TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

GitHub shuts off access to Aurelia repository, citing trade sanctions

508 pointsby gortokabout 5 years ago

41 comments

natfriedmanabout 5 years ago
Hi HN, I&#x27;m the CEO of GitHub. Flagging this account was obviously a terrible mistake, and I apologize to anyone who was affected by it. We&#x27;re investigating why it occurred and will make changes to make sure it doesn&#x27;t happen again. I am glad that we restored access to the account in less than an hour after Aurelia filed their appeal.<p>For context on why any account flagging is ever necessary, unfortunately, every company in the world is required to comply with US sanctions if they do any business at all in the United States, e.g. serving US-based customers. This includes even interacting with US banking infrastructure. So being headquartered somewhere else doesn&#x27;t help; you have to comply. And US sanctions as written do not allow us to provide commercial services or services which could be used commercially to sanctioned countries.<p>We are taking the broadest possible interpretation of US sanctions law to allow as much access to GitHub as possible and we are, as far as I know, the only major vendor to offer public repo access in US-sanctioned countries like Iran, Syria, and Cuba. I&#x27;m proud that we are taking this strong position to ensure developers everywhere can participate in open source.<p>I wish we could also offer access to private repos and still comply with government requirements. We have been advocating and will continue to advocate for broader developer access with the various government agencies involved.
评论 #22630846 未加载
评论 #22630532 未加载
评论 #22630429 未加载
评论 #22630678 未加载
评论 #22631360 未加载
评论 #22636773 未加载
评论 #22630480 未加载
评论 #22630702 未加载
评论 #22632578 未加载
评论 #22630433 未加载
评论 #22632483 未加载
评论 #22630397 未加载
评论 #22631543 未加载
评论 #22630883 未加载
评论 #22633786 未加载
评论 #22630610 未加载
评论 #22630760 未加载
评论 #22630742 未加载
EisenbergEffectabout 5 years ago
GitHub has corrected the issue, restoring our organization access and web site. They have reported that the org was flagged as part of an automated process. The flagging occurred because we have two external contributors from Iran (non GH org members). They told me that there should have been a warning and they are investigating why that didn&#x27;t happen. The CEO of GitHub also reached out personally to try to speedily rectify the situation.
评论 #22630861 未加载
评论 #22631473 未加载
评论 #22630729 未加载
评论 #22631805 未加载
评论 #22630701 未加载
firloopabout 5 years ago
This is pure speculation, but it seems that GitHub&#x27;s ownership by Microsoft causes them to be significantly more strict with the types of content that they are comfortable hosting. Expect this to continue as they expand up and down the stack; once their npm acquisition closes you&#x27;ll see this there too.<p>I think this should be a wake-up call to anyone staking their open source project on GitHub — if I let someone from a US sanctioned country contribute to my repo will I be banned? Hopefully mindshare moves to alternatives in due time.
评论 #22629326 未加载
评论 #22629306 未加载
评论 #22629840 未加载
评论 #22631976 未加载
评论 #22629676 未加载
评论 #22631140 未加载
评论 #22632553 未加载
评论 #22629645 未加载
评论 #22631229 未加载
评论 #22631298 未加载
评论 #22659771 未加载
评论 #22629974 未加载
评论 #22629671 未加载
antoncohenabout 5 years ago
What frustrates me about these kind of things is how impersonal they are. How many orgs&#x2F;users does GitHub sanction a day? Too many for it to be able to email the users and ask clarifying questions? Or even have a human dig in and double check what the algorithm says.<p>Basic human interaction would seemingly solve 99% of false account lockouts and takedowns. Even basic heuristics like this org has a repo with 11,000 stars, it isn&#x27;t a new user that just signed up yesterday, we need to look into this deeper.
评论 #22629680 未加载
评论 #22630430 未加载
评论 #22629961 未加载
评论 #22629921 未加载
tastroderabout 5 years ago
Let&#x27;s take a moment and appreciate the copy and paste support response &quot;If a user or organization believes that they have been flagged in error, then that user or organization owner has the opportunity to appeal the flag by providing verification information to GitHub. Please see our FAQ for the appeals request form.&quot; <a href="https:&#x2F;&#x2F;twitter.com&#x2F;GitHubHelp&#x2F;status&#x2F;1240682163193942018" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;GitHubHelp&#x2F;status&#x2F;1240682163193942018</a><p>Is that an official GH account? It&#x27;s old and the answers look legitimate but that one is certainly a really off-putting reaction.
评论 #22630689 未加载
评论 #22630108 未加载
评论 #22630025 未加载
droopyEyelidsabout 5 years ago
Have black hat people figured out what triggers this yet?<p>Looks like a new attack, where you make a few contributions to a project, then start proxying your logins through Iran for a while till everything you touch shuts down.
vascoabout 5 years ago
Sanctions for online services are one of the worst things about working in this industry. Being forced to implement and maintain technical solutions to block access to every day citizens of certain regions because some guys in suits decided these are second tier humans is demoralizing as hell.<p>How are people supposed to rise up and depose or vote for less tyranical governments if they cannot access information, or use services that&#x27;ll boost their businesses in the global market? Having had to implement things like this myself in the past, I just feel like puking when I do it.<p>And don&#x27;t think about just ignoring these, as soon as you get bigger than tiny, your bank will threaten to freeze all your accounts and stop doing business with you if for some reason you let some Crimean or Iranian get onto your service and pay you for it.<p>What exactly is the plan? Are we expecting that individuals who disagree with their regimes would leave their country and their families? It just feels like cold blooded retribution with no care for the regular every day population.
评论 #22629941 未加载
评论 #22630129 未加载
评论 #22629939 未加载
评论 #22630207 未加载
评论 #22630181 未加载
评论 #22630238 未加载
评论 #22630567 未加载
评论 #22630122 未加载
评论 #22630151 未加载
cfvabout 5 years ago
Without even delving on the perverse sanctions part, it should never be forgotten that the <i>whole point</i> of git is that it&#x27;s a distributed source control system. Grab your source and move it elsewhere. Heck, even an old forked gitlab community instance should work.<p>Github is good for the exposure, but it&#x27;s their house, and so their rules apply, not ours. Don&#x27;t rely on them to always be OK with you staying.
评论 #22630131 未加载
bartreadabout 5 years ago
WTH? GitHub is owned by Microsoft. Rob Eisenberg, who posted that tweet, works for Microsoft.<p>There&#x27;s so much about this I don&#x27;t get, not least of which is the fact that despite what the headline suggests, along with the amount of bile still being spewed on this thread, Aurelia is back up and running, as are all its repos: <a href="https:&#x2F;&#x2F;aurelia.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;aurelia.io&#x2F;</a>, <a href="https:&#x2F;&#x2F;github.com&#x2F;aurelia" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;aurelia</a>.<p>So, yes, GitHub properly effed up here, but they do at least appear to have backpedalled and fixed the problem quickly.
评论 #22631123 未加载
kujaomegaabout 5 years ago
Seems that Github has automated some repository banning actions.<p>3 days ago, the author of a repo got removed his account without reason and hours later got his account reactivated (<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=22593595" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=22593595</a>), after posting to hackernews.<p>As we see, the Aurelia repository were also removed, and hours later reactivated.<p>What caught my attention is that the banned user is from Russia and that Aurelia repository has got developers from Iran.<p>Is this a sign of Github country discrimination? Or is this a sign of Machine learning bias?
评论 #22630336 未加载
mrastroabout 5 years ago
I can empathize that GitHub has to abide by laws more stringently now that it&#x27;s part of Microsoft but oh boy does it&#x27;s automatic flagging system need work.<p>One day I was randomly permanently banned because a hacker starred some of my public repos from hacked accounts (only ~6 stars btw). I had no involvement whatsoever, it was likely an attempt by the hacker to dilute the target of the repos they were trying to star. It took me ~2 weeks to appeal and they still blamed me for hacking even though the IPs of those accounts were different. My ban was eventually lifted but I doubt their system works nearly as well as it should.
jtokophabout 5 years ago
It looks to be restored: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;EisenbergEffect&#x2F;status&#x2F;1240700062939791362?s=20" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;EisenbergEffect&#x2F;status&#x2F;12407000629397913...</a>
评论 #22630382 未加载
kylecordesabout 5 years ago
What a debacle. If GitHub believes this is necessary to comply with sanctions, they should provide a &quot;rather than shut me down, please block contributions that GitHub would consider sanctioned” switch.
评论 #22629688 未加载
评论 #22629943 未加载
iamleppertabout 5 years ago
So disgusting their response: &quot;If a user&quot;<p>Addressing someone in the third person is about a far from empathy as one could get. Clearly, the signal is strong to begin the exodus from Github as soon as practical.<p>They can no longer be trusted, and are no longer developer friendly.
ISLabout 5 years ago
What is Aurelia? Why would it be sanctioned?
评论 #22629409 未加载
评论 #22629416 未加载
评论 #22629532 未加载
评论 #22629417 未加载
评论 #22629399 未加载
评论 #22629413 未加载
评论 #22630259 未加载
评论 #22629692 未加载
评论 #22629422 未加载
scalableUniconabout 5 years ago
And I just finished setting up gitea(<a href="https:&#x2F;&#x2F;gitea.io&#x2F;en-us&#x2F;" rel="nofollow">https:&#x2F;&#x2F;gitea.io&#x2F;en-us&#x2F;</a>) on my server and mirrored all my repos. An elegant piece of software, setup was straightforward and took less than an hour.
Toucheabout 5 years ago
What am I missing? Seems fine to me: <a href="https:&#x2F;&#x2F;github.com&#x2F;aurelia&#x2F;framework" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;aurelia&#x2F;framework</a>
评论 #22629793 未加载
评论 #22629759 未加载
emptysongglassabout 5 years ago
If people just used git the way it was intended, as a decentralized protocol for editing and sending patches by email, we wouldn&#x27;t have this issue. See <a href="https:&#x2F;&#x2F;git-send-email.io" rel="nofollow">https:&#x2F;&#x2F;git-send-email.io</a>
dwheelerabout 5 years ago
This looks like a terrible but honest mistake. The repo is already back, after something like an hour and a half. The . io website is not back yet, but I suspect that takes a moment to get back running.
评论 #22630057 未加载
forkLdingabout 5 years ago
Weirdest part of this is that the Lead Developer at Aurelia and the guy who posted this on twitter works at Microsoft which again is weird now that Github is part of Microsoft.
peterkellyabout 5 years ago
And they&#x27;ve just bought npm!<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=22594549" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=22594549</a>
adultSwimabout 5 years ago
Note: sanctions against Iran are preventing them from buying medical supplies. Millions could die there from COVID-19.
评论 #22635275 未加载
castorpabout 5 years ago
Are there any European hosted (and owned by a European company) alternatives to GitHub or GitLab?
评论 #22635360 未加载
评论 #22635255 未加载
rolphabout 5 years ago
time to migrate and redeploy, perhaps reface things and setup a new repository.<p>the trade sanctions thing is about this repository involving paid service:<p><a href="https:&#x2F;&#x2F;github.com&#x2F;aurelia&#x2F;aurelia" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;aurelia&#x2F;aurelia</a><p>&quot;Due to U.S. trade controls law restrictions, paid GitHub organization services have been restricted. For free organization accounts, you may have access to free GitHub public repository services (such as access to GitHub Pages and public repositories used for open source projects) for personal communications only, and not for commercial purposes. &quot;<p>so it looks like its not the most stable place to make money.
tanilamaabout 5 years ago
This is laughable. What trade sanctions would apply to a JS frontend framework? Insane.
unlinked_dllabout 5 years ago
I thought this was about the music education software by the same name
thatgerhardabout 5 years ago
Since when is it Github&#x27;s job to lock others repos at all?
Kiroabout 5 years ago
Read the whole Twitter thread and all comments here and I still don&#x27;t understand what trade sanctions are applicable here.
评论 #22630013 未加载
gtrubetskoyabout 5 years ago
Github was cool when git was new years back - but these days, and especially given how git inherently is not centralized, it is not very clear to me why we all cling to github. With a little work, all that it offers can be done without any help of a centralized server&#x2F;corporation.
greutabout 5 years ago
It&#x27;s been removed from AUR packages as well, <a href="https:&#x2F;&#x2F;lists.archlinux.org&#x2F;pipermail&#x2F;aur-requests&#x2F;2020-March&#x2F;038625.html" rel="nofollow">https:&#x2F;&#x2F;lists.archlinux.org&#x2F;pipermail&#x2F;aur-requests&#x2F;2020-Marc...</a>
bilekasabout 5 years ago
Does any license in particular effect the trade sanctions? MIT for example in my eyes would be the most lax, does that mean that it does not apply for trade sanctions ?<p>Open source based on government sanctions kinda feels like some oxymoron.
Kydlawabout 5 years ago
It&#x27;s back <a href="https:&#x2F;&#x2F;twitter.com&#x2F;EisenbergEffect&#x2F;status&#x2F;1240705256389890048" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;EisenbergEffect&#x2F;status&#x2F;12407052563898900...</a>
adim86about 5 years ago
The funniest thing to me is that the twitter account complaining is a Microsoft employee and Github is owned by Microsoft but the only way he could complain and be heard is via twitter? Amazing!
Lorinabout 5 years ago
TIL about Aurelia - the streisand effect in full force :)
jtmsabout 5 years ago
I had never heard of this framework until this happened, but now I am going to check it out. Probably a very good bit of accidental publicity
longstationabout 5 years ago
Would having a decentralized repository be a good idea (one that is not subject to this kind of corporate&#x2F;political issue)?
pragmaticabout 5 years ago
And in that moment Hacker News was enlightened.
type0about 5 years ago
Are there any hints on what other countries&#x2F;regions might be getting on that sanctions list soon?
sytseabout 5 years ago
GitLab CEO here, thanks Nat for doing everything you can do to keep open source accessible around the world. We have to comply with the same restrictions and respect greatly that GitHub is taking the broadest possible interpretation of US sanctions law to help users.
评论 #22630746 未加载
评论 #22630910 未加载
justlexi93about 5 years ago
I wonder what their timeline for fixing a mistake like this is when it&#x27;s just some plebe.<p>I bet it aint an hour.
mullingitoverabout 5 years ago
Isn&#x27;t this a first amendment violation? Are we not on board with the notion that code is speech, and that the constitution applies to everyone, not just US citizens?<p>With those things in mind, I don&#x27;t understand how the Iranian peoples&#x27; free speech rights can be infringed just because their speech is in the form of code.
评论 #22630142 未加载
评论 #22630446 未加载
评论 #22630194 未加载