Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. F-Droid 2.0(f-droid.org)
    102comments
  2. Show HN: Whiteboard (YC W26) – An open-source IDE for thoughtful software design(github.com/devdotfast)
    3comments
  3. Two-tier encryption in the UK(macanorak.com)
    264comments
  4. WaveDigger: Dig into wireless signals to discover their physical locations(github.com/christianrowlands)
    4comments
  5. Nokia Design Archive (2025)(aalto.fi)
    94comments
  6. GitHub has not removed malicious imitation software after 3 weeks(successfulsoftware.net)
    56comments
  7. Google’s Project Suncatcher to put ML infrastructure in space(blog.google)
    13comments
  8. Toyota is taking the Corolla electric(electrek.co)
    18comments
  9. Apple iPhone 4 “Antennagate” Q&A (2010) [video](youtube.com)
    5comments
  10. B5-BJ2 – Ice Cream Barges – Concrete Ship Constructors (2023)(thecretefleet.com)
    3comments
  11. Search – A small, fast WebKit browser for macOS(github.com/driceroland)
    —discuss
  12. Linux support is coming to Snapdragon X2 series(qualcomm.com)
    244comments
  13. The forgotten battle of East Lansing(eastlansinginfo.news)
    —discuss
  14. Experiencing writing at our recent Chinese calligraphy workshop(viewsproject.wordpress.com)
    1comments
  15. Ideas on modernizing the open-source desktop(lwn.net)
    420comments
  16. The science of Monkey Island: can grog dissolve a metal mug that fast?(jgeekstudies.org)
    19comments
  17. My Weird New Hobby: Wandering Around Tokyo on Google Maps(ahmedhossamdev.com)
    1comments
  18. Geothermal heat map of US hot springs(soakingsprings.com)
    3comments
  19. Book review: Is parallel programming hard, and, if so, what can you do about it?(ahelwer.ca)
    —discuss
  20. RAM: the forgotten history (2024)(coredump.cx)
    3comments
  21. When the Debugger Lies(danielmangum.com)
    17comments
  22. ArXiv receives multiyear commitments to support it as an independent nonprofit(arxiv.org)
    38comments
  23. Enjoy Every Sandwich(bradmontague.substack.com)
    80comments
  24. Coulomb's law remains tricky to test at home(chillphysicsenjoyer.substack.com)
    16comments
  25. The newest ESP32 can run Linux and it's getting close to a Raspberry Pi(xda-developers.com)
    84comments
  26. VSCode's SSH Agent Is Bananas (2025)(fly.io)
    190comments
  27. Contrastive Language Models(contrastive-lm.notion.site)
    46comments
  28. Oracle cites 'force majeure' to shield itself on controversial data center(bloomberg.com)
    92comments
  29. The "Windows XP Box" (2003)(mini-itx.com)
    45comments
  30. Fixing the Portobello Police Station Clock(pointinthecloud.com)
    113comments

GitHub has not removed malicious imitation software after 3 weeks

137 pointsby 2h agosuccessfulsoftware.net
54 comments
1h agoHN ↗

If it's your software send a DMCA. They have a legally required timeframe to process those. If it's open source, however, then you don't have any valid DMCA claim.

1h agoHN ↗

Code can be open source while the name and logos are copyrighted and still enforceable via DMCA

35m agoHN ↗

Which project copyrighted its name and logo?

1h agoHN ↗

That’s not how open source works.

Open source code is still copyrighted. What the license defines is rights that people have in distributing that code. If an unofficial repository is using open source code to ship malware, and the license that software had didn’t allow that, then the unofficial repository is still breaking copyright law despite the code being open source.

1h agoHN ↗

Also open source license doesn't grant use of trademarks, but I'm not sure that means DMCA applies.

36m agoHN ↗

There's no open source license that prohibits derivative works that are malware.

32m agoHN ↗

i think it's in the spirit of it, which is enough for a DMCA lol

1h agoHN ↗

Not exactly the same, but I've noticed a pretty sizable uptick in the number of spam/scam PR comments being left on GitHub (and a longer delay before they're removed after report).

Not the worst thing in the world, they're easy to spot, but I'd like to see GitHub invest more time in protecting their users from falling victim to these bad actors.

1h agoHN ↗

In the future just issue a DMCA takedown right away for cases like this, IMO.

1h agoHN ↗

Author of the post here. Github finally took the offending page down approximately 10 minutes after the post appeared on the front page of HN. Total coincidence. I'm sure!

Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.

And it seems they are able to do things very quickly, when they want to. Bastards.

1h agoHN ↗

It might not be a willingness issue as much as a bandwidth issue.

1h agoHN ↗

unwilling to provide proper support?

Just seems like a silly rational response to the same problem.

1h agoHN ↗

Yes,evidently bandwidth from HN unblocks takedown requests of malicious content.

1h agoHN ↗

Prioritization and escalation exists in most companies. I guarantee you that once an issue hits the HN front page, even engineers who might have totally different talks will get involved. (Never worked at GH or have talked to anyone there in years but this is how everything works pretty much everywhere)

1h agoHN ↗

The public shaming will continue until the internal incentives improve. Make sure to drop that HN thread link into the internal task tracker y'all. Don't forget to report to journalists if the severity warrants it (Brian Krebs, 404media, etc).

"Show me the incentive and I'll show you the outcome."

1h agoHN ↗

Good thing HN provided them some bandwidth to do their jobs.

1h agoHN ↗

Bandwidth can be bought with money, of which Microsoft made an extra $133.7 billion this year.

1h agoHN ↗

Sounds like they can afford elite customer support.

1h agoHN ↗

We know that coding agents have been pushing GH to its limits. Scaling is hard - especially staff. Maybe they aren't trying to scale support but I think it's reasonable to give them the benefit of doubt here, given what we know publicly

1h agoHN ↗

That’s a self-inflicted issue they should have properly planned for.

1h agoHN ↗

You’re saying this is a problem money can’t solve?

There’s no need for benefit of the doubt when it comes to the level of support provided by tech companies.

Bad support by tech companies is a conscious profit-preserving choice.

54m agoHN ↗

Microsoft is not some plucky upstart company with 12 employees and an unexpectedly popular product. We do not, in fact, need to give them the benefit of the doubt here.

28m agoHN ↗

They aren't trying to scale support. If anything, they are trying to throw AI at the problem. The support team is understaffed and overwhelmed.

5m agoHN ↗

Having "hackers" on this site giving the benefit of doubt to companies clearing hundreds of billions of dollars in revenue per year will never cease to stop being ironic to me...

56m agoHN ↗

Never thought I'd see the day when Microsoft is elite.

34m agoHN ↗

They have to dump all that free cash into data centers, sorry

1h agoHN ↗

Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.

This also works for Google support.

And it seems they are able to do things very quickly, when they want to. Bastards.

I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.

It was already a problem before agents could automatically perform these actions.

And it’s not something you can really automate on their end either. At least not the judgement call on the removal. Imagine if there was a fully automated process and it inadvertently took down a legit project.

56m agoHN ↗

I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.

Stalling in the hope that reporters won't escalate, instead of allocating a tiny bit of their billions in profit to hiring for this, is malicious in my book.

43m agoHN ↗

I mean we are in the thread of evidence right now?

30m agoHN ↗

GitHub support is full of amazing, hard working people.

It is also comically understaffed. This is not because they can't find people to work - it's not given the budget necessary.

16m agoHN ↗

They might be amazing and hard working, but that doesn’t free them from the yoke of policy and script

38m agoHN ↗

I had several small requests for moderation (deleting and banning spammers posting spam/crypto scam issues/PRs in my repos and ones I contribute to) answered within a day earlier this year after more than a decade of never needing to request moderation. I'm not defending GH here as it's obviously unacceptable that the OP's issue took this long, but they definitely do or at least did have mods. I would guess they need a lot more of them if something this serious went unaddressed, or maybe the ones I interacted with are now gone and have not been backfilled.

29m agoHN ↗

It is a problem they could solve if they want to. They have billions of profits per quarter.

They just don't want to. Not malicious, just ignorant and disrespectful of their users.

20m agoHN ↗

I’m sure they are swamped with such requests

Then maybe they should be growing their customer support capacity along with their business. It drives me crazy how big companies have normalized cutting those departments down to anemic proportions. Especially those where you're a paying customer.

18m agoHN ↗

I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.

It's malice from whoever is responsible for under-staffing. It's also malice to prioritize the squeaky wheel for optics; it's intentional to reduce the spread of the knowledge of how unresponsive they are.

4m agoHN ↗

YouTube already does it autonomously with seemingly no legal consequences for them because you agree to it in their tos

1h agoHN ↗

Just send DMCA if you want their attention, they act harshly and quickly. Even when it's false one.

30m agoHN ↗

Describes pretty much any of the big companies. For example, I have seen numerous times people got their account locked on Google, or their app stuck in limbo at Apple, and then after post becomes viral all problems get solved.

6m agoHN ↗

Apple in particular is mocked because they explicitly say (used to say?) “going to the press doesn’t help”, but they’ve shown time and again that it’s the most effective way to get them to take action.

17m agoHN ↗

Same goes for all companies bigger than a startup. The first line of support is AI, the second line is clueless, and the third level is powerless. HN is the only way to reach a human with both ability and willingness to help

6m agoHN ↗

This was not my experience at all. Someone on the bitchat android commented with a virus, reported it and was taken down 2 hours later

1h agoHN ↗

why would anyone host commercial binary software on github or any other third party domain?

1h agoHN ↗

Pirates and crackers generally don't host stuff on their own domains. They don't want to pay for the bandwidth and they don't want to be traced.

42m agoHN ↗

I think they’re alluding to OP not hosting their own downloads.

35m agoHN ↗

I am the OP. I host my own downloads on my own domain and nowhere else. Only the malicious imitation is hosted on Github.

1h agoHN ↗

They’re presumably too busy with keeping availability above nine sixes

38m agoHN ↗

I recently found "free" version of Lossless Scaling on GitHub. The release installer is definitely malware. It took GitHub 3 days to shutdown malware distribution. Category of my ticket was malware report, not copyright infringe

27m agoHN ↗

I found a page that serving e-books I've purchased on github. It is a bit bad feeling

27m agoHN ↗

What do you know. Apple’s “never run to the media it never helps anything” rule works just as well with GitHub.

23m agoHN ↗

Welcome to the club!

There's an impersonation profile of me on Github (username happyhannob). I've reported it a while ago, received the same automated message, and no reaction otherwise. It's still online.

I guess you can't expect basic fraud prevention from a company currently building the future with AI...