8 ms·
Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?
Hi friends,
The skinny is this: I went to prison, all my personal items were stolen IRL and the same person changed a bunch of my passwords. Subsequently, I can't recover my GitHub account.
I have recovered most of my digital assets by proving I am me. Recovering my GitHub has proven to be more painful than Google's treatment regarding my Google Workspace.
I have the original phone number associated with my account, and can verify a bunch of private repos that are associated with my account—even the number of commits on one of them (almost 6900). I can't, however, provide any 2FA codes or backup codes because they are printed on paper that has, I assume, been destroyed.
I maintain two relatively popular Ruby packages that have gone stale since I've been gone, and there are projects my GitHub there that I was working on prior to my incarceration—including a SaaS I had hoped to launch post-prison and two books I was ready to publish. Having said, just opening another account isn't exactly the option I want to take.
I've opened a ticket, but I'm getting the "shit out of luck because we don't know you are you" treatment. I understand that security is important, but if one can prove they are them, what's the point?
Are there other avenues I have that I haven't explored yet?
- qafy 1y agounfortunately, the techniques you are trying in order to get access to a dormant Github account are EXACTLY the same ones that github gets spammed with every day by bad actors attempting supply chain attacks. You don't have anything that proves your identity any more than any rando on the internet in Github's eyes at least. Everything you have presented here may be convincing enough to me, but probably not to GitHub's opsec policies.
- jopsen 1y agoAlso suppose you Facebook account was compromised, that bad, sad for the person affected. May cause some media attention if the person was famous. But if the right GitHub account is compromised, we could see massive supply chain issues. Or a big important web service with millions of users affected. The downside of making a wrong call here is just really really big. There are real businesses being deployed from GitHub.
- muzani 1y agoI'm not even convinced it's the real person. Lost your items, lost your email, changed passwords, criminal records. Sounds like a scam for sure. No offense, OP, but it seems easier to recover the email if you can prove physical identity.
- trenchpilgrim 1y agoGet a lawyer and contact GitHub through legal means.
- isbvhodnvemrwvn 1y agoWhat law do you think is relevant in this situation?
- trenchpilgrim 1y agoNo idea, which is why I recommend talking to a lawyer and not random people on the internet. Anecdotally I have heard stories of people successfully recovering web accounts via court order.
- clamprecht 1y agoIs there a phone number associated with the account? How does GitHub want you to prove that you're you?
- joshmn 1y agoThere is, but it's not a phone number I have access to anymore. I changed it to the said person's phone number before I surrendered so that this exact scenario did not happen. I trusted the wrong person.
- anonymousiam 1y agoSeems like you could present this evidence to the police for an identity theft charge against the "wrong person." Or you could threaten to do so, and perhaps regain your property.
- clort 1y agoExcept, read the comment again - Josh changed the account so that it referenced the other persons phone number. They did not steal his phone, and it could be framed that he gave them the account. Accusing somebody of theft? Perhaps the police would side with the non-felon..
- anonymousiam 1y agoThere's no dispute that he provided his telephone number, the dispute would be over the ownership of the GitHub account, which is a separate item, and perhaps still registered in his name. Without additional details, we're both guessing.
- tasuki 1y ago> I trusted the wrong person. This hits me hard. So you went to prison, and the person you trusted the most... turned out not to be trustworthy. Please hang in there and hope you meet (or have met already?) people you can rely on! I'm very grateful for the many people in my life I can absolutely rely on.
- abxyz 1y ago> I can't, however, provide any 2FA codes or backup codes because they are printed on paper that has, I assume, been destroyed. The situation you are in is very unfortunate and I am sympathetic but in GitHub's defence, this is exactly what I hope would happen when I enable 2FA. I would be very perturbed to find out that GitHub would grant access to my account given identity documents. There are some creative solutions (e.g: a countdown to the reset with progressively more aggressive email notifications to ensure the account holder is aware) but even they are problematic. So, this sucks, but it's the price we pay for security.
- joshmn 1y agoThat's the same stance I have and why I'm torn. The little quirk here—where it makes slightly more sense—is that they received a legal notice at one point (from the US Government) about my account, there are plenty of online articles to corroborate me as me, and I have a fancy prison release ID that can help me identify me. Unfortunately this context is probably lost on the individuals who work their Zendesk. The policies are rather draconian as others have mentioned. Anyone could be the victim of theft; mine just has an awkward paper trail attached to it.
- abxyz 1y agoI think the disconnect between you and GitHub support is that you're positioning this as a problem of proving your identity whereas for GitHub support it is a policy. The GitHub policy is: you lose your 2FA, you lose your account. Verifying your identity is not relevant. GitHub provides extensive tooling to protect your account (multiple methods of 2FA, recovery codes etc.) and so from their perspective, while this is deeply unfortunate, the policy is very clear and allowing you access to the account would be a major security issue (not for your account specifically, but for GitHub as an organization). edit: https://docs.github.com/en/site-policy/other-site-policies/github-account-recovery-policy https://docs.github.com/en/site-policy/other-site-policies/g...
- MrGilbert 1y agoI'd assume that there is simply no "ok, this individual got released from prison and can proof everything" policy in place, and that might be the real issue here. Big organizations begin to tumble once you request something where there are no policies in place.
- liquidise 1y agoI haven't any help to offer, but want to say that this post along with reading your site the other day has shown a level of composure and resiliency that i aspire to. Good luck getting your access back.
- xwowsersx 1y agoThoughts of the top of my head: - If the most important thing is control of the Ruby gems, reach out to RubyGems.org support - for your projects, if you have are past collaborators on those repos, they can sometimes open GH tickets referencing the project and vouch for you. Doesn't guarantee success, but adds weight - GH (being part of MSFT) does have some channels for escalated identity verification. Lawyers or notarized ID may be needed...possibly expensive, but sometimes the only way GH support is extremely strict on account recovery once 2FA/backup codes are gone. I wish you luck!
- joshmn 1y agoI was able to recover my Rubygems account :); unfortunately my projects were all private and solo :(; I am currently looking into lawyers—if anyone has any recommendations here my inbox is open.
- pjjpo 1y agoI haven't used Rubygems before but doesn't it allow publishing from a new repo? pypi allows updating publishing configs. A repo fork (and maybe more so the GitHub identify fork) is definitely not ideal but if your users can get updates to their packages, maybe it's best to move forward as well as possible.
- pjjpo 1y agoI also imagine the identity proof for asking GH support to archive the old repo would be lighter than for recovering an account entirely.
- mattbrewsbytes 1y agoI have no experience with any of this but thinking thru the other side, if I'm an IT helpdesk person getting an account reset/unlock request, I have no means to validate any identity paperwork anyone sends in. My response would be a curt email accd to policy and move on to the next IT ticket. I think the legal path is your best bet unless you know someone higher up. A legal path could bypass all the offshore IT helpdesk staff (making assumptions, MSFT is a giant mega-corp).
- CPLX 1y agoYou could initiate some kind of legal action to access your data. You'd need a lawyer. I think it's likely that you wouldn't have legal grounds to force them to give you your data but it's an approach that would most certainly get their attention at a higher level than anything you're able to do from a customer service perspective. You'd have to have some legal argument as to why they could be obligated to produce the records under subpoena but the standards for that could be quite low.
- the__alchemist 1y agoI'm perpetually worried (and partially prepared) for this sort of scenario, as more of my accounts require 2FA. I dread the day I lose or break my phone, have my items stolen, there's a weather disaster etc. I try to make my hobby repos public and/or backed up in multiple places as a hedge.
- IlikeKitties 1y agoJust do as I do and keep all the 2FA TOTP Codes in your keepass.
- manbash 1y agoDon't you have a 2FA Recovery Code?
- georgel 1y agoFar too many of the critical services (banks) still only offer SMS 2FA.
- the__alchemist 1y agoFor most of them. It's a tool, but not a silver bullet
- zdragnar 1y agoYubikey in a safe deposit box is about as good as we can get, at least for the services that allow it.
- jackconsidine 1y agoFWIW I had a similar conundrum with Slack. I had set-up my business Slack workspace in college; 4 years after graduation my university changed policies (they used to forward name@edu => name@alumni.edu). I tried the normal means (support tickets etc) to no avail. The third or fourth time I got someone in account recovery. There was a very formal process for verifying my identity (I'm sure based on the process this happens all the time). Eventually I they helped me recover my account. It probably took a few months on the whole, but once I got the right support rep it was only a week or so. So my advice would be to submit more tickets. Because they might have a process that not all support agents know about, and some are more helpful than others.
- oldpersonintx2 1y ago[flagged]
- __alexander 1y agoWhy not create a new account and fork your old repositories? You can restart with updating your old projects and overtime you’d build back up that reputation. I’d also add a note that you were the previous author and lost access to the repositories.
- joshmn 1y agoThey're private.
- bogwog 1y ago> all my personal items were stolen IRL and the same person changed a bunch of my passwords. Have you filed a police report? Do you know who this person is? Getting your stuff back might be easier than dealing with github support.
- apwell23 1y agothief changed your github password? why? how did he get get access to your github account ?
- tasuki 1y agoNot a thief - someone they trusted.
- lydiaharrison12 1y ago[dead]
- johtso 1y agoMaybe, depending on where you are in the world, you could make some kind of GDPR request to get access to your data, even if you don't recover your account?
- logicallee 1y ago[flagged]
- techbro92 1y agoYou sound paranoid and schizophrenic you should honestly try explaining your situation to someone you know or a professional. I think you’ll realize that your thinking is a bit delusional. I can’t really understand what you’re saying here.
- tptacek 1y agoDon't do this. We don't diagnose people on HN. Just flag the comment and move on, or, if you're worried, mail hn@yc. https://hn.algolia.com/?dateRange=all&page=0&prefix=true&query=diagnosis%20by%3Adang&sort=byDate&type=comment https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... (I'm not a mod, just someone who cares a lot about this particular rule.)
- logicallee 1y agoThe profile you responded to "techbro" was made 3 years ago, has 102 karma (i.e. 1 upvote every 10 days, on average), and has never submitted anything - zero submitted articles or profiles. My profile was made 12 years ago and has 3,118 karma (approximately averaging an upvote every 1.4 days) including lots of submissions of stuff I made, for example this Show HN that I was pleased to see make it to the front page with 36 points and lots of positive comments: https://news.ycombinator.com/item?id=43141139 https://news.ycombinator.com/item?id=43141139 (the resource itself is currently offline as I've temporarily replaced my website with 50 reasons why it's wrong to disrupt communications between a husband and wife. I'll replace my website as soon as this issue is solved.) Right up your alley, I've actually written a cryptographic case study of some of the dynamics of this, I've just sent you a copy of it (you and I were in touch before - it was very well reviewed by professional cryptographers.) In your reply to this, please acknowledge your receipt of my email, and if you can, print it out as well, as it can become inaccessible later. Of course, there are a lot of NSA-affiliated people who could come out of the woodworks to support parent's slander that I "sound paranoid and schizophrenic". The reason they don't? They're witnesses in the FBI case and don't want to go to prison themselves. The FBI has already handwritten over 10,000 affidavits in this case. (They are writing by hand to avoid electronic tampering with evidence.) I am not making a media story about it yet, which would be the next step, so there are no articles about this yet. My reason for not doing so is not to bring extra attention to the case, but simply to solve it in a straightforward and expedient manner.
- bena 1y agoDo you personally know the person who stole all of your items and accounts? I understand if you can't get or won't get in contact with them, but I'm curious as to whether this was a random or someone taking advantage of you. Edit: Nevermind, I saw your response to someone else.
- punkbit 1y agoThere are alarming statistics about phone snatching in London. Plus, we are NOT OUR PHONES. Doesn't GitHub have a way for people to verify and prove somebody's identity? Given that's a fact, isn't it best to disable 2FA and stop recommending it to people? Following this post, I have reviewed all my main accounts, created recovery codes, set up backups, and added alternative email addresses, among other tasks. Hope for the best.
- devoutsalsa 1y agoWhat you might consider doing is try contacting Ruby Central, or whoever it is that runs Ruby Gems. Even if they can't/won't give you access to the account, I'm wondering if they could/would freeze publishing updates to these gems until the account "owner" proves they are who they say they are. That way they don't risk giving control to someone who is hard to verify (you) and they prevent malware from being uploaded by the person who now controls your email until they verify the you are (which obviously they shouldn't be able to do).
- lesuorac 1y agoI wonder if you can make a creative small claims court claim against them. Denying access to some repo where you spent x hours on which can be resolved by them paying you y dollars * x hours. And then hoping a lawyer takes pitty on you and restores the account?
- punkbit 1y agoThat's a good idea! I've been thinking about how they could solve this, since they accept payments; wouldn't it be possible to request a payment with a specific reference code to verify the identity? Paired with any other required identification process, documentation, etc.
- lesuorac 1y agoIIUC, the issue is not that they can't verify OP. It's that there is a policy decision not to restore access. So you have to work around the policy issue.
- 6stringmerc 1y agoWELCOME TO TANGENTIAL INJUSTICE! Lost access to my phone, then went to Tarrant County jail awaiting trail (innocent until proven guilty but $250,000 bond where no humans or property harmed), and only was able to get a few G-M-@-1-L related accounts reset following a plea bargain to get back my freedom. Lots of corpses in that system. IYKYK. What can you do? Ask nicely. Hope to escalate. First off though, think of Jack Handey... If you lost your keys in lava, man, let 'em go, they're gone.
- amanzi 1y agoCoincidentally, this article was posted on HN yesterday and has been playing on my mind... https://shkspr.mobi/blog/2022/06/ive-locked-myself-out-of-my-digital-life/ https://shkspr.mobi/blog/2022/06/ive-locked-myself-out-of-my...
- didgetmaster 1y agoIt sounds like you trusted someone you shouldn't have. This person wouldn't happen to be someone who also has spent some time in prison?
- deleted 1y ago[deleted]
- sicariomoon 1y ago[dead]
- jefdiesel 1y agowhat's your gitname?
- joshmn 1y agojoshmn
- lydiaharrison12 1y ago[dead]
- TobySKT 1y ago[dead]
- TobySKT 1y ago[dead]
- djdjsjejb 1y agoez get a new account
- alexholfan 1y ago[dead]
- graycreate 1y agoBrutal situation—sorry you’re dealing with it. A playbook that’s worked for folks: assemble “hard” proofs that tie you to the account and ask GitHub Support for human identity review, not automated 2FA reset. Think: old phone number ownership, email at a domain you control, past billing receipts (Sponsors/Actions/Marketplace), SSH public key or GPG signature fingerprints from your commits, WHOIS matching your name, and ecosystem attestations (RubyGems maintainers confirming you own those packages). Put all that in one concise ticket and request escalation. In parallel, talk to RubyGems support about stewarding the gems if GitHub recovery stalls. They can add/transfer ownership with credible verification, so users aren’t stuck. Worst case, spin up a new GitHub, mirror the repos, and note the account transition in README/changelogs—plus a release on RubyGems pointing to the new home. Not ideal, but it keeps your users safe and the project alive while you push on account recovery.