guardianproject / guardianproject/haven

Move the bug tracker off MS Github

Open
#425 8 comments 1 reaction 0 assignees View on GitHub
Dominant language
Java
Stars
6.8k
Forks
752
PR merge metrics
No merged PRs in 30d

Description

Haven caters for privacy enthusiasts and those looking to use surveillance to escape surveillance, and yet the development platform is hosted by Microsoft -- a privacy abuser. To improve the credibility of the project and attract privacy-respecting developers, please consider moving away from Github.

It's particularly important to get the bug tracker off MS Github to encourage reports.

## Direct practical problems with using Microsoft Github

1. A survey [shows](https://infosec.exchange/@bojkotiMalbona/104637098084869887) that a significant number of bug reports are **withheld** when the bug tracker is inside a restrictive or politically controversial walled-garden like MS Github or gitlab.com.
1. Github is Tor-hostile [according to Tor project](https://trac.torproject.org/projects/tor/wiki/org/doc/ListOfServicesBlockingTor#ComputingTechnical). GH has started forcing Tor users through an extra email verification step that effectively discourages bug reports: ![github-tor_hostility](https://user-images.githubusercontent.com/21023035/61580062-10fd6300-aafd-11e9-8bf2-64faddf63760.png)
1. MS failed to secure Github, which was [breached to the tune of 500gb of private projects](https://www.bleepingcomputer.com/news/security/microsofts-github-account-allegedly-hacked-500gb-stolen). Security incompetence is further showcased by an MS-imposed requirement to create and account and sign in to report an MS security bug. And for those not discouraged by that, [the sign-in page](https://msrc.microsoft.com/create-report) is also broken. Then security was breached again in July 2020 when OAuth tokens were [stolen](https://www.zdnet.com/article/hackers-stole-github-and-gitlab-oauth-tokens-from-git-analytics-firm-waydev) from both Github and Gitlab.com.
1. MS suppresses democracy by [blocking](https://www.bbc.com/news/technology-50232902) Github access to a project that facilitates protests in Catalonia.

## Ethical problems with using Microsoft products and services

5. Microsoft harms the **environment** by serving the two most destructive oil companies in the world: [ExxonMobil](https://corporate.exxonmobil.com/news/newsroom/news-releases/2019/0222_exxonmobil-to-increase-permian-profitability-through-digital-partnership-with-microsoft) and [Chevron](https://news.microsoft.com/2019/09/17/schlumberger-chevron-and-microsoft-announce-collaboration-to-accelerate-digital-transformation).
1. (#ExxonKnew) Exxon notoriously [knew](https://www.scientificamerican.com/article/exxon-knew-about-climate-change-almost-40-years-ago) about climate change since 1977. They not only kept it secret from the public, but they also financed a disinformation campaign.
1. Microsoft and Chevron were [caught](http://web.archivecrfip2lpi.onion/web/publicintegrity.org/federal-politics/republican-lawmakers-posh-hideaway-bankrolled-by-secret-corporate-cash) each paying $100k to "the Cloakroom", a project to hide bribes going from large corporations to republican politicians.
1. Chevron's right-leaning stance is further pushed through its membership with ALEC, which doubles as a superPAC and bill mill that lobbies and writes policy for U.S. republicans.
1. Microsoft is a notorious **privacy** abuser:
1. MS is a PRISM corporation prone to mass surveillance.
1. MS supported CISPA and [collaborates](http://techrights.org/wiki/index.php/Microsoft_and_the_NSA) with the NSA.
1. MS [paid](http://cal-access.sos.ca.gov/Campaign/Committees/Detail.aspx?id=1401518&view=late1&session=2017) $195k to [fight](http://web.archivecrfip2lpi.onion/web/20200318144031/www.theverge.com/2018/6/15/17468292/amazon-microsoft-uber-california-consumer-privacy-act) the California Consumer Privacy Act (CCPA).
1. MS drug tests its employees, thus intruding on their privacy outside the workplace.
1. MS finances other privacy abusers:
1. In 2012 Microsoft spent $35 million on Facebook ads and in 2015 Microsoft was the third biggest spender on Facebook ads in the world.
1. MS proxies through Accenture to [make Sweden cashless](https://web.archive.org/web/20200722105800/https://tokenpost.com/Central-Bank-of-Sweden-is-testing-digital-currency-5197). The war on cash is war on privacy.
1. MS supplies Bing search service which gives high rankings to [privacy-abusing](https://github.com/privacytoolsIO/privacytools.io/issues/374#issuecomment-460077544) CloudFlare websites.
1. MS owns and operates Outlook Email and the LinkedIn social media site, both of which are exclusive walled-gardens that limit participation to those who have a phone number and the will to share it with Microsoft.
1. MS supplies hotmail.com email service, which uses vigilante extremist org *Spamhaus* to force residential internet users to share all their e-mail metadata and payloads with a corporate third-party.
1. MS [unlawfully](https://www.cnet.com/news/amazon-google-and-microsoft-sued-over-photos-in-facial-recognition-database) used people's images without consent to train their facial recognition products
1. MS distributes a [nonfree operating system](http://gnu.org/philosophy/free-software-even-more-important.html), Microsoft Windows, which is jam-packed with [malicious functionalities](http://gnu.org/proprietary/malware-microsoft.html), including surveillance of users, DRM, censorship and a universal back door.
1. MS was [caught](https://www.vice.com/en_us/article/43kv4q/microsoft-human-contractors-listened-to-xbox-owners-homes-kinect-cortana) surreptitiously recording Xbox users and paying contractors to listen to the recordings.
1. Dutch government commissioned [a study](https://www.rijksoverheid.nl/documenten/rapporten/2018/11/07/data-protection-impact-assessment-op-microsoft-office) which found Microsoft to have [several GDPR violations](https://www.zdnet.com/article/dutch-government-report-says-microsoft-office-telemetry-collection-breaks-gdpr). E.g. Office 365 violates [GDPR article 5](https://gdpr-info.eu/art-5-gdpr/) ¶ `1.c`, [GDPR article 17](https://gdpr-info.eu/art-17-gdpr/), and stores the data outside the EEA (may also be a GDPR breach).
1. Microsoft is detrimental to **human rights** and **democracy**
1. Microsoft [finances AnyVision](https://www.forbes.com/sites/thomasbrewster/2019/08/01/microsoft-slammed-for-investing-in-israeli-facial-recognition-spying-on-palestinians) to produce facial recognition technology that the Israeli military uses as a weapon against the Palestinian people who they oppress in their occupation. Note that Israeli snipers [murdered](https://edition.cnn.com/2018/06/03/middleeast/razan-al-najjar-gaza-nurse-killed/index.html) an unarmed civilian Palestinian medic (in breach of the Geneva Convention) then [edited](https://www.independent.co.uk/news/world/middle-east/gaza-protests-latest-idf-condemned-edited-video-angel-of-mercy-medic-razan-al-najjar-a8389611.html) the video to deceive the public for PR damage control.
1. Microsoft [supports ICE](https://companies-that-work-with-ice.com) in a variety of ways in the course of ICE's implementation of Trump's xenophobic border policies. Microsoft services an ICE contract worth [$19.4 million dollars](https://thehill.com/policy/technology/393358-microsoft-employees-dissatisfied-by-ceo-response-plan-action-against-ice) despite protest from employees. In addition to MS Office products, Microsoft has renewed a [Github contract](https://www.theverge.com/2019/10/9/20906213/github-ice-microsoft-software-email-contract-immigration-nonprofit-donation) and also supplies cloud computing through its [Azure platform](https://gizmodo.com/microsoft-employees-up-in-arms-over-cloud-contract-with-1826927803).
1. MS [partnered with FedEx](http://fortune.com/2020/05/18/microsoft-fedex-partnership-build), an NRA-supporting ALEC member as well as [JP Morgan Chase](https://www.zdnet.com/article/honeywell-set-to-launch-its-quantum-computer-with-quantum-volume-of-64), the most evil bank in the world.
1. MS [conceals](https://techinquiry.org/SiliconValley-Military) US military contracts to bias PR and dodge social accountablity. They have a much bigger piece these contracts than the rest of MACFANG, they lack Googles [AI principles](https://ai.google/principles), and unlike Google they ignore employee protest and petitions.
1. MS is among the top 15 recipients of Trump's corporate tax breaks, a benefit of $128 billion. Microsoft [sacked hundreds of employees](https://web.archive.org/web/20200529160343/https://www.cheatsheet.com/web/20200529160343mp_/https://www.cheatsheet.com/money-career/these-companies-started-firing-employees-right-after-getting-tax-cuts-from-trump.html) immediately after receiving the tax breaks in February 2018.
1. MS is **anti-consumer** and anti-competitive
1. MS [tricked](http://www.theguardian.com/technology/2016/feb/02/microsoft-downloading-windows-10-automatic-update) users into "upgrading" to Windows 10, which [sabotages](https://www.cnet.com/news/microsoft-windows-10-forced-updates-auto-restarts-are-the-worst) users in a variety of ways, one of which is to [prevent cloud-free accounts](https://www.howtogeek.com/442609/confirmed-windows-10-setup-now-prevents-local-account-creation).
1. MS [strong-armed](http://www.linfo.org/microsoft_tax.html) nearly all PC manufacturers charge every buyer for an MS Windows license regardless of whether the user actually wants Windows.
1. MS [hoards](http://techrights.org/2017/03/15/still-using-patents-to-coerce) software patents and uses them to [fight free software](http://techrights.org/2017/02/27/microsoft-novell-v2-via-azure).

## Bad alternative: gitlab.com *service*
The Gitlab.com SaaS is often considered an alternative to MS Github, but it's even worse--

for many reasons
* Sexist treatment toward saleswomen who are [told to wear](https://web.archive.org/web/20200309145121/https://www.theregister.co.uk/2020/02/06/gitlab_sales_women/) dresses, heels, etc.
* Hosted by Google.
* [Proxied](https://about.gitlab.com/blog/2020/01/16/gitlab-changes-to-cloudflare/) through privacy abuser CloudFlare.
* [tracking](https://social.privacytools.io/@darylsun/103015834654172174)
* Hostile treatment of Tor users trying to register.
* Hostile treatment of new users who attempt to register with a `@spamgourmet.com` forwarding email address to track spam and to protect their more sensitive internal email address.
* Hostile treatment of Tor users *after* they've established an account and have proven to be a non-spammer.

Regarding the last bullet, I was simply trying to edit an existing message that I already posted and was forced to solve a CAPTCHA (attached). There are several problems with this:
* CAPTCHAs break robots and robots are not necessarily malicious. E.g. I could have had a robot correcting a widespread misspelling error in all my posts.
* CAPTCHAs put humans to work for machines when it is machines that should work for humans.
* CAPTCHAs are defeated. Spammers find it economical to use third-world sweat shop labor for CAPTCHAs while legitimate users have this burden of broken CAPTCHAs.
* The reCAPTCHA puzzle requires a connection to Google
1. Google's reCAPTCHAs compromise security as a consequence of surveillance capitalism that entails collection of IP address, browser print.
* anonymity is [compromised](https://cryptome.org/2016/07/cloudflare-de-anons-tor.htm).
* (speculative) could Google push malicious j/s that intercepts user registration information?
1. Users are forced to execute [non-free javascript](https://libreplanet.org/wiki/Group:Free_Javascript_Action_Team#Ideas_for_focus) ([recaptcha/api.js](https://www.google.com/recaptcha/api.js)).
1. The reCAPTCHA requires a GUI, thus denying service to users of text-based clients.
1. CAPTCHAs put humans to work for machines when it is machines who should be working for humans. *PRISM* corp Google Inc. benefits financially from the puzzle solving work, giving Google an opportunity to collect data, abuse it, and profit from it. E.g. Google can track which of their logged-in users are visiting the page presenting the CAPTCHA.
1. The reCAPTCHAs are often broken. This amounts to a denial of service. ![gitlab_google_recaptcha](https://user-images.githubusercontent.com/18015852/51769530-9d494300-20e3-11e9-9830-1610b3ae9059.png)
* E.g.1: the CAPTCHA server itself refuses to give the puzzle saying there is too much activity.
* E.g.2:
![ccha](https://user-images.githubusercontent.com/18015852/55681364-07713600-5926-11e9-8874-137e4faaf423.png)
1. The CAPTCHAs are often unsolvable.
* E.g.1: the CAPTCHA puzzle is broken by ambiguity (is one pixel in a grid cell of a pole holding a street sign considered a street sign?)
* E.g.2: the puzzle is expressed in a language the viewer doesn't understand.
1. (note: for a brief moment gitlab.com switched to hCAPTCHA by *Intuition Machines, Inc.* but now they're back to Google's reCAPTCHA)
1. Network neutrality abuse: there is an access inequality whereby users logged into Google accounts are given more favorable [treatment](https://www.fastcompany.com/90369697/googles-new-recaptcha-has-a-dark-sideby) the CAPTCHA (but then they take on more privacy abuse). Tor users are given extra harsh treatment.

There's nothing wrong with self-hosting an instance running Gitlab CE or using the Gitlab instance of another party.

## Decent alternatives

1. self-hosting (Gogs, Gitea, Gitlab CE, etc.)
1. (+) avoids the "shake-up" problem of shrinking the community each time the project moves (there is no risk that the privacy factors would later take a negative turn).
1. Bitbucket
1. (-) dodgy j/s up the yin yang that [clusterfucks uMatrix](https://github.com/privacytoolsIO/privacytools.io/issues/843#issuecomment-483830547)
1. (-) has some relationship with Netlify, who uses AWS
1. (-) non-free software?
1. Launchpad
1. notabug.org ("NAB") ([privacy policy](https://notabug.org/tos#Privacy)). Based on a liberated fork of gogs.
1. (+) [supports Tor](https://notabug.org/tor) (although the *onion* web UI is currently disabled in response to attack, so the onion site only accepts git connections)
1. (+) supports SSH keys and SSH over Tor
1. (+) no CAPTCHAs
1. (+) registration very non-intrusive, and not controlling about where you get your email
1. (-) noteworthy drawback unrelated to privacy: e-voting non-existent.
1. (-) noteworthy drawback unrelated to privacy: NAB doesn't associate PGP keys to users, so PGP signed commits may be unavailable or more manual work needed.
1. (-) IRC support channel is dead.
1. [Codeberg](https://codeberg.org/). Runs on [Gitea](https://docs.gitea.io/en-us/), which is a Gogs fork.
1. (+) web UI works on Tor (probably SSH as well)
1. (+) supports SSH and GPG keys
1. (+) registration very non-intrusive, and not controlling about where you get your email
1. (+) functions without any j/s, and the javascript that exists is all 1st-party
1. (+) supports e-voting
1. (-) logins don't work from all Ungoogled Chromium installations
1. (-) no onion address
1. yerbamate.dev
1. git.openprivacy.ca
1. git.nixnet.xyz
1. git.sr.ht
1. framagit.org: Gitlab CE instance
1. git.jami.net: Gitlab CE instance, perhaps dedicated to jami
1. sourcehut.org
1. http://dweb.happybeing.com/blog/post/002-safegit-decentralised-git-on-safe-network/

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the repository's current GitHub issue and bug-reporting workflow, then compare the alternatives discussed in the issue, including GitLab.com. The issue does not name a destination, migration plan, files, or tests, so completion criteria would need to be agreed before implementation can begin.

Written by the indexing model from the issue text.

Assessment

Tech stack
github, gitlab
Domain
devops
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.