GitCode, a git-hosting website operated Chongqing Open-Source Co-Creation Technology Co Ltd and with technical support from CSDN and Huawei Cloud.
It is being reported that many users’ repository are being cloned and re-hosted on GitCode without explicit authorization.
There is also a thread on Ycombinator (archived link)
China cares of nothing, from patents to licences. Culture of steal and copy, rebrand and sell/use
I would argue that this culture would possibly be good to learn from them, first. It didn’t come to existence as some kind of social evolution, but was impressed by power.
Second, at least they are behind Europeans in the culture of genocide.
Solution: create a GitHub repo with Markdown articles outlining human rights abuses by the CCP and have a large number of GitHub users star and fork the repo.
You’ve heard of CamelCase and lowercase and intVariableName variable naming styles. Get ready for:
for (int Taiwan == 0; Taiwan < HongKong; Taiwan++) { int TianamenSquare == 0; … }
That’s the whole point of this: they will automatically filter that out, and this is an impotent, though well intended, gesture.
How will they filter it out? If they just don’t mirror anything with ‘forbidden’ terms, we can poison repos to prevent them being mirrored. If they try to tamper with the repo histories then they’ll end up breaking a load of stuff that relies on consistent git hashes.
I feel like the effort to make such a repo and make it popular enough to be cloned and rehosted is a lot more effort than someone manually checking the results of an automated filter process.
The “effort economy” is hugely in favor of the mirroring side
Yeah I figured as much. It was mostly a joke. At the end of the day, if stuff is on GH, people can take it. It’s barely even stealing. Unless the license disagrees of course but then you were putting a lot of trust in society by making it public in the first place.
That’s what I don’t get about this. Why does anyone care? Even this Chinese company, why do they care to clone it all? It’s already all hosted and publicly available.
Apparently they aren’t respecting licenses. It’s possible to have source code publicly available on GH but have it not be truly FOSS. But that’s generally not a great idea since you’re effectively relying on the honour system for people not to take your code.
Even this Chinese company, why do they care to clone it all? It’s already all hosted and publicly available.
Until it isn’t. Perhaps they are preparing for a future war with the US and assume their access to all that code will be blocked. They want to copy it now while they have access.
Good point.
The real solution is to include a few
tiananmenSquare
variables in all the repositories. Either they exclude the entire repository or just the specific file, in either case the entire project may be unusable.It’s a new coding paradigm, I will take some time getting used to looking for libraries in the
uyghur/tianamen
folder.So… You’re saying instead of “main”, “app”, or “core”, we should change the convention to make tiananmenSquare the entry point for apps?
Or maybe make it the filename for utils, so it’ll just break
For example.
But honestly I was more joking. The thing that makes most projects useful is the developers developing it, and they can’t clone that
China filters every byte of Internet traffic in and out of the country.
It seems naive to think they can’t accomplish the same thing for a GitHub mirror.
They’re not supposed to, it’s just about blocking them from using the software :)
Maybe we should consider the same for the US government instead of being afraid of the big Chinese boogeyman across the sea? Because I guarantee you the US has just as many, if not more. But China bad. 🙄
I was making a joke about abusing Chinese censorship in order to stop them cloning GitHub repos (assuming that was something you wanted to do). The joke being that the CCP suppresses information about their human rights abuses. That is not true of the US. You could absolutely make a GitHub repo detailing the crimes of the US government. Nobody will stop you.
Tell that to Julian Assange
Is that what you think got him in trouble?
yes. he published us crimes in iraq/afghanistan.
50 Cent Army Repellant:
六四
1989 Tiananmen Square Massacre
I always thought the term “Wumao” sounded suspiciosly like “woo Mao.”
Yes yes, what about the US?
426
Removed by mod
Tankie whataboutism strikes again.
Two things can be bad at the same time. Wild, I know.
Edit: also, the point of my joke wasn’t the human rights abuses. It is that these things are censored in China. So your comment is even more irrelevant. One could very easily create a repo outlining American crimes and put it on GitHub. But doing so in China with CCP crimes will have you sent to a Gulag
Removed by mod
I’m not American. I don’t even like America.
Hell even i’m American and don’t like America
Removed by mod
Lmao it’s literally the name of a logical fallacy. How is the term itself fallacious?
Also I harbour no racism or ill will toward the Chinese people. My girlfriend is Chinese and I care about her a lot and love learning about her culture. I just don’t abide the human rights atrocities (or censorship thereof) committed by any government.
Removed by mod
everyone should have stuff in their code comments, tianamen, hong kong, taiwan, uyghurs
deleted by creator
genius.
create a GitHub repo with Markdown articles outlining human rights abuses by the CCP
Once you have logged “China killed 100 Zillion people! End CCP now!” in Chinese GitHub, everyone in China will realize that their lives are actually very bad and they need to do a Revolution immediately.
And here I was thinking that might prevent them mirroring the repo but whatever
Yeah… The main thing I see here is that China (read; government , not the people, not being racist here) will take this code, they will make improvements on it, they will NOT give back. Basically like Microsoft, but now an entire country.
Chinese government hasn’t exact had a good reputation when it comes to taking technology and not giving anything back
Not like I’d want contributions from the chinese state programmers.
Feels like an easy entry for state level supply chain attack.Who says they aren’t trying right now? I recall SSH had an attempt quite recently, I can guarantee that China is trying hard to include anything to out in back doors
If we steal IP from China does the American government give us a business loan?
China has no IP
I love how this image is a pun
I’m not getting it. Explain, please?
IP Man. Great movies.
Ahh, thanks. I think that may be a grandad level pun
Bs
I don’t understand why this is a bad thing? Open source code is designed to be shared/distributed, and an open-source license can’t place any limits on who can use or share the code. Git was designed as a distributed, decentralized model partly for this reason (even though people ended up centralizing it on Github anyways)
They might end up using the code in a way that violates its license, but simply cloning it isn’t a problem.
The code needs to maintain the copyrights and authors. They are “mirroring” usernames into their own domain, with mails that dont correspond to the original authors, stealing their contributions.
with mails that dont correspond to the original authors,
Oh! I didn’t realise this. Do you have an example?
That would make it plagiarism, which ethically is a whole different matter than merelly copying that which is free to copy.
I expect it’s going likely to be used to train some Chinese AI model. The race to AGI is in progress. IMO: “ideas” (code included) should be freely usable by anyone, including the people I might disagree with. But I understand the fear it induces to think that an authoritarian government will get access to AGI before a democratic one. That said I’m not entirely convinced the US is a democratic government…
PS: I’m french, and my gov is soon to be controlled by fascist pigs if it’s not already, so I’m not judging…
I expect it’s going likely to be used to train some Chinese AI model.
Even if they do that, the license for open source software doesn’t disallow it from being done.
It certainly can. Most licences require derivative works to be under the same or similar licence, and an AI based on FOSS would likely not respect those terms. It’s the same issue as AI training on music, images, and text, it’s a likely violation of copyright and thus a violation of open source licensing terms.
Training on it is probably fine, but generating code from the model is likely a whole host of licence violations.
Most licences require derivative works to be under the same or similar licence
Some, but probably not most. This is mostly an issue with “viral” licenses like GPL, which restrict the license of derivative works. Permissive licenses like the MIT license are very common and don’t restrict this.
MIT does say that “all copies or substantial portions of the Software” need to come with the license attached, but code generated by an AI is arguably not a “substantial portion” of the software.
code generated by an AI is arguably not a “substantial portion” of the software
How do you verify that though?
And does the model need to include all of the licenses? Surely the “all copies or substantial portions” would apply to LLMs, since they literally include the source in the model as a derivative work. That’s fine if it’s for personal use (fair use laws apply), but if you’re going to distribute it (e.g. as a centralized LLM), then you need to be very careful about how licenses are used, applied, and distributed.
So I absolutely do believe that building a broadly used model is a violation of copyright, and that’s true whether it’s under an open source license or not.
I agree with you, and don’t really have any answers :)
By comparing it to the original work.
And how will you know what original work(s) to compare it to?
I’m seeing this misconception in a lot of places.
Just because something is on GitHub, doesn’t mean it’s open source. It doesn’t automatically grant permission to share either.
deleted by creator
Correct, you are allowed to click the “fork” button and nothing else. You’re still not allowed to download, use, modify, compile or redistribute the code in any way that doesn’t involve the “fork” button.
It may not be de jure open source, but if the code is posted publicly on the internet in a way that anyone can download and modify it, it sort of becomes de facto open source (or “source available” if you prefer).
Please don’t muddy the water with terms like this. Something is open source if and only if it has an open source license.
But china bad and scary.
I personally don’t care if someone “steals” my code (Here’s my profile if you want to do so: https://github.com/ZILtoid1991 ), however it can mean some mixture of two things:
- China is getting ready for war, which will mean the US will try its best to block technology, including open source projects.
- China is planning to block GitHub due to it being able to host information the Chinese government might not like.
Of course it could mean totally unrelated stuff too (e.g. just your typical anti-China and/or anti-communist paranoia sells political points).
Isn’t GitHub already blocked in China?
It is
US will try its best to block technology, including open source projects.
You can’t block open source projects from anyone. That’s the entire point of open source. For a license to be considered open-source, it must not have any limitations as to who can use it.
You can’t block open source projects from anyone.
I think they were referring to blocking GitHub from public access. In the event of a world war I could easily see Microsoft obeying the order to shut down GitHub.
It is not illegal is it?
If it is legal, then thank you China for the free backup.
I do believe it’s illegal if they take a repository with a restrictive license (which includes any repository without a license), and then make it available on their own service. I think China just doesn’t care.
If it’s hosted in a public repo, anyone can clone it, that’s very much part of most git flows.
What you can do with the software, how you can use it, that’s another matter, based on the licence.
That of course assumes China will respect the copyright…
Sure, you can probably clone it - I’m not 100% sure, but I think laws protect that as long as it’s private use.
You can also fork it on GitHub, that’s something you agree to in the GitHub ToS - though I think you’re not allowed to push any modifications if the license doesn’t allow it?
Straight up taking the content from GitHub, uploading it to your own servers, and letting people grab a copy from there? That’s redistribution, and is something that needs to be permitted by the license. It doesn’t matter if it’s git or something else, in the end that’s just a way to host potentially copyrighted material.
Though if you have some reference on why this is not the case, I’d love to see it - but I’m not gonna take a claim that “that’s very much a part of most git flows”.
Illegal according to who?
The US? Why would China care, they are their own country with their own laws.
International courts? Who is enforcing those judgments?
deleted by creator
It’s not about laws at this level but about whether it is worth to do vs possible repercussions
Again, what repercussions? Who will enforce an ICC judgement against the CCP? Laws aside, what possible actions could be taken? I guess sanctions but that’s unlikely over something like this.
You can buy pirated software or pre-cracked consoles in stores there. They don’t care.
Law do not exist by itself; it’s the result of balance of power. How would you know that your State do not use illegally free software ? And if you know it, could you sue it ? Even if it’s a classified administration ?
Apply laws Internationally is even worse. It usually depends of the imperialist relationship between States. For exemple, Facebook rules was illegal in France, but France changes it’s laws rather than sue Facebook. A decade later, the whole European Union could forte RGPD upon the GAFAM.
China have nothing to fear in ignoring those licence, and we shouldn’t rely on it to protect our work. However we could strengthen our common defenses, through FOSS for people in the US … and maybe trade unions elsewhere.
I think the major issue is here is that they are “mirroring” with the same username without clear indicating they are mirrors and they are modifying all the github links in Readme to GitCode. But if you want to claim your project, they want to only comment using the issue section of a project which requires account; but then you have to have a Chinese phone number to register account, and you will automatically get a Huawei Cloud account when you registering it
Edit: also some background info about the company behind GitCode from my other comment: the company behind GitCode is funded and owned by CSDN (China Software Developer Network) and the actual infrastructure and service is provided by Huawei Cloud. On the website they have written this statement in the registration page.
CSDN is mostly a platform to share posts on software development, but it is known to have a lot of issues, including:
- poor content and directly copied posts from other people without consent, which to a point people is considering the site a content farm; it is even a top blocked site on Kagi;
- All code provided there requires “coins” to download, even they are open-sourced code; it was reported multiple people in China got scammed via CSDN;
- You have to login to copy code on the post, and sometimes hides half the post to require you to login to read.
- All code provided there requires “coins” to download, even they are open-sourced code; it was reported multiple people in China got scammed via CSDN;
- You have to login to copy code on the post, and sometimes hides half the post to require you to login to read.
Oh fuck! Capitalism with beastly grin strikes back.
God damn it, Jiaan Yang!
I call my uncle, he’s very corrupt
New New Internet.
Put content that is illegal in China into your code, problem solved!
Include “Winnie the Poo” into your next oss project!
AbstractBaseWinnieThePoohFactory
The phrase Tiananmen Square massacre in each file.
Actually that happened 😂 they accidentally “mirrored” some activists’ repository and got blocked temporarily
Great! Now I know who to contact when I accidentally delete all the plaintext API keys and passwords I had stored in a public github repo.
Apart from the dozens of scrape bots that already stole them?
You’re supposed to revoke API keys that are leaked. Not try to “unleak” them
Oh boy, Lemmy really doesn’t get sarcasm without the “/s”, huh?
I love how every Chinese company is called “China”
Yeah… That’s because they are. it is required that every Chinese Company has to be owned by “tHe PeOpLe” (CCP)
Lmao
Gotta disguise being a capitalist country somehow.
Capitalism is when the public owns the things. And Communism is when a handful of private individuals owns the things.
No… Capitalism is when a handful of individuals own the means of production and have full authority on how they are used.
Communism is more akin to when the workers decide what to do with the means of production they operate.
You got this literally backwards.
So what’s it called when the government is a handful of private individuals, as opposed to representing the public?
Oligarchy or aristocracy, and that’s Russia. And the US at this point lol.
The Aristocrats
Badum tish!
Facebook = America
Yeah, though the Chinese government isn’t doing this out of the goodness of their heart, this is what open source is about.
Someone reupload yuzu, stat!
Some random Chinese company: does something jenky
Blogger: “The entire country of China is doing this jenky thing!”
The random Chinese company: owned by Huawei and CSDN (where CSDN is known to be the worst site known to Chinese developers where they literally costs money to let you download open source code)
Edit: i think my original is a bit unclear, so this is a more detailed info: the company is funded and owned by CSDN (China Software Developer Network) and the actual infrastructure and service is provided by Huawei Cloud. On the website they have written this statement in the registration page.
CSDN is mostly a platform to share posts on software development, but it is known to have a lot of issues, including:
- poor content and directly copied posts from other people without consent, which to a point people is considering the site a content farm; it is even a top blocked site on Kagi;
- All code provided there requires “coins” to download, even they are open-sourced code; it was reported multiple people in China got scammed via CSDN;
- You have to login to copy code on the post, and sometimes hides half the post to require you to login to read.
All Chinese companies are the CCP. That’s how the system works.
And all US companies follow US laws and crazy people say they do the bidding of CIA/NSA/FBI- which they do, to a degree.
Yea they would have to do their bidding if the government came knocking with subpoenas.
Funny how you say something similar and we have such different karma for it.
Might be because of our approaches?
Your’s comes across as a sort of whatabout that nobody asked for and mine is just a statement of fact related to what you mentioned.
It’s not inaccurate to say that the Chinese government has a tighter leash on all business in their country than the US has in theirs though.
And they have been!
omw to get all the homebrew stuff NIntendo got removed from github lol