11 ms·
Ask HN: Is personal GitHub information public domain?
Who is correct in this case?
I've been rather constructive in attempting to resolve this matter with gitpay to simply remove my information. However they have not been cooperative.
This person also provides an argument that is not valid.
What are your thoughts on this conversation?
https://github.com/gitpay/website/pull/4
- Macha 10y agoIt depends on what the licence is for Github, both in terms of information contributed to them and information obtained from them. IANAL and I'm too lazy to read it, but I suspect the case is you've given Githuba very broad licence to use the info but they've passed on a much more restrictive one to their users so they can't just run g1thub, an exact mirror of the site. Public domain is very unlikely, but that doesn't mean gitpay is in breach of their terms.
- hnysacct 10y agoThanks Macha, good point. Yeah whether gitpay is in breach of github's terms is a bit unclear. On one hand, you allow your content/information to be viewed but not necessarily copied. So, information is not really in the public domain it's just publicly available. In this case, gitpay should allow anyone who does not wish to have their information available on their website should have a delete feature, and should not hesitate on takedown requests. Odd that they launched without such a feature. Upon inspection of their code, at least what is public, they don't have any function for deleting information.
- joshu 10y agoLinkified: https://github.com/gitpay/website/pull/4 https://github.com/gitpay/website/pull/4
- franciscop 10y agoI agree you are on the right path here. You have three options from my point of view (this is not legal advice): 1. Get lawyers involved 2. Get social media and shame involved, which will probably make them take action. You seem to be doing 2 by being in the front page of HN, take it to twitter as well. This is ridiculous but it's "easy and cheap" way of doing it. 3. Nullify your account by setting up fake data and making them update it (automatically?). This is why you sometimes want throwaway services or http://mailinator.com/ http://mailinator.com/ , for companies who abuse people's data as seems to be the case. Waiting for others to comment here, as it's a really interesting topic and I want to see other options as well
- hnysacct 10y agoThanks franciscop and thank you for your advice! It's definitely an interesting topic as it touches upon a few ethics. I'm considered #1 but the thing is it might take time. The person stated that the PR will be reviewed in the New Year, so by the time I involve lawyers the matter might have already been resolved. So, at the moment I've taken the matter to social media to bring up the matter of ethics in this case. Thanks again!
- deleted 10y ago[deleted]
- JoshTriplett 10y agoTo the extent copyright applies to such information (which would vary by jurisdiction and the details of the information), it most certainly doesn't fall in the "public domain" (a widely misused term). You've granted Github a license to use it, and Github allows others to view it. The question then becomes whether users of Github's API may copy that information. Legally, Github has the ability to grant permission to third parties, so if they choose to do so, you can't un-grant that permission, because you've already granted it to Github. However, Github doesn't have to grant that permission, and may set conditions on it via their ToS and their API ToS. And it doesn't seem entirely clear whether Github's ToS allows what Gitpay has done. Legal issues aside, though, scraping another service to create pseudo-accounts and refusing to provide even an opt-out does not seem like a good business practice. While Gitpay appears to have done several things right that other services get wrong, this definitely isn't one of them, and it needs fixing.
- TAForObvReasons 10y ago> The question then becomes whether users of Github's API may copy that information. Answered opaquely in terms of service: > Customers may access their GitHub account data via an API (Application Program Interface) My interpretation is that the "their" qualifier disallows people from using the API to access other people's data without proper authorization.
- JoshTriplett 10y ago> My interpretation is that the "their" qualifier disallows people from using the API to access other people's data without proper authorization. That interpretation wouldn't make sense with many well-established uses of Github's APIs today. For example, consider a CI service that tests incoming pull requests, and shows the details of each pull request, including the user who submitted it. Showing appropriate user information in context (associated with their Github contributions), however, seems quite different from mass-scraping user information to create fake "claim me" accounts. Github may or may not want to allow that (and they can always change or clarify their position).
- jrochkind1 10y ago
- EE84M3i 10y agoIt seems to me it should be a) reasonable for gitpay to offer a way to 'opt out' if you don't want your information there anymore, even if they're not legally required to. b) fine to let the gitpay folks wait to add that until the end of the holiday season. The user who created the issue linked from the top of this thread seems to be overwhelming the developers, who have graciously taken time out of their vacation to say they'll follow up next week. The relative severity of this does not seem to warrant a more urgent response.
- guitarbill 10y agoYeah, the pushiness really isn't helping. Neither are nebulous legal threats like DCMA, etc. The devs seem like rational people so far, so escalating things at this stage will win you no favours, even if you are "correct in this case". Faster would be better, but we're all just human. Edit: Wow, it seems the comments on the github issue are degenerating fast. Remember, the maintainers are also people. I'm sure there's a teachable moment here, it being Christmas and all.
- hnysacct 10y agoThe devs are somewhat hostile in this case. It's a matter of introducing the feature to help out mitigate other requests to take down information. They have the entire user base of github as "inactive users" so they might get more requests. But, the fact that the first comment from the dev came out sort of hostile is the major concern. That's why the attention is brought to the community to decide which argument is right. It's not pushing for action... it's deciding if/who is at fault and whether gitpay should have been doing this sort of thing in the first place. It's a question of ethics in the bigger picture.
- guitarbill 10y ago> The devs are somewhat hostile in this case. You keep saying this, but they really aren't. At least as far as I can see from what's public. Communication is difficult, maybe give them the benefit of doubt? (And some peace and quiet) To me, it sounds you're trying to make a huge issue out of this now, in the hopes it'll get things done quicker. Which is a horrible tactic. This isn't even about who's right or wrong. So far, it seems like nobody disagrees with your basic premise, just the timeframe. Just look at your phrasing. "hostile in this case", "sort of hostile is the major concern", "which argument is right", "it's deciding if/who is at fault", "it's a question of ethics in the bigger picture". Until the say "No", this is all just overreacting.
- jc4p 10y agoMaybe this is off-topic but I'm wondering what people think about tech recruiting websites that scrape profiles on sites like Github to sell you to other recruiters (or for other purposes, like GitPay). With badly coded websites like GeekedIn the attack vector is all of their data being public like so: https://www.troyhunt.com/8-million-github-profiles-were-leaked-from-geekedins-mongodb-heres-how-to-see-yours/ https://www.troyhunt.com/8-million-github-profiles-were-leak... But with the websites that aren't as badly coded, the annoyance is recruiters messaging you on your Github account pitching you random jobs. Do you get those? This is something we deal with at Stack Overflow (where I work) a lot. People love trying to scrape our content and creating Chrome plug-ins that when someone loads up a Github or SO profile shows all the random bits of info they've been able to scrape about that person. It leads into a lot of issues for us e.g.: Recruiter claims to have gotten my email address from Stack Overflow http://meta.stackoverflow.com/q/318621/472021 http://meta.stackoverflow.com/q/318621/472021 to the point where we've (semi) recently changed our ToS to directly be able to fight cases like this: A Terms of Service update restricting companies that scrape your profile information without your permission http://meta.stackexchange.com/questions/277369/a-terms-of-service-update-restricting-companies-that-scrape-your-profile-informa http://meta.stackexchange.com/questions/277369/a-terms-of-se... Do you think Github should try to do something similar? I just want to have a place to put my code and be able to easily talk to others working on code, not something that results in recruiters messaging me and random websites taking my data hostage. Edit: In case you want to see what the "attack vector" looks like, find any of your recent Github commits, e.g. for me: https://github.com/jc4p/quick-hue-toggle/commit/28f4cf724968557cfae1e90793561c1b96d80384 https://github.com/jc4p/quick-hue-toggle/commit/28f4cf724968... and add a `.patch` at the end to get the patch file: https://github.com/jc4p/quick-hue-toggle/commit/28f4cf724968557cfae1e90793561c1b96d80384.patch https://github.com/jc4p/quick-hue-toggle/commit/28f4cf724968... and bam, my e-mail (per my git user config) is right there. Should we all be using fake e-mails when we commit to git?
- user5994461 10y agoI think recruiters shouldn't have access to my email address and my email address should never be public on any service.
- 10y ago
- tingletech 10y agothe gitpay site also lacks a posted privacy policy, making the site illegal in CA https://consumercal.org/about-cfc/cfc-education-foundation/california-online-privacy-protection-act-caloppa-3/ https://consumercal.org/about-cfc/cfc-education-foundation/c...
- chris_7 10y agoThey appear to be located in California, check: whois gitpay.com
- hnysacct 10y agowrong domain: Gitpay is gitpay.org.
- chris_7 10y agoGot it. They are in the UK.
- tingletech 10y agoThen they probably need that "we use cookies" banner, and will fall under the Data Protection Act. "The Data Protection Act does not define fair processing. But it does say that, unless a relevant exemption applies, personal data will be processed fairly only if certain information is given to the individual or individuals concerned. It is clear that the law gives organisations some discretion in how they provide fair processing information – ranging from actively communicating it to making it readily available." https://ico.org.uk/for-organisations/guide-to-data-protection/principle-1-fair-and-lawful/ https://ico.org.uk/for-organisations/guide-to-data-protectio...
- tingletech 10y agoIt does not matter if they are in CA "An operator of a commercial Web site or online service that collects personally identifiable information through the Internet about individual consumers residing in California who use or visit its commercial Web site or online service shall conspicuously post its privacy policy on its Web site, or in the case of an operator of an online service, make that policy available... An operator shall be in violation of this subdivision only if the operator fails to post its policy within 30 days after being notified of noncompliance." but sort of moot, because I don't think there is anyway to enforce it.
- Macha 10y agoRelevant previous incident with another git tipping site: https://news.ycombinator.com/item?id=8542969 https://news.ycombinator.com/item?id=8542969
- deleted 10y ago[deleted]
- rajington 10y ago> Social Linked Data: Gitpay follows the SoLiD specification for the next generation of web apps http://gitpay.org/ http://gitpay.org/ > Users should have the freedom to choose where their data resides and who is allowed to access it by decoupling content from the application itself. https://solid.mit.edu/ https://solid.mit.edu/
- theaustinseven 10y agoRegardless of whether or not they are legally in the right, this is a definite dark-pattern. Users should not exist on your site unless they signed up. Full stop. This shouldn't be a question of whether they should allow users to delete themselves, but rather why they are creating users for people who don't even know about the service.
- jlarocco 10y agoIf the info was scraped from public Github pages then I think it's legal for Gitpay to use it, assuming they aren't violating the Github TOS. That doesn't mean it's not a shitty thing to do, and I really think it should be a violation of the Github TOS to republish the information without the user's explicit consent. This has come up a number of times, and I'm really surprised Github hasn't addressed it already. I don't care if people read my info on Github (that's why I made it public), but it's really sleazy to co-opt that information to automatically create accounts on other services for people.
- hnysacct 10y agoExactly. You don't have control over other services spawning up accounts for you. Which is just an annoyance if they have a way for you to take the information down (most do) but when they don't... that's a problem.
- magicmu 10y agoExposing personal information like that, while maybe not illegal (I don't have the qualifications to say), is something I definitely see as unethical; at least if an opt-out option isn't even provided. Beyond the personal info like email, full name, and profile picture (all of which is definitely easily scrapable and not a _huge_ deal to me), I noticed that it had made the type, modulus, and exponent of each of my RSA keys available. I know that these can be derived from an RSAPublicKey, but I'm not sure what making them easily viewable means (if anything). Could someone with more encryption knowledge shed some light on that?
- hnysacct 10y agoCurious about that too now.
- deleted 10y ago[deleted]
- awinder 10y agoNow I'm kinda curious how many other sites pull this type of stunt. I'm definitely torn on how I feel about this, I find it even more weird that there's people listed as following me on a site that I just have a shadow account on. Most of all I just want to know how many other weird sites I have shadow accounts on and what kind of interaction people have with shadow-me. As far as the product decision on this one, man, I can't imagine which alternative universe this would ever play well in. Is it like a Silicon-Valley-esque VC numbers pumping game or what?
- hnysacct 10y agoA bunch of freelancer and recruiting type sites do that as well. However they make it easy for you to have your information removed. > Is it like a Silicon-Valley-esque VC numbers pumping game or what? That is my initial thought too. If you create a website and create shadow accounts or "LinkedData" then you're creating the illusion that you have a larger following than you really do. Whether that was gitpay's intention, probably not.
- hnysacct 10y agoA bunch of freelancer and recruiting type sites do that as well. However they make it easy for you to have your information removed. > Is it like a Silicon-Valley-esque VC numbers pumping game or what? That is my initial thought too. If you create a website and create shadow accounts or "LinkedData" then you're creating the illusion that you have a larger following than you really do. Whether that was gitpay's intention, probably not.
- stonogo 10y agoThe future of gitpay: http://web.archive.org/web/20160325072958/http://blog.readability.com/2012/06/announcement http://web.archive.org/web/20160325072958/http://blog.readab... Collecting money on others' behalf without prior consent is a terrible idea, and prepopulating your site with others' data to make it look like you have consent is even worse.
- ezekg 10y agoThis website is just asking for an SQL injection. My goodness. Edit: I spoke too soon. The database has been dropped: http://gitpay.org/user.php http://gitpay.org/user.php.
- guitarbill 10y agoAmazing, they've used prepared statements wrong every time: https://github.com/gitpay/website/blob/master/functions.php https://github.com/gitpay/website/blob/master/functions.php Sadly, SQL injection vulnerabilities aren't a rarity for PHP sites :( It's too easy to make this exact mistake.
- JoshTriplett 10y agoIt amazes me that PHP (or the database library in question) allows you to call `prepare` on a non-literal string without even a warning.
- hnysacct 10y agoIt's too easy to misuse PHP that way. Though I think enabling E_STRICT would produce a warning.
- Macha 10y agoSo, let's drop PHP for a moment. If you were writing a database library in say Java, how would you know or prevent the user passing you a concatenated string over a string literal? Is it Java's fault that you can't (excepting major bytecode hackery maybe?)?
- JoshTriplett 10y ago> If you were writing a database library in say Java, how would you know or prevent the user passing you a concatenated string over a string literal? Extend the language to detect passing a string literal to certain functions or macros. Rust does this for macros that take a format string, like "println!" and "format!". GCC can do this for printf as well. And Perl has taint checking.