Medium's Policies and Guidelines
github.com
github.com
Just in case anybody is wondering why medium's terms of service are at the top of HN right now
We also keep a changelog on our site as an alternative: https://wordpress.com/tos-change-log/
(Privacy policies are a hot topic in EdTech these days!)
Really, what we have here is the draft documents from which they publish their policies and guidelines, just like a public source repo is a draft repo from which production is deployed (hopefully).
https://medium.com/policy/medium-terms-of-service-9db0094a1e...
https://medium.com/policy/medium-rules-30e5502c4eb4
https://help.medium.com/hc/en-us/articles/214151487
I don't see an indication that the GitHub version is legally binding.
On the other hand, if your code is modified, it can exfiltrate data that you are never getting back, no matter what the legal system says. Even credit card numbers are not the worst, since in theory you can end up reversing every single fraudulent transaction made, and insurance might cover your liability. But in the case of Medium, it could, say, leak the real world identity of a blogger or citizen journalist in a place where doing so would put their lives at risk. So if you are already trusting a third party with the lives of your users who are trusting you with their lives (whether they should or not), is having the text of your EULA swapped by the lyrics of "I am never gonna give you up" really a worst case scenario?
At this point, given how many people use it as the authoritative source for their software, GitHub is already critical infrastructure, on par with GPS and the electrical grid of many countries. So if GitHub goes rogue or is compromised, the damage can be pretty catastrophic. Brave new world, ain't it?
It depends on who you talk to. The legal dept would say that code can be replaced. The coding people similarly look down on contracts as paper anachronisms. Which matters more depends on the situation. The one that matter in any moment is whichever has been attacked most recently.
I would say that errors in a contract are more expensive to fix than code. A change to code can be patched once detected. But drop a key line from a contract, perhaps the limitation on jurisdiction or arbitration, and you might be stuck with costly litigation even if you make a change asap.
So, if I went to a car dealership with my own modified contract in hand, and surreptitiously changed it for the one being put forth by the dealer and got him to sign it, would he be bound by that contract? (independent of whether or not I am committing a crime in that scenario)
Re: The code can be replaced. Sure, I am not worried about losing code at rest, for anything non-trivial you should have plenty of copies of a git repository anyways. But if modified code gets deployed, then suddenly you can take actions that might cost human lives or leak sensitive data and that genie can't be put back in the bottle, at any cost.