GitHub confirms it is blocking developers in Iran, Syria, North Korea, Cuba, and Crimea from accessing private repositories and paid accounts due to sanctions
But not China who had directed a massive DDOS attack at Github for hosting anti-censorship software tools https://techcrunch.com/... https://twitter.com/... Niac / @niacouncil : US sanctions are broad, but companies are not generally prohibited from providing services to Iranian persons who are resident outside #Iran. We urge @Github to rvw its compliance policies & ensure it's not overcomplying/ discriminating vs Iranian persons https://twitter.com/... Chris Albon / @chrisalbon : This is how you address a problem. Explain the context, explain what happened, explain how you are doing your best. https://twitter.com/... @terencehuynh : Before anyone start hating on GitHub for this: GitLab does this too for their cloud offering too due to being on Google Cloud Platform (but they also offer a version that you can self-host) Attack the govt policy, not the businesses who are forced to follow them. https://twitter.com/... Emanuele Rampichini / @emanuele_r : https://help.github.com/... How to loose your remote IT job in 3 easy step of you are in a not in a sanctioned Country: - Go for an holiday to Cuba - Check something on @github - Go back home relaxed and discover you have been banned. 1/2
Context & Ripple Effects
Two developers — one in Crimea, one in Iran — had publicly reported their accounts were restricted due to US trade controls days before GitHub confirmed the policy, making this an official acknowledgment rather than a leak. It also extends a precedent: Apple cut Crimea-based developers off after sanctions back in 2015.
The confirmation lands badly with advocacy groups: NIAC argues US sanctions do not broadly bar services to Iranian persons resident outside Iran and urges GitHub to check whether it is overcomplying. The episode also stokes fears elsewhere — by December 2019 GitHub's COO was weighing a China-based branch as Chinese developers worried sanctions could eventually gate their access to open-source infrastructure.
First-order effects
- Developers in Iran, Syria, North Korea, Cuba, and Crimea immediately lose access to private repositories and paid accounts, cutting sanctioned-region teams out of collaborative code hosting overnight.
- GitHub absorbs immediate reputational pressure: NIAC's public call for a policy review puts the company in the position of defending compliance choices the sanctions themselves may not require.
Second-order effects
- Rival hosting platforms have an opening to court displaced sanctioned-region users, and the optics of overcompliance push every US-headquartered code platform to clarify where its own enforcement line sits.
- The block feeds distrust among Chinese developers about future access, contributing directly to GitHub's consideration of a localized China branch — a structural accommodation driven by sanctions risk.
Third-order effects
- If the pattern holds, developer infrastructure becomes a routine enforcement surface for US trade controls, with platforms defaulting to geographic blocking first and remediation later — a path GitHub itself followed when it later secured a US government license to restore service to Iranian developers.
- Sanctioned-region development communities may consolidate around self-hosted or non-US alternatives, eroding American platforms' role as neutral global infrastructure for open-source collaboration.
The trend: US sanctions are turning global developer platforms into instruments of trade policy, forcing companies like GitHub to choose between blanket blocking and license-backed carve-outs.