7 ms·
GitHub publishes DMCA deletion notifications sent by Bilibili
- ghomrassen 7y agoHeard about this a couple days ago, crazy stuff. For those who don't know, bilibili is a massive video hosting platform in China aimed toward the younger generation. So the question is who leaked it and why? Just a disgruntled employee or the effect of 996?
- toomuchtodo 7y agohubot (a Github bot) automatically publishes DMCA takedown requests into the repo [1] in question. [1] https://github.com/github/dmca/ https://github.com/github/dmca/
- akerl_ 7y agoI suspect the commenter you’re responding to means ~”who leaked the source code referenced in the DMCA, and why”. The DMCA takedown request refers to a repo that it claims contains internal information and data from the claiming company.
- josteink 7y agoAccording to this repo Symantec just filed a DMCA notice to Android source code about a week ago: https://github.com/github/dmca/blob/master/2019/04/2019-04-09-Symantec.md https://github.com/github/dmca/blob/master/2019/04/2019-04-0... Crazy.
- deleted 7y ago[deleted]
- manojlds 7y agoWhat android source code? It's a repos called android_test of some user. This seems to have been the main factor - com/symantec/mobilesecurity - in the code.
- darklajid 7y agoWhy crazy? They do list every .. folder (and call them 'repositories'), which is probably stupid. But https://github.com/shil99/android_test/tree/master/external/NMS_Test/src/com/symantec/mobilesecurity https://github.com/shil99/android_test/tree/master/external/... literally has their name in the path/package name, so it isn't crazy (unless you know more?) to believe that this was stolen/reverse engineered Symantec code, no? At LEAST it's a very confusing and misleading directory tree for a random repository? Files below src/ should be sources, not a 3rd party Symantec lib or whatever, so I'd give them the benefit of the doubt here.
- NegativeLatency 7y agoWhat is 996?
- sjcsjc 7y agoI first heard of it last week from this article: https://www.bbc.co.uk/news/business-47934513 https://www.bbc.co.uk/news/business-47934513
- hollerith 7y agoThe practice of requiring employees to work from 9 to 9 6 days a week.
- imhoguy 7y agohttps://en.wikipedia.org/wiki/996_working_hour_system https://en.wikipedia.org/wiki/996_working_hour_system
- deleted 7y ago[deleted]
- rococode 7y agoElaborating a bit more on the size of bilibili: it has around 100m monthly users and trades as NASDAQ:BILI with a market cap of ~$5.7B. This is not some small-time shop, as far as social media companies go bilibili is one of the more established companies out there.
- pluma 7y agoI'll never understand what market cap has to do with company size. Stock prices are basically an arbitrary value mostly determined by how much people buying stock think the stock is worth, are they not? Correct me if I'm wrong but theoretically an overhyped two man operation running at a financial loss could generate the same market cap as a much larger company with massive profits? As I understand it, the only somewhat tangible factor is the actual money in the company which again can be bloated by overeager investors. I'm not being facetious, I'm genuinely curious about the rationale.
- kitd 7y agoAmong other things, market cap gives an indication of the future value investors place in the company. Your 2-man shop would unlikely have a similar market cap unless they can demonstrate some blindingly simple strategy to take over the world. Your big corp already has access to a large userbase (100m users in Bilibili's case if the previous poster is to be believed). That makes future growth and profits much more likely.
- Radle 7y agoWell if your company only has one product with all the secrets leaked on github, it matters whether the company was worth 10 Million or 6 Billion before bad things happen.
- calgaryeng 7y ago"Enterprise Value" is one of the legitimate measures of company size, and is defined as market capitalization + net debt. You can think of this as equivalent to the size of the company because it would be the amount of money you'd need (roughly speaking) to buy the entire company outright.
- pferde 7y agoProbably a little of each. The repository "title" of swituo/openbilibili-go-common, when pushed through google translate, says: "I don't know if these are embarrassing... The troubles of morality are going out and turning right to pay attention to 996.icu"
- yorwba 7y ago"我不清楚这些是啥… 道德心泛滥的麻烦出门右转关注996.icu!" means "I don't know what these are... I hope those with an overflowingly moral heart won't be too bothered to go out and turn right to star 996.icu" The original repo was taken down, so I don't think you can attribute that message to the leaker.
- rqs 7y agoShould be translated to: "I have no idea what are these (or what is this) ... If you have too many moralities to spend, go spend them on 996icu!"
- zhte415 7y agoBilibili was also criticised by the Chinese government last week for the 'quality' of some hosted content (read: pornography, satire). The next day its foothold in younger generations was praised by the same relevant organs (read: being told to focus or educational and 'moral' content).
- akerro 7y agoBackups https://github.com/search?q=go-common https://github.com/search?q=go-common
- akerro 7y agoSeems like a misuse of DMCA to me. Chinese company misusing powerful acts in USA.
- iforgotpassword 7y agoExcuse me? Someone stole bilibili's code base and/or private keys and published it to github. How is it abuse to try and get that taken down?
- wolco 7y agoNot sure either. Ownership of the code could belong to the leaker.
- Operyl 7y agoWhat? That doesn't seem likely, given that in almost all scenarios you're assigning copyright to your employer..
- deleted 7y ago[deleted]
- DannyBee 7y agoMy guess is they somehow believe that because the DMCA is a US law, only US companies can invoke it legally.
- Kaiyou 7y agoSince when do the Chinese honor copyright? Did I miss something?
- Operyl 7y agoThis is exactly the perfect scenario for the usage of DMCA... Not abuse, but exercising rights to code they literally own.
- avip 7y agoToo late. GitHub is scraped very frequently (as in seconds) for sensitive stuff. It’s out and github cannot do anything about it
- counter2015 7y agoAs far as I know, an employee who was illegally laid off by bilibili put part of the company's background code on GitHub to vent his anger. And then GitHub has directionally shielded the keywords "bilibili" and "go-common", But it can be bypassed by typing only one character less. there are still a lot of projects alive. It is not yet known who leaked it. Also for the reason.
- 4684499 7y ago> illegally laid off Source please?
- counter2015 7y agoYou can find some reports here by using Translation software(If this report hasn't been deleted yet)。 BiliBili once made a statement on Weibo, but delete in a few minutes. https://www.heibai.org/post/1214.html https://www.heibai.org/post/1214.html
- counter2015 7y ago> illegally laid off for this part, I can't give credible sources, I know it from hearsay
- yorwba 7y agoYou could link to the hearsay, assuming it was online. FWIW, the report you link in your other comment has a screenshot of a conversation where someone claims that the code was leaked by an intern from Nankai University who didn't know how to use git. [1] That they're identified by their university makes me suspect that it's a rumor (edit: making fun of the university), though. [1] https://www.heibai.org/zb_users/upload/2019/04/20190423062149_35805.png https://www.heibai.org/zb_users/upload/2019/04/2019042306214...
- 42yeah 7y agoThis letter seems like it was hastily written and sent out in quite a hurry.
- DarkWiiPlayer 7y agoNow this is embarrasing https://github.com/swituo/openbilibili-go-common/blob/8866d1359a2a501009b976b02bb27e4949cc4e77/app/admin/main/apm/dao/canal_test.go#L51 https://github.com/swituo/openbilibili-go-common/blob/8866d1...
- praptak 7y agoCode base is fair game DMCA-wise. I wonder about the private keys though. I don't think they are copyrightable (although it would cool to have a poem as the private key). So, does DMCA cover that too?
- neiman 7y agoGood question. My guess is that the only thing needed to be copyrightable is the one thing which is not.
- sandworm101 7y agoThey are copyrightable as works, and even if they arent then they are as devices protecting works. The level of creativity needed for copyright is minimal. A key pair is generated by machine, but at the request of a human according to parameters selected by the human. That is likely enough.
- steve19 7y agoA key is just a long number. The AACS encryption key controversy was the subject of DCMA take downs because the key could be used to strip DRM, not because it was a number.
- saint_abroad 7y agoSince recipes are not protected under copyright law [1] it's unlikely mathematical parameter lists have sufficient "literary expression" for protection. OTOH, a passphrase of substantial creativity [2] may be protected by copyright. Crucially (for any takedown), this would cover transformations by key derivation functions. IANAL. [1] https://www.copyright.gov/help/faq/faq-protect.html https://www.copyright.gov/help/faq/faq-protect.html [2] https://fairuse.stanford.edu/2003/09/09/copyright_protection_for_short/ https://fairuse.stanford.edu/2003/09/09/copyright_protection...
- sandworm101 7y agoA purely random number is almost certainly always beyond copyright, but as soon as someone puts limitations on that randomness a court may find that enough. And what matters for a takedown is not the number, but the actually document being published. Github is not hosting the random number. It is hosting that number in the context of a larger document and it is that document that is subject to the takedown request. Things might be different if github hosted only the number without the associated labels and code.
- founderling 7y agoWhy do you think that the DMCA would lead to some sort of deletion of repositories that was sent over a wire to a website that the DMCA was meant to be into? It's not a simple case either. But it feels a bit strange that there aren't any links to this kind of DMCA takedown. It seems strange that a company like BitBucket would even have this kind of information without the DMCA notice. Or maybe I'm just a cynic.
- ddtaylor 7y agoIt appears to already be on IPFS https://ipfs.io/ipfs/QmYiQ5jbtmx24ketNA65MJ3VpSDFWikGmvnBErqpmiXtRC https://ipfs.io/ipfs/QmYiQ5jbtmx24ketNA65MJ3VpSDFWikGmvnBErq...
- comex 7y agoHERO.md: https://gitlab.com/wkingfly/openbilibili/blob/master/HERO.md https://gitlab.com/wkingfly/openbilibili/blob/master/HERO.md I have no idea what it means, but I like it.
- silvester23 7y agoThese are playable races and character classes from Warcraft III (and the expansion The Frozen Throne). Most of these probably also appear in World of Warcraft, though I cannot say for sure. As to why this file is in the top directory of the repo, your guess is as good as mine.
- brenniemac 7y agoI think more specifically this is referring to heroes from Dota (which of course links back to Warcraft III as you said)
- Zekio 7y agonah, they are just the default heroes that exist in Warcraft 3 Reign of Chaos and Frozen Throne, which is easily discerned by the names and the fact the races are listed as titles and the Neutral heroes doesn't have a race mentioned in English Also there are a lot more heroes in the Dota map for Warcraft 3 than on that short list
- deleted 7y ago[deleted]
- dustinmoris 7y agoNot great... MD5 password hashing: https://github.com/swituo/openbilibili-go-common/blob/8866d1359a2a501009b976b02bb27e4949cc4e77/app/service/main/passport-game/service/passport_login.go#L185 https://github.com/swituo/openbilibili-go-common/blob/8866d1... Hardcoded credentials: https://github.com/swituo/openbilibili-go-common/blob/8866d1359a2a501009b976b02bb27e4949cc4e77/app/admin/ep/marthe/dao/tapd.go#L17 https://github.com/swituo/openbilibili-go-common/blob/8866d1... More hard coded secrets: https://github.com/swituo/openbilibili-go-common/blob/8866d1359a2a501009b976b02bb27e4949cc4e77/app/service/ep/footman/cmd/tapd/tapd.go#L54 https://github.com/swituo/openbilibili-go-common/blob/8866d1... This configuration is my favourite: https://github.com/swituo/openbilibili-go-common/blob/8866d1359a2a501009b976b02bb27e4949cc4e77/library/queue/databus/report/conf.go https://github.com/swituo/openbilibili-go-common/blob/8866d1... And of course, RSA keys which they use for all of their RSA encryption: https://github.com/swituo/openbilibili-go-common/blob/8866d1359a2a501009b976b02bb27e4949cc4e77/app/service/main/passport-game/service/passport_key.go https://github.com/swituo/openbilibili-go-common/blob/8866d1... ... their problem is not that the source code is all public over the internet now... their problem is the engineering team. If source code leaks the worst outcome should be some IP leakage, but not a compromised live system. That can and should be easily avoided by not having everything in your source code, especially when you are such a big company with so many employees...
- alias_neo 7y agoI've always wondered, how it could be that someone can be smart enough to write what on the surface is some fairly clean Golang, and yet at the same time, dumb enough to put secrets in the code. I can forgive the use of MD5, because they probably just don't know their hashing/crypto but secrets? It's literally in the name. There is so much material in your 5 links alone, that anyone who desires could utterly own their infrastructure, and then some.
- nemothekid 7y agoIt’s one of those things that you dangerously start when your project is small then when you balloon in size, you find that everyone is hard coding secrets in code and standing up some secrets infrastructure would take weeks to get right. It’s easier now with tools like Vault but let’s say you joined bilibili today - where do you even begin? You have a massive cultural problem before you even begin to tackle the technical one. Even a smart engineer may just resign to doing things the wrong way than trying to fight a huge political battle.
- dikei 7y agoApart from the storing secret in repository, I'm quite impressed by their repository structure. It looks a lot better than the mess I often see in our internal projects.
- dis-sys 7y agoSure, Bilibili's copyright must be respected, no question on that whatsoever. That being said, let's have a look on how this multi-billion company treats its programmers - flv.js is opened sourced by bilibili, it has 14,668 starts on github [1]. Bilibili paid the smart & hardworking programmer who single handedly started this project and made it popular $700 USD per month [2], there is a very long zhihu.com thread [2] on this matter with 4 million views and almost 400 detailed responses. $700 is about 10% of the fair market rate in China for skills like that. Sorry, but I am not going to take the moral high ground and defend bilibili's rights any time soon. It is a company violating the rights of its programmers on hourly basis. Shame on you BiliBili. [1] https://github.com/Bilibili/flv.js https://github.com/Bilibili/flv.js [2] https://www.zhihu.com/question/53686737 https://www.zhihu.com/question/53686737
- chippy 7y agoI think you are taking a moral high ground by attacking the company's practices. I think defending corporate legal rights is mostly not about morality which is why speaking about morals in this story is important. Like in how the legal system it's not what's right or wrong or truth that's important but legal justice, so we need morality to play a part in making sure it doesn't get out of hand.
- ksec 7y ago> $700 is about 10% of the fair market rate in China for skills like that. So you are suggesting $7000 for skills like that? There are still countless PHP / Golang / Rails jobs going for under $2K. While I agree $700 is insanely low even if you are in some Tier 3 cities, I don't think 10% paint an accurate picture of the current state of Programming Paid in China.
- dis-sys 7y agoAs clearly mentioned in the reply, $7,000/month is the fair market rate for someone who can propose/promote/complete such a project with visible impact on the community.
- ddtaylor 7y ago
- owaislone 7y agoIf you don't have time to integrate with a secret store, at least use something like Blackbox to store encrypted in git: https://github.com/StackExchange/blackbox https://github.com/StackExchange/blackbox
- gerbilly 7y agoI use something like this to set a few global variables at build time. This keeps my secrets out of the source code. go build \ -ldflags="\ -X main.programVersion=`git describe` \ -X main.username=$USERNAME \ -X main.password=$PASSWORD" This isn't perfect, of course, because you can just use strings(1) to find the secrets embedded in the binary, but it is a step up from what they did. It's fine for our internal go apps. I'm not sure what I would do if the secrets were for connecting to public cloud infrastructure though. Perhaps encrypt them with a separate key per customer, then feed in the key via an env variable? Any ideas?
- duncan-donuts 7y agoI would read connection string information from the env. This[0] might be useful if you’re not familiar with 12 factor apps. 0: https://12factor.net/config https://12factor.net/config
- CameronNemo 7y agoAn example configuration file is also acceptable. It is also less prone to leakage if your application runs other untrusted (or simply less trusted) code and does not sanitize the environment first.