[HN Gopher] Ipmitool Repository Archived, Developer Suspended by...
       ___________________________________________________________________
        
       Ipmitool Repository Archived, Developer Suspended by GitHub
        
       Author : marcodiego
       Score  : 133 points
       Date   : 2023-03-13 15:37 UTC (7 hours ago)
        
 (HTM) web link (www.phoronix.com)
 (TXT) w3m dump (www.phoronix.com)
        
       | bayandin wrote:
       | It looks related to an organisation he linked to
       | https://github.com/YADRO-KNS. All its repos and repos of other
       | people from it are archived as well.
       | 
       | https://home.treasury.gov/policy-issues/financial-sanctions/...
        
         | asciii wrote:
         | Spot on here. The CHANGELOG has comments for YADRO product ids.
         | 
         | > https://github.com/ipmitool/ipmitool/search?q=YADRO
        
           | cft wrote:
           | It looks like YADRO is making server hardware. IPMI is just
           | enumerating server hardware in the linked GitHub.
        
             | lamontcg wrote:
             | The author works for YADRO:
             | 
             | https://ru.linkedin.com/in/aamelkin
             | 
             | Microsoft has to shut off his account due to his
             | relationship with a company officially sanctioned by the US
             | government.
        
               | chatmasta wrote:
               | It's ironic you link to his (apparently not suspended)
               | profile on LinkedIn, which is also owned by Microsoft.
        
           | [deleted]
        
         | kvathupo wrote:
         | That's very interesting: I'm not sure how to feel about this.
         | On one hand, it aligns with my ethics to shut-down the
         | operations of sanctioned companies to minimize their harm. On
         | the other,
         | 
         | 1. Ethics are relative
         | 
         | 2. Should open-source contributions be dependent on such
         | ethics?
         | 
         | On (1), I'm sure non-Americans would have ethical qualms with
         | our Defense companies. Would I be okay with the hypothetical of
         | letting a non-American company stop open-source development on
         | a useful Lockheed Martin tool?
         | 
         | On (2), I have personally seen open-source contributions from
         | sanctioned companies, e.g. Megvii. Is it fair to ban those
         | employees (who may simply be unwilling to go through the hoops
         | of immigration)?
         | 
         | As an aside, perhaps this repo could move to GNU Savannah?
        
           | firebaze wrote:
           | > On one hand, it aligns with my ethics to shut-down the
           | operations of sanctioned companies to minimize their harm.
           | 
           | Only if the sanctions are warranted by ethics. Which they are
           | not, in this case - there isn't anything online I can find
           | which supports sanctioning this specific company.
           | 
           | This is a repeating pattern in this conflict: even without
           | substantial or even circumstantial proof that a russian
           | company benefits from or at least tolerates the war, in the
           | event Ukraine tells us to sanction the respective company, we
           | have to obey or else.
           | 
           | What do we expect? Should all russian companies shut down
           | because of the war? Would this be what we expect from all
           | western companies, like when we attacked Iraq because of
           | Weapons of Mass Destruction?
           | 
           | This is slowly really getting ridiculous. Even more so if
           | this opens up an attack vector from even more non-friendlies
           | because of an orphaned github account.
        
             | kofejnik wrote:
             | Every Russian company needs to be sanctioned. Especially a
             | tech one.
        
             | yencabulator wrote:
             | As seen elsewhere in these HN comments:
             | https://sanctions.nazk.gov.ua/en/sanction-company/6813/
             | 
             | > Putin has publicly stated his concerns about Russia's
             | access to microelectronics
             | 
             | > To further increase pressure on Russia's electronics
             | sector, the Department of State is designating numerous
             | advanced Russian electronics entities.
             | 
             | > Limited Liability Company Yadro Fab Dubna is implementing
             | a project to create Russia's largest modern production
             | plant for the production of circuit boards
        
             | [deleted]
        
         | rozab wrote:
         | Nice job, more info here
         | https://sanctions.nazk.gov.ua/en/sanction-company/6813/
        
       | newsclues wrote:
       | Is he Russian? Looks like he may be in Moscow, and there is a
       | war...
        
         | atomicUpdate wrote:
         | For anyone that didn't RTFA:
         | 
         | > There is no clear indication why GitHub blocked Amelkin but
         | may have to do with him being based out of Moscow, Russia as
         | his repositories do not appear otherwise controversial.
        
           | rasz wrote:
           | Server management tool with a potential of pushing backdoored
           | update being controlled by someone residing in Moscow is
           | plenty controversial.
        
             | redprince wrote:
             | Unless you know of the hurdles this hypothetical source
             | code change would need to clear to have any effect. Then
             | there is no controversy at all.
        
             | cryptonector wrote:
             | Reason: DMCA
             | 
             | Public: Oof.
             | 
             | vs
             | 
             | Reason: War
             | 
             | Public: Fork it!
             | 
             | vs
             | 
             | Reason: <unstated>
             | 
             | Public: now what?
        
             | lyind wrote:
             | "Supply chain my attack!" -- The Leader
        
             | ghostoftiber wrote:
             | > a potential
             | 
             | > residing in Moscow
             | 
             | Guilty until proven innocent isn't a good look, especially
             | when it comes down to where people live or their ethnic
             | background.
        
               | sam_lowry_ wrote:
               | Ethnic? Rather succeptiple to thermo-rectile
               | cryptoanslysis, as they call it jokingly in Russia.
        
               | CameronNemo wrote:
               | He is not being convicted of a crime, the software supply
               | chain is just being locked down.
        
               | jacob019 wrote:
               | US law does not apply to foreign nationals residing in a
               | foreign country. Russia is ruthlessly murdering their
               | neighbors and has indicated that they are at war with the
               | collective west. Russia has a long history of cyber
               | espionage against the US and is actively engaged in
               | Internet warfare. This is an entirely reasonable
               | precaution by Microsoft. It's a sad moment.
        
               | 1MachineElf wrote:
               | Maybe not. Microsoft stands to gain by crippling the most
               | popular FOSS BMC tool. They would rather everyone have to
               | use Windows-centric proprietary alternatives.
        
               | naikrovek wrote:
               | yes, clearly they've crippled it... they're still hosting
               | it and allowing people to fork and clone the repo.
               | 
               | US export and import restrictions must be followed by
               | companies who operate in the US. GitHub is one of those
               | companies, and the developer in question is associated
               | with a newly restricted company, so GitHub _must_ cease
               | allowing that company to operate on its infrastructure.
        
               | ms7m wrote:
               | > US law does not apply to foreign nationals residing in
               | a foreign country.
               | 
               | I don't think parent meant it in the context of US Law,
               | but more as a general statement, is it a reasonable
               | precaution by MS to ban X solely on the actions of their
               | government?
        
               | jacob019 wrote:
               | Although the presumption of innocence until proven guilty
               | is a fundamental principle of US law and an essential
               | part of our ideology, it is not a universal moral truth.
               | In my opinion, it is justifiable and suitable to prohibit
               | X from having access to sensitive infrastructure based
               | solely on the actions of their government, especially
               | when X is subject to the decisions of that government.
        
               | jstarfish wrote:
               | > is it a reasonable precaution by MS to ban X solely on
               | the actions of their government?
               | 
               | One could argue it's discriminatory; they banned him
               | because he's Russian.
               | 
               | ...which is the problem with this rhetoric.
               | 
               | Russia and China are known to entice or coerce otherwise-
               | innocuous civilians into acts of espionage. Their foreign
               | policies explicitly exploit our presumptions of
               | innocence, inclusivity and trust. Pre-emptive banning to
               | avoid another SolarWinds is more than reasonable
               | precaution; it's something that should have been done
               | years ago.
               | 
               | But in the meantime, by our own policies we're
               | _obligated_ to allow foxes into the henhouse. We 're
               | shamed for discriminating against foxes if we turn them
               | away, and shamed again for asking questions about how the
               | Great Chicken Massacre of 2023 was allowed to happen.
               | Chaos engineering at its finest.
        
               | jacob019 wrote:
               | Entertaining analogy! I agree with your point, but we are
               | not obligated by policy to allow foxes into the henhouse,
               | rather we are obligated by our social norms.
        
           | striking wrote:
           | https://ru.linkedin.com/in/aamelkin
           | 
           | > Alexander Amelkin - BIOS/BMC Team Lead - YADRO
           | 
           | YADRO is a recently sanctioned Russian company
        
         | denton-scratch wrote:
         | There are always wars. USA is not at war with Russia - at
         | least, not openly.
        
       | dboreham wrote:
       | For the curious, "archived" here means : repo is read-only but
       | still exists.
        
       | ashishb wrote:
       | Any recommended automated mirroring tools to keep a backup of
       | private GitHub repos to avoid the situation where your GitHub
       | account is suspended?
        
         | mzur wrote:
         | I use this shell script with a cron job:
         | https://gist.github.com/rodw/3073987 It can back up repos,
         | issues and wikis.
        
         | rsync wrote:
         | I keep interesting and valuable repos in my rsync.net account
         | and I use git to pull them directly:                 ssh
         | user@rsync.net git clone mirror ... blah blah ...
         | 
         | ... which is nice because I don't use my own bandwidth.
        
         | Fatnino wrote:
         | Isn't your working copy a backup?
        
           | bob1029 wrote:
           | A lot of people also use GH issues to track ideas/code
           | snippets/etc.
        
           | ashishb wrote:
           | I have deleted local copies from my machine in the past.
           | 
           | And when there are other contributors local copy is not
           | guaranteed to be up to date unless you yourself are actively
           | contributing as well.
        
         | upon_drumhead wrote:
         | I use https://github.com/qvl/ghbackup
        
         | coffeeri wrote:
         | If you are fine with self hosting a gitea instance, you'll be
         | able to set up a pull mirror.
         | 
         | https://docs.gitea.io/en-us/repo-mirror/#pulling-from-a-remo...
        
         | ofchnofc wrote:
         | [dead]
        
       | neilv wrote:
       | I suppose this is due to economic sanctions, but of course
       | there's also the infosec concern.
       | 
       | Much of "tech" right now is still cavalier about software
       | provenance in general. And IPMI is one of the more sensitive
       | points.
       | 
       | I have a pretty warm-fuzzy aspirations about open source at its
       | best: being collective effort, of people of goodwill, around the
       | world, working together, for the benefit of all.
       | 
       | It's tragic that our world has so much conflict, aggression,
       | inequity, and other ills. Open source is one place that we've
       | sometimes formed bridges despite this, but it's not entirely
       | immune to the larger world problems.
        
       | TheDesolate0 wrote:
       | [dead]
        
       | badrabbit wrote:
       | There is a ton of Repos owned by Russians. It would be chaos if
       | they suspended them for that alone. Maybe someone falsley
       | reported one of his repos?
        
       | 1MachineElf wrote:
       | I'd bet GitHub's hardware, if they use any at all for their
       | servers, has ipmitool installed.
       | 
       | When you're in GitHub's position, how does your SBOM
       | vulnerability management program handle it when you imperil your
       | own infrastructure?
        
       ___________________________________________________________________
       (page generated 2023-03-13 23:02 UTC)