Hacker News new | ask | show | jobs
by barkbro 3531 days ago
According to the article, the stores were running malicious javascript which grabs people's credit card info. This obviously means they are vulnerable in some kind of way, but I fail to see how this is reasonably likely to be exploited. Even if it was, you also have to consider the benefit of warning the users.

I am not a security expert though, and I might be missing out on something.

1 comments

The responsibility of GitLab and GitHub is not to investigate if those 1000 sites are indeed running malware and how dangerous the malwares on these sites are, and who could be harmed by these malwares.

The responsibility of GitLab and GitHub is also not to judge if it's "more important" to protect the site owners' businesses or the people going to the sites.

If some sites are running malware, the site owners are responsible for fixing it and not harming the people using their sites, not GitLab or GitHub.

On the contrary if site owners could be harmed by the name of their sites being on such list on GitLab or GitHub, then GitLab or GitHub are responsible according to the DMCA.

So GitLab and GitHub are just acting on what they are held responsible for according to the law.

Disclaimer: I am working as a contractor for GitLab and I am not a lawyer. I took no part in GitLab's decision to censor the list and this is just my own opinion.

> On the contrary if site owners could be harmed by the name of their sites being on such list on GitLab or GitHub, then GitLab or GitHub are responsible according to the DMCA.

Nope. DCMA is about copyright, and we have not gotten to the point where someones URL is copyrighted.

According to https://en.wikipedia.org/wiki/Digital_Millennium_Copyright_A...:

> It criminalizes production and dissemination of technology, devices, or services intended to circumvent measures (commonly known as digital rights management or DRM) that control access to copyrighted works. It also criminalizes the act of circumventing an access control, whether or not there is actual infringement of copyright itself.

So no the DMCA is not just about copyright.