The trouble I had trying to contact Twitter support about a security issue
twitter.com
twitter.com
The only two ways to reach such hostile corporations is via legal or a PR disaster.
That would be relevant enough here (and several Germans have successfully got courts to issue warrants for that, and got restraining actions against twitter users)
I could not find, from a cursory review, any GitHub offices in the EU. Nor does an entity not investigating a doxxing claim in a timely manner make them "hostile", only apathetic.
I'd have agreed with you on that until last year, when the US decided that US law applies to foreign entities, even if they have never been in the US, never did business with US entities, never used USD, etc (the famous case w.r.t. 9/11 and Saudi Arabia which Obama vetoed).
That case legitimizes using national law against a foreign entity. And, just like in the Megaupload case, where the US seized assets of a German citizen in New Zealand, the EU could seize GitHub's assets remotely.
Such a situation has happened only once before, where an airplane of a foreign airline was seized to force the airline to issue a refund to a customer. In the same way, servers rented by GitHub could be seized, and, as argued above, enough cases exist to justify that.
Is it appropriate in this case? Probably not. Does the EU have a legal tool to enforce it? Yes.
I’m not so sure. France seizing Google assets last year was quite a sign, and they’d likely be able to do so again.
Yes, the EU Commission and the German government are quite corrupt since Google, Uber, MS and co have outright bought them, but France, the EU Parliament and the courts would still fight in this case.
The second was literally caused by a typo on my end, and it literally took 82 days and me asking some random GitHub employee on his AMA repository what to do when support ignores you to get it resolved.
Edit: Your first reminder email is already quite harsh ("STILL no response? [...] Come on!")... wouldn't be surprised if that pissed the assigned support worker off.
See stackoverflow etc were for a couple of years at least it seemed that more likely or not any really useful question/answer would be flagged/closed/something. I've seen less of it lately so either I developed a blind spot, google changed ranking, SO decided to stop doing this (I've seen some people trying to advocate common sense in meta.)
One of my favourites: an otherwise relevant question on networking being flagged of because the equipent in question was placed between two corporate networks and the rules specified that it had to be placed in a corporate network. :-/
It started with "choose your option", "press x.." call routing. You know, the ones which keep you trapped in a menu while charging premium rates. How many times have we all shouted "give me a human!!" to an automated call system?
This rampant increase in (money/job/man-hour -saving) bots seems to me to be very short-sighted and totally destroying the relationships that companies used to have (or dreamed of having) with their customers/users/(unwitting prisoners).
I don't think this is true at all. If the bots were effective problem solvers then there'd be no problem. The issue is not some emotional need for human connection. OP certainly didn't need that - he would have been fine with a bot that correctly identified his email as a security report, forwarded it to the appropriate engineer, and let him know.
The issue is that the bots are completely useless for anything but idiot problems. Frankly, a comparably competent human would be much more frustrating.
So, it's not clear to me that app-based 2FA actually is broken. Still, given the security weakness of SMS, not letting people disable it in favour of an alternative form of 2FA does seem like a bad decision.
"Security issue" should be a red flag for support.
What can you realistically expect from "support" when you're not an actual paying customer of Twitter?
And I think that's not unreasonable. The security team is mainly about triaging security vulnerabilities. They likely aren't equipped to deal with an issue that appears to be restricted to a single account, that's related to an optional feature.
Now, Twitter's main-line support seems to be worse than useless, but I suppose that's to be expected, sadly.
It is security for the user, not for the server. It is still security.
It's actually three. Three accounts, on three different browsers (Chromium, Firefox, Safari), using three different operating systems (Ubuntu, Windows, macOS). I was able to replicate it exactly as I've described every single time. They claim that they haven't. I'm in no position to try it with a larger number of accounts.
If you don't pay for the product you are the product.
I wonder how they respond to 2FA fault complaints from accounts like @realKimJongUn .