13 ms·
GitLab reinstates list of servers that have malware
- Terretta 10y agoWhat a lovely mea culpa. Straight to the point. We thought another way, but here's the counter argument, we agree, are sorry, and fixed. Rare candor.
- Arcsech 10y agoYep. So rare to see this, especially in this day and age. Also more justification for my decision to switch to GitLab for all my personal stuff!
- sytse 10y agoThanks for the kind words and thanks for using GitLab!
- trcollinson 10y agoTotally agree! Though why stop at personal stuff? I moved all of my business stuff to gitlab as well. Just the gitlab-ci stuff alone is worth the price of admission. There are a few funny little edges (gitlab.com seems a bit slow at times, and I finally have to break down and spin up my own gitlab runners so I didn't have to wait on shared runners for ci), but overall, I have no complaints at all. Heck, I am working on a pipeline for automated deployments as we speak. Gitlab is awesome.
- Arcsech 10y agoWe do use a self-hosted version of GitLab for some of our projects at work (CE I think), and GitHub for others - which one depends on which team you're on. I only didn't mention that we use GL at work since I have no input into the matter - for the longest time we were using Gitolite hosted on a toaster oven and GL on a proper server is a big improvement, even though we use very few of its features (we have alternative CI and code review solutions). Because I know it will be asked, the reason we're not using GL's features is mostly organizational inertia since we had to use those tools back when we were using Gitolite - having used GL's CI and code review solutions on personal projects, I don't think they're any worse than what we're using now.
- intrasight 10y agoIndeed. My faith in GitLab is restored!
- HowardStark 10y agoRestored? When was it lost?
- SwellJoe 10y agoThis is the proper decision here, but not merely for the reason they've given. The best reason the list should be widely available: The exploit has already happened in this case, and disclosing it doesn't help attackers do further harm; the harm is already done. Removing the list is closing the barn door after the horses are gone.
- happyslobro 10y agoIt's worse than that, more like blocking the fire lane before the ladder truck can begin evacuating people.
- deleted 10y ago[deleted]
- kkjuuio888 10y agoLets be honest about it; the real reason it was pulled down could've very well been to limit culpability in dissemination.
- nothrabannosir 10y agoUnlikely. At least in Gitlab's case. Why would they have reinstated it?
- smnscu 10y agoJust applied for a position at GitLab, absolutely love this company! PS: you can do it too, they're completely remote! https://about.gitlab.com/2016/03/04/remote-working-gitlab/ https://about.gitlab.com/2016/03/04/remote-working-gitlab/ https://about.gitlab.com/jobs/ https://about.gitlab.com/jobs/
- deleted 10y ago[deleted]
- sytse 10y agoThanks for applying Andrei, and thanks for spreading the word.
- nihonium 10y agoHi, How does it work when someone apply to a remote job from another country? Do you have to be on their payroll, or is it contract basis via an umbrella company or own limited company? Cheers
- YorickPeterse 10y agoThis depends on the country. We have an official entity in the United States and The Netherlands. For example, European employees tend to be employed by GitLab B.V. (the Dutch entity). Those outside of the covered areas are officially contractors if I'm not mistaken.
- sytse 10y agoIn most countries we would hire you as a contractor. In the US, UK, Netherlands, and India you would be an employee. For our contracts see https://about.gitlab.com/handbook/contracts/ https://about.gitlab.com/handbook/contracts/
- Normal_gaussian 10y agoI find it admirable that you publish these contracts publicly however I was curious as to how aware the employees are of part 14 of the European contract: > Other than with the prior written permission of the Employer, the Employee is prohibited during the term of the Employment Contract to carry out work – either paid or not – of any nature whatsoever, either for himself and/or for third-parties. Personally I would never sign this because it prohibits any form of work for myself. Notably it would also prohibit any and all work for open source projects. Laughably this would also seem to prevent me working on my own house. In fact, to my mind, this is a beyond unreasonable clause. And has really made me put on hold all the positive thought I had had for GitLab (which was relatively significant due to employee comments and my minimal experience with the product). As you are the CEO I'm hoping you have a perfectly reasonable explanation for how such a clause landed in the contract.
- learned 10y agoGitLab's customer service and reaction speed never ceases to amaze me. For anyone interested in constructing great customer relationships, I recommend using GitLab as a case study.
- dsabanin 10y agoLooks like GitLab is the new GitHub - open, human and doing the right thing. Great!
- gohrt 10y agoThe article's logic doesn't make sense. In every vulnerability, the users are the victims. Web stores aren't a special case in the debate of "responsible disclosure" vs "immediate disclosure". GitLab changed their stance from "responsible disclosure" vs "immediate disclosure". That's their choice, but they shouldn't mince words about it.
- weeks 10y agoI don't think this could be accurately described as merely a _vulnerability_ disclosure. These web stores are already compromised, therefore anyone that makes a purchase is exposing their payment information. Furthermore there is no "responsible" way to contact thousands of web stores across the globe. The best case for disclosure is Google's Safe Browsing beginning to warn users immediately.
- deathanatos 10y agoThe users here are the users browsing the web store with the intent to purchase something, not the server operators. Both are victims if the malware author's intent is successful. In the usual sense of a server having a vulnerability, there are just two parties involved: the server operators, and the malicious party exploiting the server. That's the case in which GitLab is saying to not publish a list of such vulnerable servers. In this case, the server operators are not yet victims; responsible disclosure is supposed to help us (the good guys) keep it that way. But in this case, we have an already exploited server. The server operators are already victims. The point of publishing lists here is to attempt to prevent the malware from further skimming credit card numbers off users attempting to purchase goods from the infected storefronts. Like before, the point here is to prevent more people from falling prey to the skimmers here, but the action we must take to do so effectively is the opposite.
- oneplane 10y agoThat is not the issue here. The issue is that the webshops aren't the problem code-wise but business-wise. They don't want to maintain their software that hosts the shop, completely ignore private disclosure or simply ignore it. If they don't want to fix it, the next best thing is to warn people about it.
- jlgaddis 10y ago> At GitLab we strongly believe in responsible disclosure, ... So publishing a list of servers ... is not OK. In my opinion, this comes very close to "censoring" content. That's great that GitLab believes in responsible disclosure, but that doesn't mean that everyone does or that you get to force your beliefs on your users or customers. If you do in fact plan to censor content then you need to be very clear about that up front and identify what types of content you will not permit. I'm glad that GitLab has done a 180 and reinstated the content. In the future, I hope they will fully think through any decisions to pull down content that they don't "agree with". I do give them credit for recognizing they made a bad call and admitting to it.
- woogley 10y ago> If you do in fact plan to censor content then you need to be very clear about that up front and identify what types of content you will not permit It seems to me their TOS covers this sort of thing. It's not some platform with free-speech rights, it's content hosting with limited liability and legal caution.
- jlgaddis 10y agoI certainly understand that it belongs to GitLab and they can absolutely run it in any way they see fit. If there are certain types of content that they do not want to host, they can absolutely refuse to do that -- and remove such content when they discover it. All I am saying is that they should identify what types of (otherwise legal or permitted) content they will not permit to be hosted on their platform. It is implicit that illegal content will be removed but that's not what I'm referring to. For example, if a web host doesn't want to host the KKK's web site then they can absolutely refuse to serve them. If $webhost's religious CEO doesn't want to host content related to gambling, well, that is their right. If Amazon doesn't want to host Wikileaks, they don't have to. I just wish companies would state what content they don't permit instead of using a term like "objectionable" or "unacceptable" and interpreting it however they like from day-to-day. I'll admit that I haven't read all of their various Terms and Policies in their entirety (there's a lot of them!) but I did skim through them and didn't see anything other than the usual mentions.
- dudul 10y agoOne of the few companies out there who give me hope. Switched all my projects to GitLab a while ago, never looked back.
- messutied 10y agoI live in Germany, and feel Gitlab website is quite slow :/ is it supposed to be as snappy as Github?
- YorickPeterse 10y agoThis depends a bit on what parts of GitLab(.com) you're using. For example, viewing issues should generally be as fast as GitHub.com (http://stats.pingdom.com/81vpf8jyr1h9/1902794/2016/10 http://stats.pingdom.com/81vpf8jyr1h9/1902794/2016/10 vs http://stats.pingdom.com/81vpf8jyr1h9/1902795/2016/10 http://stats.pingdom.com/81vpf8jyr1h9/1902795/2016/10). Other parts may be a bit slower; pushing for example can still be a bit slow at times.
- dudul 10y agoI'm on the East Coast. For a while GitLab was quite slow. Much better now. They made a lot of progress in the past 3 or 4 releases. However, I agree that GitHub is still better in terms of performance. Now, I put things like tooling, pricing model, features, and ethic of the company above performance :)
- sytse 10y agoThanks for sticking with us Dudul. We want to make sure performance will also be a reason to pick us and are working on it in https://gitlab.com/gitlab-org/gitlab-ce/issues?scope=all&state=opened&utf8=%E2%9C%93&label_name%5B%5D=Performance https://gitlab.com/gitlab-org/gitlab-ce/issues?scope=all&sta... and https://gitlab.com/gitlab-com/infrastructure/issues?scope=all&state=opened&utf8=%E2%9C%93&label_name%5B%5D=performance https://gitlab.com/gitlab-com/infrastructure/issues?scope=al...
- sytse 10y agoIt is our ambition to make GitLab.com as fast as GitHub.com but currently we're slower. Please see https://gitlab.com/gitlab-com/infrastructure/issues/59 https://gitlab.com/gitlab-com/infrastructure/issues/59 for more information on how we're working to improve this.
- nodesocket 10y agoLet's be honest, the people that are reading the list on GitLab are highly unlikely to be end consumers purchasing at those stores. If anything, this list provides a potential target list for other hackers to try and compromise those stores even further. I believe this to be irresponsible and furthermore still a violation of responsible disclosure.
- sytse 10y agoI agree that it is unlikely that consumers directly use the list themselves. But have you seen https://twitter.com/gwillem/status/786908740838682624 https://twitter.com/gwillem/status/786908740838682624 that was linked from the OP? "631 compromised stores have been fixed in the last 4 days". I think publishing the list helped accelerate the fixing process. And companies like Google might use the list to detect malware sites in search results.
- startling 10y agoThe people you're afraid of ("if anything, this list provides a potential target list for other hackers to try and compromise those stores even further") already have access to the data gwillem used as a source.
- nodesocket 10y agoAny by further distributing the list to a greater audience, that makes it ok?
- startling 10y agoIt's a matter of degree. Do the positives of publishing outweigh the negatives? I think so.
- jacalata 10y agoIsn't that true for the vast majority of responsible disclosure instances?
- TheSpiceIsLife 10y ago
- kefka 10y agoThey should be much more careful in how these types of reportings are done. You were doing a public service of already-explited machines that are snarfing credit card numbers. And that is of great importance for anyone who buys stuff online (Like... all of us). It also goes to show, that we need to further develop P2P type technologies like IPFS and similar stacks, to rid ourselves from monolithic companies dictatorial hands. Because what they find "unsuitable", you are no longer welcome. That's a problem, for all of us. I had a similar problem with a VPS provider 2 weeks ago. I run IPFS on all my nodes, and comply with good netizen and compsec principles. They ToSsed me, because "my machine was scanning :4001 and they received a complaint". Bullshit. That is the chatter IPFS uses when maintaining the DHT. However, I was actually using a machine and what I paid for... and they didn't like it. Fortunately, since all my data is via IPFS (and /ipfs and /ipns thanks to filesystem mounting), my data was already backed up and distributed. Filing a dispute with Paypal and purchasing another VPS provider was simple.
- 08-15 10y agoI don't get why anyone views this as a positive thing. The announcement effectively says "We took it down because we didn't think about it, but then we changed our mind." Okay---and a lively discussion on HN had nothing do with it, I presume. GitLabb, you could have admitted publicly that you made a mistake, but you didn't. Making excuses is a promise of repetition, so I read this as "Next time something like this happens, we're again going to delete the account, unless there is too much backlash on HN again." Sorry guys, but the damage is done and you missed your one chance to repair it.
- bmelton 10y agoI see that you've been downvoted, and while I can sort of see why, your thoughts somewhat echo my own, which earned you an upvote. Everybody's tripping over themselves to praise Gitlab here, and while I agree that they probably made the right decision here, in this case, the biggest issue to me is that they saw nothing wrong with the censorship of a gist (or repo, or codebase) in the first place, and that strikes me in a distinctly negative way. This post was one of disclosure. I am a free speech advocate on any issue for which there aren't compelling legal reasons necessitating removal (e.g., child porn), and I do my level best to make an effort to do businesses that prefer allowing free speech to the restriction of speech they disagree with. As a Gitlab user, this gives me great pause.
- basicplus2 10y agoIs there a plugin that compares sites I visit to this list automatically?
- fibo 10y agoGitLab is a (bad) copy and paste of GitHub, even the name is similar. I know maybe I will burn some karma point but I want to express my opinion cause I believe in the value of creating things, not to steal ideas. What if the list were put on GitLab first? Probably, without the GitHub example you would not remove it, even notice it.
- byuu 10y ago> GitLab is a (bad) copy and paste of GitHub, even the name is similar. Yeah, the part of the name they copied is so shameless. That's just going to end up causing user confusion -- thinking that both sites are related to Git in some way. /s
- dustinmoris 10y agoGitLab is a joke. They just copy what other do, but as soon there is a bit of bad publicity they immediately change their opinions just to please the community. GitLab has really become the communities' bitch. They copy paste everything they find and try to please everyone, but I don't think this will get them very far. I am glad there's so many other tech companies who try to do their own thing by being innovative.
- AlfeG 10y agoSoooo, is there an extension that will prevent me from visiting sites from the list?
- pbhjpbhj 10y agoYou could add them to your /etc/hosts file, eg using this snippet: https://gist.github.com/pbhj/0bf3041fa6eca6a1429cdc0f25764749 https://gist.github.com/pbhj/0bf3041fa6eca6a1429cdc0f2576474...