Rendered at 11:03:55 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
hermitcrab 18 hours ago [-]
Author of the post here. Github finally took the offending page down approximately 10 minutes after the post appeared on the front page of HN. Total coincidence. I'm sure!
Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.
And it seems they are able to do things very quickly, when they want to. Bastards.
koolba 18 hours ago [-]
> Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.
This also works for Google support.
> And it seems they are able to do things very quickly, when they want to. Bastards.
I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
It was already a problem before agents could automatically perform these actions.
And it’s not something you can really automate on their end either. At least not the judgement call on the removal. Imagine if there was a fully automated process and it inadvertently took down a legit project.
debugnik 18 hours ago [-]
> I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
Stalling in the hope that reporters won't escalate, instead of allocating a tiny bit of their billions in profit to hiring for this, is malicious in my book.
amdsn 18 hours ago [-]
I had several small requests for moderation (deleting and banning spammers posting spam/crypto scam issues/PRs in my repos and ones I contribute to) answered within a day earlier this year after more than a decade of never needing to request moderation. I'm not defending GH here as it's obviously unacceptable that the OP's issue took this long, but they definitely do or at least did have mods. I would guess they need a lot more of them if something this serious went unaddressed, or maybe the ones I interacted with are now gone and have not been backfilled.
majorchord 18 hours ago [-]
Can you provide evidence of these claims?
csomar 18 hours ago [-]
I mean we are in the thread of evidence right now?
veverkap 18 hours ago [-]
GitHub support is full of amazing, hard working people.
It is also comically understaffed. This is not because they can't find people to work - it's not given the budget necessary.
nikanj 17 hours ago [-]
They might be amazing and hard working, but that doesn’t free them from the yoke of policy and script
ktm5j 17 hours ago [-]
I mean.. for better or worse, this is how corporate America works. Hiring to solve a problem that's not costing them money (and solving it doesn't make money) is probably not going to happen, especially with the current state of the economy. They have more of an obligation to make money for their investors than they do anything else, that's just how it works.
Paracompact 16 hours ago [-]
> They have more of an obligation to make money for their investors than they do anything else, that's just how it works
Where does this myth come from, and how does it survive? It's either an excuse for parasitic corporatism, or an expression of learned helplessness. Nobody has been successfully sued for prioritizing the long-term health and reputation of a company over self-starving quarterly profit.
Is there a perverse incentive toward the latter anyway? Yes. But it mostly serves current leadership, who are evaluated and paid on short horizons, at the expense of the long-term investors who own most of the equity.
"Accepting funding from investors puts you in a fiduciary role in which you’re responsible for managing their money and putting their needs above your own"
mindcrime 15 hours ago [-]
The reality is "it's complicated". But the strongest form of this - that "companies must maximize profits over ALL over concerns NO MATTER WHAT" is basically a myth. See:
So yeah, "fiduciary duty" is a real thing, but that's not quite the same thing as saying that every single decision has to be focused on nothing but profit maximization.
ktm5j 15 hours ago [-]
So you think making bad business decisions is holding up to fiduciary duty? You can't throw money at every problem that you'd like to solve, calling that malice is silly was the point I was trying to make.
mindcrime 10 hours ago [-]
> So you think making bad business decisions is holding up to fiduciary duty?
I didn't say anything remotely like that, so I'm going to assume you're not trying to have a good faith discussion here, and decline to participate any further. Have a nice day.
applfanboysbgon 14 hours ago [-]
Paying staff to avoid distributing literal malware on your platform is not a bad business decision. And even if it was - yes, bad business decisions are within the scope of fiduciary duty. Have you ever seen someone successfully sued under this clause for making a bad business decision, in your life? Fiduciary duty is more like, you can't take the money and run or pay your nephew a $10,000,000 salary to play ping pong in the office. As long as you're not doing something clearly, intentionally harmful to the business and investors, you're clear.
joe_the_user 14 hours ago [-]
Neglecting all other ethical duties beside profits is so close to malice it takes ...an, ah, expert, to tell you the differences and how important they are.
And this neglecting all duties besides profits thing is real, it is institutionalized by decisions of investors, by managers hired by investors, by regulators "captured" by investors and so-forth. It is the norm. But that doesn't it's a legal or ethical that a given manager or employee has, at least not currently.
15 hours ago [-]
tripletao 15 hours ago [-]
Nothing in that article says you're obligated to maximize profit, and you're not:
> To quote the U.S. Supreme Court opinion in the recent Hobby Lobby case: “Modern corporate law does not require for-profit corporations to pursue profit at the expense of everything else, and many do not.”
Executives are free to pursue near-term profit at the expense of everything else if they choose, and the shareholders are free to replace them if they don't. That's a choice by those executives or shareholders though, not an obligation.
ktm5j 15 hours ago [-]
I said it's their biggest priority, not their only priority... solving a problem that doesn't cost money and the solution doesn't make money is bottom of the barrel. Come on guys, be real.
usefulcat 14 hours ago [-]
FWIW I totally agree with that. What I (and several others) disagree with is the idea that the concept of fiduciary duty confers an obligation to pursue profit at the expense of all else.
Is there an incentive to do that? Yes, or at least it's obviously quite possible. But is there an obligation? No.
Relative to the comment you were responding to, it sounded like you were defending the idea that an obligation exists.
The distinction matters because if such an obligation did exist it would effectively excuse a lot of bad behavior.
tripletao 14 hours ago [-]
You used the word "obligation", not "priority". That's simply not correct, and it transfers responsibility from the people making these decisions to whatever nebulous system would enforce that "obligation".
If you look at the case law for fiduciary responsibility, then you'll find that executives have a strong obligation against self-dealing (decisions that clearly benefit them at the expense of the shareholder), but not much else. The "business judgment rule" makes it generally lawful for executives to make decisions that you, the shareholders, the judge, or anyone else might consider to be bad business judgment. It couldn't really be otherwise, since the difference between wasteful spending and a wise investment in the company's reputation might be unclear even decades later.
If shareholders disagree with an executive's business judgment, then their remedy is to fire that executive. That remedy has nothing specific to "making money"--the shareholders are just as free to fire a CEO for excessive attention to profit as insufficient.
usefulcat 16 hours ago [-]
Where on that page is there anything to indicate that hiring more QA or mods would be so bad as to be considered a breach of fiduciary duty? That seems like a pretty big exaggeration, at best.
This behavior is a matter of incentives, not obligations. No need to apologize for them.
"Fiduciary duty" does not mean "pursue profit to the exclusion of all other considerations".
mistrial9 16 hours ago [-]
many readers here have not experienced a standard of customer support that was common decades ago. Google in particular created a new standard for ignoring the customer on a large scale, in my own experiences. Secondly, the customer paid money to a company for service, while an emergent business form does not take money from the customer directly, blurring the definition of customer.
I strongly agree that failure to stand for consumer rights is both learned helplessness and an apologist cooperator psychology. CA Voter here.
usefulcat 16 hours ago [-]
> They have more of an obligation to make money for their investors
"Obligation" is the wrong word. Should be "incentive".
hyperhello 17 hours ago [-]
If we have no way to strike back, they will simply suck every drop of blood out the way you use every part of the buffalo. There is no way to escape Microsoft when they just buy everything and turn it into part of their garbage moat.
ruined 17 hours ago [-]
how does anyone expect to solve AI alignment when we can't even solve corporate alignment
ktm5j 17 hours ago [-]
Life sure ain't perfect.. not much you can do about that sometimes.
rcleveng 8 hours ago [-]
Unfortunately this is very true. It often takes someone pretty high up on the food chain to see it on HN, X, or get an email/LinkedIn message asking about something for it to become a priority.
I don't see that changing for any of the large companies unfortunately, anytime soon.
rkagerer 17 hours ago [-]
I’m sure they are swamped with such requests
Then maybe they should be growing their customer support capacity along with their business. It drives me crazy how big companies have normalized cutting those departments down to anemic proportions. Especially those where you're a paying customer.
someonebaggy 16 hours ago [-]
Remember when Google lost a lawsuit for defaming a business in their AI search results?
alightsoul 17 hours ago [-]
YouTube already does it autonomously with seemingly no legal consequences for them because you agree to it in their tos
nullc 14 hours ago [-]
YouTube also totally fails to remove obvious fraud videos, even ones they mark verified. (If someone takes over a verified channel and renames it, they keep the verified flag). -- also with no legal consequences.
elAhmo 18 hours ago [-]
It is a problem they could solve if they want to. They have billions of profits per quarter.
They just don't want to. Not malicious, just ignorant and disrespectful of their users.
dogleash 17 hours ago [-]
>I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
It's malice from whoever is responsible for under-staffing. It's also malice to prioritize the squeaky wheel for optics; it's intentional to reduce the spread of the knowledge of how unresponsive they are.
vkou 17 hours ago [-]
> I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
Handling these requests at whatever scale they operate is their responsibility.
Nobody held a gun to their head and forced them to take on all of their customers.
elAhmo 18 hours ago [-]
Describes pretty much any of the big companies. For example, I have seen numerous times people got their account locked on Google, or their app stuck in limbo at Apple, and then after post becomes viral all problems get solved.
latexr 17 hours ago [-]
Apple in particular is mocked because they explicitly say (used to say?) “going to the press doesn’t help”, but they’ve shown time and again that it’s the most effective way to get them to take action.
superze 1 hours ago [-]
Love the conclusion at the end, because it summarizes GitHub leadership pretty well.
zamalek 17 hours ago [-]
For this specific case, a DMCA would have gotten you a much faster take down. As far as I can tell it's automated. Sure, they could appeal it but then the malware nature of it would be in the crosshairs of the reviewer.
Not excusing their slow response, though.
ajmurmann 18 hours ago [-]
It might not be a willingness issue as much as a bandwidth issue.
post-it 18 hours ago [-]
Bandwidth can be bought with money, of which Microsoft made an extra $133.7 billion this year.
ajmurmann 18 hours ago [-]
We know that coding agents have been pushing GH to its limits. Scaling is hard - especially staff. Maybe they aren't trying to scale support but I think it's reasonable to give them the benefit of doubt here, given what we know publicly
cwillu 18 hours ago [-]
Microsoft is not some plucky upstart company with 12 employees and an unexpectedly popular product. We do not, in fact, need to give them the benefit of the doubt here.
ajmurmann 12 hours ago [-]
From having worked at abd four startups and massive companies, the company being massive actually might make some things harder.
punchmesan 10 hours ago [-]
Like, philosophically? Because companies on Microsoft's scale can move heaven and earth to accomplish whatever they please regardless of difficulty. If it's difficult that just means it costs more money. Microsoft is planning to put ML infrastructure in space, but you're saying that building a support org, which Microsoft is very familiar with, is too hard because they're so big?
dualvariable 17 hours ago [-]
Having "hackers" on this site giving the benefit of doubt to companies clearing hundreds of billions of dollars in revenue per year will never cease to stop being ironic to me...
ChickeNES 16 hours ago [-]
On the site run by a VC firm? Why is that a shock? Besides, hacker does not mean being a kneejerking reactionary against corporations.
landdate 8 hours ago [-]
I don't think you understand the website if you think this is some revelation. The people here are social climbing demons who will earn their reward in hell. But the term hackers is apt, they are hacks and are hacking their soul to pieces. If only you or I had courage to actually do something other than to make snide remarks at their expense. Introspection is almost as bad as ambition.
ndiddy 15 hours ago [-]
This is one of the things I dislike the most about large tech companies. They get way more customers than they can adequately provide support/moderation for and either offer no support or shitty automated support. Then when something falls through the cracks people always go "what do you expect them to do, hire enough people?" Yeah I do!
veverkap 18 hours ago [-]
They aren't trying to scale support. If anything, they are trying to throw AI at the problem. The support team is understaffed and overwhelmed.
iAMkenough 18 hours ago [-]
That’s a self-inflicted issue they should have properly planned for.
cj 18 hours ago [-]
You’re saying this is a problem money can’t solve?
There’s no need for benefit of the doubt when it comes to the level of support provided by tech companies.
Bad support by tech companies is a conscious profit-preserving choice.
whateveracct 18 hours ago [-]
They have to dump all that free cash into data centers, sorry
kstrauser 18 hours ago [-]
Never thought I'd see the day when Microsoft is elite.
NobodyNada 18 hours ago [-]
Sounds like they can afford elite customer support.
18 hours ago [-]
pllbnk 15 hours ago [-]
I have for a long time said that the way to regulate these huge companies would be to have government-mandated SLOs for live support.
For example (simplified), if a user makes a call, a person with sufficient privileges to handle 90% of the cases should answer on the other end within 2 minutes. If the case cannot be handled, the higher-up with privileges to handle 99% of the cases should be reached within 5 minutes. And to be fair, it should be mandated for all companies, not only FAANG-like.
But a company like Meta (for example) with a billion customers would then have to decide whether they want to work on quality improvements for their services or whether they would like to hire a million technical support staff.
ajmurmann 10 hours ago [-]
If users value support so much, you should start a competitor with excellent support. I suspect though that very few users are willing to pay the additional cost.
pllbnk 6 hours ago [-]
Once in a while support is truly needed around the less frequently used paths in the system but impossible to reach. Most users don't need it, but those comparatively few that do really value it. Problem is, these companies are so entrenched, in some cases there is literally nowhere else to go.
tliltocatl 3 hours ago [-]
Abuse reports aren't even done by users. That's a classical externality.
iAMkenough 18 hours ago [-]
Good thing HN provided them some bandwidth to do their jobs.
cyanydeez 18 hours ago [-]
unwilling to provide proper support?
Just seems like a silly rational response to the same problem.
locknitpicker 18 hours ago [-]
Yes,evidently bandwidth from HN unblocks takedown requests of malicious content.
ajmurmann 18 hours ago [-]
Prioritization and escalation exists in most companies. I guarantee you that once an issue hits the HN front page, even engineers who might have totally different talks will get involved. (Never worked at GH or have talked to anyone there in years but this is how everything works pretty much everywhere)
locknitpicker 3 hours ago [-]
> Prioritization and escalation exists in most companies.
Yes, indeed public awareness of a problem affects how an issue is reprioritized. Some companies even employ web scrapers to do sentiment analysis at each release, and visible issues do get bumped to high priority.
It's amusing how some people in this thread try to pretend this doesn't happen, and make these bold assertions with a straight face in replies to people who were in actual meetings where issues were escalated because of this.
toomuchtodo 18 hours ago [-]
The public shaming will continue until the internal incentives improve. Make sure to drop that HN thread link into the internal task tracker y'all. Don't forget to report to journalists if the severity warrants it (Brian Krebs, 404media, etc).
"Show me the incentive and I'll show you the outcome."
monster_truck 17 hours ago [-]
They're generally extremely quick about this if you ping ~anyone on the security team with the offending url and a link to the real repo. There is a long ongoing game of cat & mouse against malware in repackaged things like first party windows utilities to leverage the signed binaries.
hermitcrab 14 hours ago [-]
>if you ping ~anyone on the security team
And how I am supposed to know who they are or how to reach them?
what is surprising that's most big companies, post on social media and they start caring. probably because they get a bunch of spam in their reports and it's hard to filter through.
alightsoul 17 hours ago [-]
This was not my experience at all. Someone on the bitchat android commented with a virus, reported it and was taken down 2 hours later
kachnuv_ocasek 17 hours ago [-]
Hacker News saves the day once again!
nikanj 17 hours ago [-]
Same goes for all companies bigger than a startup. The first line of support is AI, the second line is clueless, and the third level is powerless. HN is the only way to reach a human with both ability and willingness to help
hsuduebc2 18 hours ago [-]
Just send DMCA if you want their attention, they act harshly and quickly. Even when it's false one.
If GitHub staff is still reading this thread, maybe you can take down https://screenmemory.github.io/ as well. I reported it 4 weeks ago, ticket ID 4703161
OCTAGRAM 18 hours ago [-]
I recently found "free" version of Lossless Scaling on GitHub. The release installer is definitely malware. It took GitHub 3 days to shutdown malware distribution. Category of my ticket was malware report, not copyright infringe
hermitcrab 17 hours ago [-]
Author here. I initially reported it as an imitation. A few days later I added evidence that it was malware.
Havoc 18 hours ago [-]
They’re presumably too busy with keeping availability above nine sixes
Please give GitHub some slack, just check out the massive number of copilot changes they've had to release over the last 3 weeks (https://github.blog/changelog/). There's clearly little time left for security, maintenance, or reliability work.
tgsovlerkhgsel 15 hours ago [-]
Lack of moderation is an issue everywhere, because there are few consequences for the platforms.
Booking.com kept a clearly fraudulent listing (images clearly stolen from another Booking.com listing with mirroring + some filters) fully online for at least two days (I got distracted and stopped taking daily screenshots after that). I just got a response that they've taken it down almost 10 days after I had initially reported it (although I think they marked it as not bookable some time before that).
joshuat 19 hours ago [-]
Not exactly the same, but I've noticed a pretty sizable uptick in the number of spam/scam PR comments being left on GitHub (and a longer delay before they're removed after report).
Not the worst thing in the world, they're easy to spot, but I'd like to see GitHub invest more time in protecting their users from falling victim to these bad actors.
icemanvault 16 hours ago [-]
These kinds of imitation attacks seem to be getting more common. It’s not just random malware anymore — some of them are getting surprisingly polished and even use the real product name and logo.
Interesting (and a bit sad) how visibility on HN seems to speed things up on GitHub’s side.
msalihb 18 hours ago [-]
I found a page that serving e-books I've purchased on github. It is a bit bad feeling
nixgeek 17 hours ago [-]
I see OP edited their post claiming getting to HN's front helped.
I think the likelihood GitHub did something within 10 minutes of a post appearing on HN's front page is approximately zero.
Nobody in GitHub Trust & Safety is sat there watching HN.
An executive or communications professional who might have heard it got on HN, or seen it appear in a tool monitoring Microsoft and GitHub's mentions across the internet, and who then flagged the post, Trust & Safety would probably spend *more than 10 minutes* noticing the email or Teams message, then trying to find the right ticket internally. Then after locating the ticket you still have to investigate the facts, discuss, and click buttons to ban/delete the user.
It's (much) more likely this sat in a queue until someone got to it and the timing of it being on HN is a complete coincidence.
Sebguer 16 hours ago [-]
I think you wildly underestimate how much more empowered the people monitoring social media escalations are versus the standard front-line support. In a clear-cut case like this I can absolutely imagine someone getting pinged and pressing the 'kill bad thing' button immediately after the post hitting the front page, because I've seen this happen many times.
hyperhello 17 hours ago [-]
It’s not a coincidence if they had already found the problem, wrote up the solution, primed it for action, and then it sat in some “management queue” for essentially forever, until someone called someone with a go.
hermitcrab 17 hours ago [-]
It's a hell of a coincidence.
lightedman 15 hours ago [-]
"Nobody in GitHub Trust & Safety is sat there watching HN"
Please, any competent software dev business has eyes on this page on an hourly basis.
I'm in aerospace and we're crawling on this site, all the way at the top levels.
joe_the_user 14 hours ago [-]
the timing of it being on HN is a complete coincidence.
The lengths people will go to "never attribute to malice..." are pretty impressive in these days of baldly stated or visible malice from the top.
kelnos 13 hours ago [-]
If they were using your logo, you could have sent a DMCA takedown notice. That would have likely gotten a faster, more serious response.
MBCook 18 hours ago [-]
What do you know. Apple’s “never run to the media it never helps anything” rule works just as well with GitHub.
kg 19 hours ago [-]
In the future just issue a DMCA takedown right away for cases like this, IMO.
18 hours ago [-]
hannob 17 hours ago [-]
Welcome to the club!
There's an impersonation profile of me on Github (username happyhannob). I've reported it a while ago, received the same automated message, and no reaction otherwise. It's still online.
I guess you can't expect basic fraud prevention from a company currently building the future with AI...
revexos 17 hours ago [-]
Seems like they don't even care
josefritzishere 18 hours ago [-]
[dead]
jay73763 18 hours ago [-]
why would anyone host commercial binary software on github or any other third party domain?
hermitcrab 18 hours ago [-]
Pirates and crackers generally don't host stuff on their own domains. They don't want to pay for the bandwidth and they don't want to be traced.
sgskinner 18 hours ago [-]
I think they’re alluding to OP not hosting their own downloads.
hermitcrab 18 hours ago [-]
I am the OP. I host my own downloads on my own domain and nowhere else. Only the malicious imitation is hosted on Github.
someonebaggy 19 hours ago [-]
If it's your software send a DMCA. They have a legally required timeframe to process those. If it's open source, however, then you don't have any valid DMCA claim.
hnlmorg 18 hours ago [-]
That’s not how open source works.
Open source code is still copyrighted. What the license defines is rights that people have in distributing that code. If an unofficial repository is using open source code to ship malware, and the license that software had didn’t allow that, then the unofficial repository is still breaking copyright law despite the code being open source.
someonebaggy 18 hours ago [-]
There's no open source license that prohibits derivative works that are malware.
whateveracct 18 hours ago [-]
i think it's in the spirit of it, which is enough for a DMCA lol
someonebaggy 17 hours ago [-]
Um no, you have to send it about an actual copyright violation, not just because you don't like something.
It's not illegal to send an incorrect one by mistake but GitHub probably won't process it. It's illegal to send an incorrect one intentionally. Now that it's been pointed out to you that making malware isn't a copyright violation, it's intentional if you send a DMCA anyway.
NewJazz 18 hours ago [-]
Also open source license doesn't grant use of trademarks, but I'm not sure that means DMCA applies.
93po 18 hours ago [-]
Code can be open source while the name and logos are copyrighted and still enforceable via DMCA
rpdillon 17 hours ago [-]
You're thinking of trademarks. Different body of law.
Logos can be part of both. A sufficiently unique logo (e.g. not just the name in Times New Roman) is absolutely copyrighted and an image of it cannot be distributed/reproduced without authorization unless fair use, which the malware project is not.
You're correct I was overly broad about the actual name use being DMCA-able though.
nomel 16 hours ago [-]
You can have copyright open source code, which is what allows open source licenses to enforce their terms. Open source doesn't mean "free to do whatever you want". There are very restrictive open source licenses, and you can deviate from the common open source licenses.
Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.
And it seems they are able to do things very quickly, when they want to. Bastards.
This also works for Google support.
> And it seems they are able to do things very quickly, when they want to. Bastards.
I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.
It was already a problem before agents could automatically perform these actions.
And it’s not something you can really automate on their end either. At least not the judgement call on the removal. Imagine if there was a fully automated process and it inadvertently took down a legit project.
Stalling in the hope that reporters won't escalate, instead of allocating a tiny bit of their billions in profit to hiring for this, is malicious in my book.
It is also comically understaffed. This is not because they can't find people to work - it's not given the budget necessary.
Where does this myth come from, and how does it survive? It's either an excuse for parasitic corporatism, or an expression of learned helplessness. Nobody has been successfully sued for prioritizing the long-term health and reputation of a company over self-starving quarterly profit.
Is there a perverse incentive toward the latter anyway? Yes. But it mostly serves current leadership, who are evaluated and paid on short horizons, at the expense of the long-term investors who own most of the equity.
"Accepting funding from investors puts you in a fiduciary role in which you’re responsible for managing their money and putting their needs above your own"
https://corpgov.law.harvard.edu/2012/06/26/the-shareholder-v...
https://www.legislate.ai/blog/does-the-law-require-public-co...
https://lawreview.law.ucdavis.edu/archives/56/5/end-sharehol...
https://news.ycombinator.com/item?id=20325023
https://en.wikipedia.org/wiki/Shareholder_value
So yeah, "fiduciary duty" is a real thing, but that's not quite the same thing as saying that every single decision has to be focused on nothing but profit maximization.
I didn't say anything remotely like that, so I'm going to assume you're not trying to have a good faith discussion here, and decline to participate any further. Have a nice day.
And this neglecting all duties besides profits thing is real, it is institutionalized by decisions of investors, by managers hired by investors, by regulators "captured" by investors and so-forth. It is the norm. But that doesn't it's a legal or ethical that a given manager or employee has, at least not currently.
> To quote the U.S. Supreme Court opinion in the recent Hobby Lobby case: “Modern corporate law does not require for-profit corporations to pursue profit at the expense of everything else, and many do not.”
https://www.nytimes.com/roomfordebate/2015/04/16/what-are-co...
Executives are free to pursue near-term profit at the expense of everything else if they choose, and the shareholders are free to replace them if they don't. That's a choice by those executives or shareholders though, not an obligation.
Is there an incentive to do that? Yes, or at least it's obviously quite possible. But is there an obligation? No.
Relative to the comment you were responding to, it sounded like you were defending the idea that an obligation exists.
The distinction matters because if such an obligation did exist it would effectively excuse a lot of bad behavior.
If you look at the case law for fiduciary responsibility, then you'll find that executives have a strong obligation against self-dealing (decisions that clearly benefit them at the expense of the shareholder), but not much else. The "business judgment rule" makes it generally lawful for executives to make decisions that you, the shareholders, the judge, or anyone else might consider to be bad business judgment. It couldn't really be otherwise, since the difference between wasteful spending and a wise investment in the company's reputation might be unclear even decades later.
If shareholders disagree with an executive's business judgment, then their remedy is to fire that executive. That remedy has nothing specific to "making money"--the shareholders are just as free to fire a CEO for excessive attention to profit as insufficient.
This behavior is a matter of incentives, not obligations. No need to apologize for them.
"Fiduciary duty" does not mean "pursue profit to the exclusion of all other considerations".
I strongly agree that failure to stand for consumer rights is both learned helplessness and an apologist cooperator psychology. CA Voter here.
"Obligation" is the wrong word. Should be "incentive".
I don't see that changing for any of the large companies unfortunately, anytime soon.
Then maybe they should be growing their customer support capacity along with their business. It drives me crazy how big companies have normalized cutting those departments down to anemic proportions. Especially those where you're a paying customer.
They just don't want to. Not malicious, just ignorant and disrespectful of their users.
It's malice from whoever is responsible for under-staffing. It's also malice to prioritize the squeaky wheel for optics; it's intentional to reduce the spread of the knowledge of how unresponsive they are.
Handling these requests at whatever scale they operate is their responsibility.
Nobody held a gun to their head and forced them to take on all of their customers.
Not excusing their slow response, though.
There’s no need for benefit of the doubt when it comes to the level of support provided by tech companies.
Bad support by tech companies is a conscious profit-preserving choice.
For example (simplified), if a user makes a call, a person with sufficient privileges to handle 90% of the cases should answer on the other end within 2 minutes. If the case cannot be handled, the higher-up with privileges to handle 99% of the cases should be reached within 5 minutes. And to be fair, it should be mandated for all companies, not only FAANG-like.
But a company like Meta (for example) with a billion customers would then have to decide whether they want to work on quality improvements for their services or whether they would like to hire a million technical support staff.
Just seems like a silly rational response to the same problem.
Yes, indeed public awareness of a problem affects how an issue is reprioritized. Some companies even employ web scrapers to do sentiment analysis at each release, and visible issues do get bumped to high priority.
It's amusing how some people in this thread try to pretend this doesn't happen, and make these bold assertions with a straight face in replies to people who were in actual meetings where issues were escalated because of this.
"Show me the incentive and I'll show you the outcome."
And how I am supposed to know who they are or how to reach them?
Fraud
Do the ends justify the means?
https://en.wikipedia.org/wiki/Consequentialism
> ping ~anyone on the security team
> HN provided them some bandwidth
> also works for Google support
> answered within a day earlier this year
> no reaction otherwise. It's still online.
> app stuck in limbo at Apple
https://en.wikipedia.org/wiki/Cargo_cult_programming
> given what we know publicly
> thread of evidence
https://en.wikipedia.org/wiki/Anecdotal_evidence
https://lowendbox.com/blog/will-github-ever-remove-this-null...
Booking.com kept a clearly fraudulent listing (images clearly stolen from another Booking.com listing with mirroring + some filters) fully online for at least two days (I got distracted and stopped taking daily screenshots after that). I just got a response that they've taken it down almost 10 days after I had initially reported it (although I think they marked it as not bookable some time before that).
Not the worst thing in the world, they're easy to spot, but I'd like to see GitHub invest more time in protecting their users from falling victim to these bad actors.
I think the likelihood GitHub did something within 10 minutes of a post appearing on HN's front page is approximately zero.
Nobody in GitHub Trust & Safety is sat there watching HN.
An executive or communications professional who might have heard it got on HN, or seen it appear in a tool monitoring Microsoft and GitHub's mentions across the internet, and who then flagged the post, Trust & Safety would probably spend *more than 10 minutes* noticing the email or Teams message, then trying to find the right ticket internally. Then after locating the ticket you still have to investigate the facts, discuss, and click buttons to ban/delete the user.
It's (much) more likely this sat in a queue until someone got to it and the timing of it being on HN is a complete coincidence.
Please, any competent software dev business has eyes on this page on an hourly basis.
I'm in aerospace and we're crawling on this site, all the way at the top levels.
The lengths people will go to "never attribute to malice..." are pretty impressive in these days of baldly stated or visible malice from the top.
There's an impersonation profile of me on Github (username happyhannob). I've reported it a while ago, received the same automated message, and no reaction otherwise. It's still online.
I guess you can't expect basic fraud prevention from a company currently building the future with AI...
Open source code is still copyrighted. What the license defines is rights that people have in distributing that code. If an unofficial repository is using open source code to ship malware, and the license that software had didn’t allow that, then the unofficial repository is still breaking copyright law despite the code being open source.
It's not illegal to send an incorrect one by mistake but GitHub probably won't process it. It's illegal to send an incorrect one intentionally. Now that it's been pointed out to you that making malware isn't a copyright violation, it's intentional if you send a DMCA anyway.
EDIT: e.g. https://www.mozilla.org/en-US/foundation/trademarks/policy/
You're correct I was overly broad about the actual name use being DMCA-able though.
https://en.wikipedia.org/wiki/Software_copyright
Now, projects might choose to license their logo permissively, but that's an active choice.