GitHub Renamed Me (2014)
russbishop.net
russbishop.net
I asked GitHub if they could change my username to one that was already taken. As long as the account does not have repos of their own and was deemed sufficiently inactive they can take it.
The support staff approved my request, but I have friends who’ve gotten declined.
> I created my account two years ago in anticipation of being able to open-source more code and I wanted to reserve my name; I had a couple of forked repos but that's it.
The author says GitHub can 'modify his repos at will', but earlier he says he doesn't even have any repos besides a few forks (which were likely not modified)
I had received an email several years ago informing me that it was going to be removed. They gave me the equivalent to a coupon for a free year of the github personal plan as compensation.
To this day it'll tell you that the username is "unavailable" if you try to sign up with it, and the page just 404s.
Today the profile just 404s
edit: yep this is his account
My only thought was that it was during the MSFT acquisition due diligence, and my username was an unfortunate victim of whatever compliance requirements they had to satisfy.
I’ve asked personally in the last 12 months for a couple situations and been declined by GitHub Support.
Looking quickly on Reddit mine isn’t an unusual experience.
It was good while it lasted!
Tried again about 12 months ago for a different username/org and was told this is no longer possible.
I almost gave it away the first time, but the person wouldn’t provide proof of it being their name. Future requests made me realize it was just a coveted username
Two years might be a little short though.
There are individuals that pay ~$4/month for GitHub Teams, plus other services (Copilot, CI, LFS, Packages, etc). They may not have public repos, but that shouldn't matter.
Or simply they can do it, then it'll up to you to sue them.
Good luck!
I assume they think their checking for emptiness and inactivity covers these cases to some reasonable likelihood.
Yes it would, OP would hypothetically push to old user/org not realising their namespace had changed, but the key would check out, and potentially what was private would now be public.
But anyway, it was a hypothetical, and relatively unlikely, since for real damage (what should be private being public) you'd need to know or be misfortunate/lucky in happening to use exactly the right (or wrong) repo name anyway. And as I said hopefully/I assume they do wipe remove the key anyway.
It's still a bit curious and troublesome.
Doing a bit of snooping, this post was March 2014, his first interaction on Github was February 2015. So he still didn't do anything on Github for 11 months after the name change.
Plenty of projects are using GitHub as a social hub. Pushing code isn't the sole use of a username there.
Sure, he mentioned it. He reserved the name in preparation for open sourcing some projects, but medical and personal issues delayed that happening for a while.
https://docs.github.com/en/enterprise-cloud@latest/admin/ide...
The people they care about don't use GitHub oauth, but instead use their own private idp like Okta.
Seems a good idea to put user generated content somewhere else, like example.com/users/OJFord instead of top-level say, and then if you decouple handle from displayed name people don't care to claim they're clean name as in OP so much either. But of course for the URL, you have to think of that in your early days - GitHub can't break all those links now!
> Does this mean Github staff can basically take over any private account without contacting the owners?
That's an incredibly common feature to have on the admin side. Three of the four companies I've worked at have had some form of "log in as this user" button, with general guidance to not do anything dumb. The fourth had good reasons for not supporting that, but it made debugging anything happening in production incredibly annoying.
> Could they quietly manipulate my own repos by changing my ssh key and pushing commits?
They _literally own the servers_. They don't need your ssh key. Likely not _everyone_ has direct filesystem access, but at least a few people do.
By hosting anything on a cloud service, you are trusting the people running that service. If you don't trust them, don't do that.
Address: 1800 Bishops Gate Blvd
Isn't gate common way to suffix scandals in USA?
If the client keys on "login" rather than "id" (this GitHub tutorial, for example, only mentions the former, not the latter: https://docs.github.com/en/apps/creating-github-apps/writing...) and then stores "github user rbishop can access account 123456 on our system", the new owner of the account name would likely be able to hijack the previous owner's 3rd party accounts.
I can only guess they thought it was setup for some sort of scam, but I can't imagine what.
1. A script/CI/etc is pulling the latest releases from the repository. 2. Ownership of the account is changed. 3. The new owner controls the contents of the repository, and can perform a supply chain attack.
I'm not sure GitHub would be liable there, but personally I wouldn't want to find out the hard way.