I will neither admit nor deny supplying my credentials to Sci-hub.
I'm neutral on the matter, but there are some obvious paths of recourse for publishers who don't want people sharing their credentials.
(Disclaimer: I work for Crossref, which is an organisation in the scholarly publishing space.)
I'm asking because a friend of mine who's enrolled in 2 colleges, just downloaded the same scholarly PDF (one that's also available through sci-hub) with 2 different college credentials and they had the same sha256sum.
Then when he tried it through sci-hub, he also got the same sha256sum.
Sorry if my disclaimer wasn't clear. I was just pointing out affiliation as standard on HN.