Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. F-Droid 2.0(f-droid.org)
    75comments
  2. Two-tier encryption in the UK(macanorak.com)
    229comments
  3. Nokia Design Archive (2025)(aalto.fi)
    88comments
  4. GitHub has not removed malicious imitation software after 3 weeks(successfulsoftware.net)
    27comments
  5. Linux support is coming to Snapdragon X2 series(qualcomm.com)
    239comments
  6. WaveDigger: Dig into wireless signals to discover their physical locations(github.com/christianrowlands)
    2comments
  7. B5-BJ2 – Ice Cream Barges – Concrete Ship Constructors (2023)(thecretefleet.com)
    1comments
  8. Ideas on modernizing the open-source desktop(lwn.net)
    394comments
  9. The science of Monkey Island: can grog dissolve a metal mug that fast?(jgeekstudies.org)
    15comments
  10. Why is the human body so crap except for the liver?(dynomight.net)
    discuss
  11. Experiencing writing at our recent Chinese calligraphy workshop(viewsproject.wordpress.com)
    discuss
  12. RAM: the forgotten history (2024)(coredump.cx)
    2comments
  13. ArXiv receives multiyear commitments to support it as an independent nonprofit(arxiv.org)
    37comments
  14. Enjoy Every Sandwich(bradmontague.substack.com)
    61comments
  15. When the Debugger Lies(danielmangum.com)
    17comments
  16. Coulomb's law remains tricky to test at home(chillphysicsenjoyer.substack.com)
    12comments
  17. The newest ESP32 can run Linux and it's getting close to a Raspberry Pi(xda-developers.com)
    69comments
  18. VSCode's SSH Agent Is Bananas (2025)(fly.io)
    186comments
  19. Contrastive Language Models(contrastive-lm.notion.site)
    41comments
  20. The "Windows XP Box" (2003)(mini-itx.com)
    44comments
  21. The Year of Internal Tools(geocod.io)
    18comments
  22. Federal judge orders Texas to air condition all prisons by the end of 2029(texastribune.org)
    3comments
  23. LinkedIn wins court order blocking mass scraping of user data(therecord.media)
    20comments
  24. Fixing the Portobello Police Station Clock(pointinthecloud.com)
    112comments
  25. Virtio-nvgpu: Near-native Nvidia GPU access inside a KVM guest(github.com/nestrilabs)
    59comments
  26. Hackers influence ChatGPT and Gemini to direct users to scam centers(medium.com/arielsimon)
    34comments
  27. Dynamic Abliteration: Non-Destructive Refusal Suppression via Engram Steering(blog.madhukaraphatak.in)
    31comments
  28. Owners mourn spoiled food after firmware update bricks Samsung smart fridges(arstechnica.com)
    213comments
  29. What Is RLCD? The Secret Behind Jev(di-zhang-llm.github.io)
    4comments
  30. Why 'What's Opera, Doc?' looks like that(animationobsessive.substack.com)
    22comments

GitHub has not removed malicious imitation software after 3 weeks

85 pointsby 1h agosuccessfulsoftware.net
26 comments
41m agoHN ↗

If it's your software send a DMCA. They have a legally required timeframe to process those. If it's open source, however, then you don't have any valid DMCA claim.

36m agoHN ↗

Code can be open source while the name and logos are copyrighted and still enforceable via DMCA

30m agoHN ↗

That’s not how open source works.

Open source code is still copyrighted. What the license defines is rights that people have in distributing that code. If an unofficial repository is using open source code to ship malware, and the license that software had didn’t allow that, then the unofficial repository is still breaking copyright law despite the code being open source.

16m agoHN ↗

Also open source license doesn't grant use of trademarks, but I'm not sure that means DMCA applies.

40m agoHN ↗

Not exactly the same, but I've noticed a pretty sizable uptick in the number of spam/scam PR comments being left on GitHub (and a longer delay before they're removed after report).

Not the worst thing in the world, they're easy to spot, but I'd like to see GitHub invest more time in protecting their users from falling victim to these bad actors.

39m agoHN ↗

In the future just issue a DMCA takedown right away for cases like this, IMO.

37m agoHN ↗

Author of the post here. Github finally took the offending page down approximately 10 minutes after the post appeared on the front page of HN. Total coincidence. I'm sure!

Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.

And it seems they are able to do things very quickly, when they want to. Bastards.

35m agoHN ↗

It might not be a willingness issue as much as a bandwidth issue.

33m agoHN ↗

unwilling to provide proper support?

Just seems like a silly rational response to the same problem.

33m agoHN ↗

Yes,evidently bandwidth from HN unblocks takedown requests of malicious content.

30m agoHN ↗

Prioritization and escalation exists in most companies. I guarantee you that once an issue hits the HN front page, even engineers who might have totally different talks will get involved. (Never worked at GH or have talked to anyone there in years but this is how everything works pretty much everywhere)

25m agoHN ↗

The public shaming will continue until the internal incentives improve. Make sure to drop that HN thread link into the internal task tracker y'all. Don't forget to report to journalists if the severity warrants it (Brian Krebs, 404media, etc).

"Show me the incentive and I'll show you the outcome."

30m agoHN ↗

Good thing HN provided them some bandwidth to do their jobs.

29m agoHN ↗

Bandwidth can be bought with money, of which Microsoft made an extra $133.7 billion this year.

27m agoHN ↗

Sounds like they can afford elite customer support.

25m agoHN ↗

We know that coding agents have been pushing GH to its limits. Scaling is hard - especially staff. Maybe they aren't trying to scale support but I think it's reasonable to give them the benefit of doubt here, given what we know publicly

20m agoHN ↗

That’s a self-inflicted issue they should have properly planned for.

19m agoHN ↗

You’re saying this is a problem money can’t solve?

There’s no need for benefit of the doubt when it comes to the level of support provided by tech companies.

Bad support by tech companies is a conscious profit-preserving choice.

6m agoHN ↗

Microsoft is not some plucky upstart company with 12 employees and an unexpectedly popular product. We do not, in fact, need to give them the benefit of the doubt here.

8m agoHN ↗

Never thought I'd see the day when Microsoft is elite.

17m agoHN ↗

Moral of the story. If you want even the most basic level of support from Github, you need to get on the front page of HN first.

This also works for Google support.

And it seems they are able to do things very quickly, when they want to. Bastards.

I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.

It was already a problem before agents could automatically perform these actions.

And it’s not something you can really automate on their end either. At least not the judgement call on the removal. Imagine if there was a fully automated process and it inadvertently took down a legit project.

8m agoHN ↗

I wouldn’t chalk any of this up to malicious intent. I’m sure they are swamped with such requests.

Stalling in the hope that reporters won't escalate, instead of allocating a tiny bit of their billions in profit to hiring for this, is malicious in my book.

16m agoHN ↗

Just send DMCA if you want their attention, they act harshly and quickly. Even when it's false one.

32m agoHN ↗

why would anyone host commercial binary software on github or any other third party domain?

26m agoHN ↗

Pirates and crackers generally don't host stuff on their own domains. They don't want to pay for the bandwidth and they don't want to be traced.

17m agoHN ↗

They’re presumably too busy with keeping availability above nine sixes