On the 31st August I got an email from a customer, telling me that they had found an imitation of my data wrangling software on Github. I’m not linking to it, but here is a screenshot: It is …

278 points•hermitcrab•6 days ago•119 comments•

119 comments

hermitcrab6 days ago
Author of the post here. Github finally took the offending page down approximately 10 minutes after the post appeared on the front page of HN. Total coincidence. I'm sure!

Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.

And it seems they are able to do things very quickly, when they want to. Bastards.

koolba6 days ago
> Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.

This also works for Google support.

> And it seems they are able to do things very quickly, when they want to. Bastards.

I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.

It was already a problem before agents could automatically perform these actions.

And it’s not something you can really automate on their end either. At least not the judgement call on the removal. Imagine if there was a fully automated process and it inadvertently took down a legit project.

debugnik6 days ago
> I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.

Stalling in the hope that reporters won't escalate, instead of allocating a tiny bit of their billions in profit to hiring for this, is malicious in my book.

dogleash6 days ago
>I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.

It's malice from whoever is responsible for under-staffing. It's also malice to prioritize the squeaky wheel for optics; it's intentional to reduce the spread of the knowledge of how unresponsive they are.

rkagerer6 days ago
I’m sure they are swamped with such requests

Then maybe they should be growing their customer support capacity along with their business. It drives me crazy how big companies have normalized cutting those departments down to anemic proportions. Especially those where you're a paying customer.

alightsoul6 days ago
YouTube already does it autonomously with seemingly no legal consequences for them because you agree to it in their tos
rcleveng6 days ago
Unfortunately this is very true. It often takes someone pretty high up on the food chain to see it on HN, X, or get an email/LinkedIn message asking about something for it to become a priority.

I don't see that changing for any of the large companies unfortunately, anytime soon.

elAhmo6 days ago
Describes pretty much any of the big companies. For example, I have seen numerous times people got their account locked on Google, or their app stuck in limbo at Apple, and then after post becomes viral all problems get solved.
latexr6 days ago
Apple in particular is mocked because they explicitly say (used to say?) “going to the press doesn’t help”, but they’ve shown time and again that it’s the most effective way to get them to take action.
zamalek6 days ago
For this specific case, a DMCA would have gotten you a much faster take down. As far as I can tell it's automated. Sure, they could appeal it but then the malware nature of it would be in the crosshairs of the reviewer.

Not excusing their slow response, though.

ajmurmann6 days ago
It might not be a willingness issue as much as a bandwidth issue.
post-it6 days ago
Bandwidth can be bought with money, of which Microsoft made an extra $133.7 billion this year.
pllbnk6 days ago
I have for a long time said that the way to regulate these huge companies would be to have government-mandated SLOs for live support.

For example (simplified), if a user makes a call, a person with sufficient privileges to handle 90% of the cases should answer on the other end within 2 minutes. If the case cannot be handled, the higher-up with privileges to handle 99% of the cases should be reached within 5 minutes. And to be fair, it should be mandated for all companies, not only FAANG-like.

But a company like Meta (for example) with a billion customers would then have to decide whether they want to work on quality improvements for their services or whether they would like to hire a million technical support staff.

iAMkenough6 days ago
Good thing HN provided them some bandwidth to do their jobs.
cyanydeez6 days ago
unwilling to provide proper support?

Just seems like a silly rational response to the same problem.

locknitpicker6 days ago
Yes,evidently bandwidth from HN unblocks takedown requests of malicious content.
monster_truck6 days ago
They're generally extremely quick about this if you ping ~anyone on the security team with the offending url and a link to the real repo. There is a long ongoing game of cat & mouse against malware in repackaged things like first party windows utilities to leverage the signed binaries.
hermitcrab6 days ago
>if you ping ~anyone on the security team

And how I am supposed to know who they are or how to reach them?

wingerlang6 days ago
If GitHub staff is still reading this thread, maybe you can take down https://screenmemory.github.io/ as well. I reported it 4 weeks ago, ticket ID 4703161
rcleveng6 days ago
Please give GitHub some slack, just check out the massive number of copilot changes they've had to release over the last 3 weeks (https://github.blog/changelog/). There's clearly little time left for security, maintenance, or reliability work.
OCTAGRAM6 days ago
I recently found "free" version of Lossless Scaling on GitHub. The release installer is definitely malware. It took GitHub 3 days to shutdown malware distribution. Category of my ticket was malware report, not copyright infringe
hermitcrab6 days ago
Author here. I initially reported it as an imitation. A few days later I added evidence that it was malware.
Havoc6 days ago
They’re presumably too busy with keeping availability above nine sixes

Read the full thread on Hacker News →

Related stories