sites so i can steer clear of them.
juskreyover 8 years ago
What is the problem to publish on your own site?
评论 #12712981 未加载
评论 #12712919 未加载
vSanjoover 8 years ago
I don&#x27;t know enough about these kinds of situations yet to form a reasonable argument for-or-against. Is what was done considered a kind, favourable thing for the developers behind those sites or is it something that shouldn&#x27;t have been displayed?
评论 #12712740 未加载
vacriover 8 years ago
&quot;Moderated&quot;, not &quot;censored&quot;. Neither GitHub nor GitLab have stopped the message going out from outlets other than their own. Would we be comfortable calling the moderators here on HN &quot;censors&quot;?
stepik777over 8 years ago
I tried to pay in several of these shops. Most didn&#x27;t even had the functionality to pay with card. The only one in my sample where I was able to get to the payment form had redirected me to the proper payment gateway.
akerroover 8 years ago
<a href="http:&#x2F;&#x2F;gogsys33repvmfz5.onion&#x2F;" rel="nofollow">http:&#x2F;&#x2F;gogsys33repvmfz5.onion&#x2F;</a> Free gog git server in Tor.<p>Also, it will ask for an email on registration, but it isn&#x27;t verified and no email is sent.
leni536over 8 years ago
I wonder how google acts, if you dump the list here:<p><a href="https:&#x2F;&#x2F;www.google.com&#x2F;safebrowsing&#x2F;report_badware&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;safebrowsing&#x2F;report_badware&#x2F;</a>
评论 #12713175 未加载
beedogsover 8 years ago
Money talks. Uness it&#x27;s consumers&#x27; money being stolen, it seems.
rawfanover 8 years ago
Now I see. I thought this was a list of stores hacked through the current vulnerability. This is a list of stores hacked through 1-2y old vulnerabilities.
problemsover 8 years ago
Post it on a WordPress.com blog or host it on an OVH box or put it behind CloudFlare. All of these are quite censorship resistant in my experience.
iniminoover 8 years ago
The article states the lists were taken down but does not say why. Perhaps there will be an explanation forthcoming from Github or the researcher.
webjunkie01over 8 years ago
The only way this will get fixed is if a script is written to take advantage of the vulnerabilities and clean the sites affected.
blahblah12356over 8 years ago
Post it to Pastebin.com or make a torrent!
qwertyuiop924over 8 years ago
Well, as an absolute last resort, you can use Freenet or Dat to store your list.
franciscopover 8 years ago
Have you thought about contacting Adblockers or even Browsers? They might be interested in this data to block the sites for the average Joe.
评论 #12713125 未加载
lucaspillerover 8 years ago
I&#x27;m kind of with Gitlab on this one, just publishing a list of broken sites isn&#x27;t going to help them get fixed. Most of the owners probably barely know the Googles from the Facebooks, so even if you email them saying &#x27;you have this JavaScript thing that&#x27;s bad&#x27; they won&#x27;t understand and will blow you off.<p>OP doesn&#x27;t go into details of how they check the stores, but I&#x27;d assume they have some sort of script as they checked 255k. If that&#x27;s the case it would be trivial to send an automated email if malware is detected, and include links explaining how to fix it.<p>It won&#x27;t resolve everything but it&#x27;s a lot nicer than naming&amp;shaming businesses who have effectively done nothing wrong. What I mean is they probably hired a developer or team to build their website, and assumed that they would build a secure website - they didn&#x27;t go out purposely and find someone to build them a site that would be hacked.
评论 #12713284 未加载
评论 #12713070 未加载
评论 #12713057 未加载
评论 #12713572 未加载
评论 #12713257 未加载
评论 #12713132 未加载
评论 #12713114 未加载
评论 #12713148 未加载
formula_ningunaover 8 years ago
The malisious code on those websites isn&#x27;t your bussiness guys. If their owners wish not to respond and not fix it -- they have a right to do so. Why are you all so anxious? It has nothing to do with you all. Just don&#x27;t buy from them, that is simple.<p>Needless to say, I&#x27;ve seen most of those websites for the 1st time.<p>The world is unfair? No, it&#x27;s fair and this proves that it is fair.
评论 #12713884 未加载