[HN Gopher] Ipmitool Repository Archived, Developer Suspended by...
___________________________________________________________________
Ipmitool Repository Archived, Developer Suspended by GitHub
Author : marcodiego
Score : 133 points
Date : 2023-03-13 15:37 UTC (7 hours ago)
(HTM) web link (www.phoronix.com)
(TXT) w3m dump (www.phoronix.com)
| bayandin wrote:
| It looks related to an organisation he linked to
| https://github.com/YADRO-KNS. All its repos and repos of other
| people from it are archived as well.
|
| https://home.treasury.gov/policy-issues/financial-sanctions/...
| asciii wrote:
| Spot on here. The CHANGELOG has comments for YADRO product ids.
|
| > https://github.com/ipmitool/ipmitool/search?q=YADRO
| cft wrote:
| It looks like YADRO is making server hardware. IPMI is just
| enumerating server hardware in the linked GitHub.
| lamontcg wrote:
| The author works for YADRO:
|
| https://ru.linkedin.com/in/aamelkin
|
| Microsoft has to shut off his account due to his
| relationship with a company officially sanctioned by the US
| government.
| chatmasta wrote:
| It's ironic you link to his (apparently not suspended)
| profile on LinkedIn, which is also owned by Microsoft.
| [deleted]
| kvathupo wrote:
| That's very interesting: I'm not sure how to feel about this.
| On one hand, it aligns with my ethics to shut-down the
| operations of sanctioned companies to minimize their harm. On
| the other,
|
| 1. Ethics are relative
|
| 2. Should open-source contributions be dependent on such
| ethics?
|
| On (1), I'm sure non-Americans would have ethical qualms with
| our Defense companies. Would I be okay with the hypothetical of
| letting a non-American company stop open-source development on
| a useful Lockheed Martin tool?
|
| On (2), I have personally seen open-source contributions from
| sanctioned companies, e.g. Megvii. Is it fair to ban those
| employees (who may simply be unwilling to go through the hoops
| of immigration)?
|
| As an aside, perhaps this repo could move to GNU Savannah?
| firebaze wrote:
| > On one hand, it aligns with my ethics to shut-down the
| operations of sanctioned companies to minimize their harm.
|
| Only if the sanctions are warranted by ethics. Which they are
| not, in this case - there isn't anything online I can find
| which supports sanctioning this specific company.
|
| This is a repeating pattern in this conflict: even without
| substantial or even circumstantial proof that a russian
| company benefits from or at least tolerates the war, in the
| event Ukraine tells us to sanction the respective company, we
| have to obey or else.
|
| What do we expect? Should all russian companies shut down
| because of the war? Would this be what we expect from all
| western companies, like when we attacked Iraq because of
| Weapons of Mass Destruction?
|
| This is slowly really getting ridiculous. Even more so if
| this opens up an attack vector from even more non-friendlies
| because of an orphaned github account.
| kofejnik wrote:
| Every Russian company needs to be sanctioned. Especially a
| tech one.
| yencabulator wrote:
| As seen elsewhere in these HN comments:
| https://sanctions.nazk.gov.ua/en/sanction-company/6813/
|
| > Putin has publicly stated his concerns about Russia's
| access to microelectronics
|
| > To further increase pressure on Russia's electronics
| sector, the Department of State is designating numerous
| advanced Russian electronics entities.
|
| > Limited Liability Company Yadro Fab Dubna is implementing
| a project to create Russia's largest modern production
| plant for the production of circuit boards
| [deleted]
| rozab wrote:
| Nice job, more info here
| https://sanctions.nazk.gov.ua/en/sanction-company/6813/
| newsclues wrote:
| Is he Russian? Looks like he may be in Moscow, and there is a
| war...
| atomicUpdate wrote:
| For anyone that didn't RTFA:
|
| > There is no clear indication why GitHub blocked Amelkin but
| may have to do with him being based out of Moscow, Russia as
| his repositories do not appear otherwise controversial.
| rasz wrote:
| Server management tool with a potential of pushing backdoored
| update being controlled by someone residing in Moscow is
| plenty controversial.
| redprince wrote:
| Unless you know of the hurdles this hypothetical source
| code change would need to clear to have any effect. Then
| there is no controversy at all.
| cryptonector wrote:
| Reason: DMCA
|
| Public: Oof.
|
| vs
|
| Reason: War
|
| Public: Fork it!
|
| vs
|
| Reason: <unstated>
|
| Public: now what?
| lyind wrote:
| "Supply chain my attack!" -- The Leader
| ghostoftiber wrote:
| > a potential
|
| > residing in Moscow
|
| Guilty until proven innocent isn't a good look, especially
| when it comes down to where people live or their ethnic
| background.
| sam_lowry_ wrote:
| Ethnic? Rather succeptiple to thermo-rectile
| cryptoanslysis, as they call it jokingly in Russia.
| CameronNemo wrote:
| He is not being convicted of a crime, the software supply
| chain is just being locked down.
| jacob019 wrote:
| US law does not apply to foreign nationals residing in a
| foreign country. Russia is ruthlessly murdering their
| neighbors and has indicated that they are at war with the
| collective west. Russia has a long history of cyber
| espionage against the US and is actively engaged in
| Internet warfare. This is an entirely reasonable
| precaution by Microsoft. It's a sad moment.
| 1MachineElf wrote:
| Maybe not. Microsoft stands to gain by crippling the most
| popular FOSS BMC tool. They would rather everyone have to
| use Windows-centric proprietary alternatives.
| naikrovek wrote:
| yes, clearly they've crippled it... they're still hosting
| it and allowing people to fork and clone the repo.
|
| US export and import restrictions must be followed by
| companies who operate in the US. GitHub is one of those
| companies, and the developer in question is associated
| with a newly restricted company, so GitHub _must_ cease
| allowing that company to operate on its infrastructure.
| ms7m wrote:
| > US law does not apply to foreign nationals residing in
| a foreign country.
|
| I don't think parent meant it in the context of US Law,
| but more as a general statement, is it a reasonable
| precaution by MS to ban X solely on the actions of their
| government?
| jacob019 wrote:
| Although the presumption of innocence until proven guilty
| is a fundamental principle of US law and an essential
| part of our ideology, it is not a universal moral truth.
| In my opinion, it is justifiable and suitable to prohibit
| X from having access to sensitive infrastructure based
| solely on the actions of their government, especially
| when X is subject to the decisions of that government.
| jstarfish wrote:
| > is it a reasonable precaution by MS to ban X solely on
| the actions of their government?
|
| One could argue it's discriminatory; they banned him
| because he's Russian.
|
| ...which is the problem with this rhetoric.
|
| Russia and China are known to entice or coerce otherwise-
| innocuous civilians into acts of espionage. Their foreign
| policies explicitly exploit our presumptions of
| innocence, inclusivity and trust. Pre-emptive banning to
| avoid another SolarWinds is more than reasonable
| precaution; it's something that should have been done
| years ago.
|
| But in the meantime, by our own policies we're
| _obligated_ to allow foxes into the henhouse. We 're
| shamed for discriminating against foxes if we turn them
| away, and shamed again for asking questions about how the
| Great Chicken Massacre of 2023 was allowed to happen.
| Chaos engineering at its finest.
| jacob019 wrote:
| Entertaining analogy! I agree with your point, but we are
| not obligated by policy to allow foxes into the henhouse,
| rather we are obligated by our social norms.
| striking wrote:
| https://ru.linkedin.com/in/aamelkin
|
| > Alexander Amelkin - BIOS/BMC Team Lead - YADRO
|
| YADRO is a recently sanctioned Russian company
| denton-scratch wrote:
| There are always wars. USA is not at war with Russia - at
| least, not openly.
| dboreham wrote:
| For the curious, "archived" here means : repo is read-only but
| still exists.
| ashishb wrote:
| Any recommended automated mirroring tools to keep a backup of
| private GitHub repos to avoid the situation where your GitHub
| account is suspended?
| mzur wrote:
| I use this shell script with a cron job:
| https://gist.github.com/rodw/3073987 It can back up repos,
| issues and wikis.
| rsync wrote:
| I keep interesting and valuable repos in my rsync.net account
| and I use git to pull them directly: ssh
| user@rsync.net git clone mirror ... blah blah ...
|
| ... which is nice because I don't use my own bandwidth.
| Fatnino wrote:
| Isn't your working copy a backup?
| bob1029 wrote:
| A lot of people also use GH issues to track ideas/code
| snippets/etc.
| ashishb wrote:
| I have deleted local copies from my machine in the past.
|
| And when there are other contributors local copy is not
| guaranteed to be up to date unless you yourself are actively
| contributing as well.
| upon_drumhead wrote:
| I use https://github.com/qvl/ghbackup
| coffeeri wrote:
| If you are fine with self hosting a gitea instance, you'll be
| able to set up a pull mirror.
|
| https://docs.gitea.io/en-us/repo-mirror/#pulling-from-a-remo...
| ofchnofc wrote:
| [dead]
| neilv wrote:
| I suppose this is due to economic sanctions, but of course
| there's also the infosec concern.
|
| Much of "tech" right now is still cavalier about software
| provenance in general. And IPMI is one of the more sensitive
| points.
|
| I have a pretty warm-fuzzy aspirations about open source at its
| best: being collective effort, of people of goodwill, around the
| world, working together, for the benefit of all.
|
| It's tragic that our world has so much conflict, aggression,
| inequity, and other ills. Open source is one place that we've
| sometimes formed bridges despite this, but it's not entirely
| immune to the larger world problems.
| TheDesolate0 wrote:
| [dead]
| badrabbit wrote:
| There is a ton of Repos owned by Russians. It would be chaos if
| they suspended them for that alone. Maybe someone falsley
| reported one of his repos?
| 1MachineElf wrote:
| I'd bet GitHub's hardware, if they use any at all for their
| servers, has ipmitool installed.
|
| When you're in GitHub's position, how does your SBOM
| vulnerability management program handle it when you imperil your
| own infrastructure?
___________________________________________________________________
(page generated 2023-03-13 23:02 UTC)