GitHub Education Verification Has Become Absurdly Invasive, Broken, and Detached from How Universities Actually Work #207973
Unanswered
edluyuan
asked this question in
GitHub Education
Replies: 1 comment
|
💬 Your Product Feedback Has Been Submitted 🎉 Thank you for taking the time to share your insights with us! Your feedback is invaluable as we build a better GitHub experience for all our users. Here's what you can expect moving forward ⏩
Where to look to see what's shipping 👀
What you can do in the meantime 💻
As a member of the GitHub community, your participation is essential. While we can't promise that every suggestion will be implemented, we want to emphasize that your feedback is instrumental in guiding our decisions and priorities. Thank you once again for your contribution to making GitHub even better! We're grateful for your ongoing support and collaboration in shaping the future of our platform. ⭐ |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
🏷️ Discussion Type
Bug
💬 Feature/Topic Area
Verification Help & Guidance
Hi everyone,
This is getting stupidly irritating.
I am trying to renew my GitHub Education benefits, and the verification process has become so unnecessarily invasive, brittle, and detached from how universities actually operate that I genuinely do not understand who designed this system or who it is supposed to work for.
First: why is precise physical location required at all?
Requiring students to physically prove that they are standing at some location GitHub has decided constitutes a university campus is already an extraordinary privacy requirement for something as mundane as verifying student status. It goes far beyond what should reasonably be necessary when universities can issue enrollment letters, institutional email addresses, student IDs, transcripts, and other official documentation.
Worse, the location verification appears to assume that a university is a single point on a map.
That is simply not how many major universities work.
Universities in London, New York, and essentially every other major city routinely operate across multiple buildings, hospitals, institutes, laboratories, research centres, and satellite sites. A student or researcher can be physically working at their university every day without being anywhere near whatever polygon GitHub has decided represents the "campus."
That is exactly my situation. I am at my university, working in a dedicated university laboratory, but apparently that location does not count. To satisfy GitHub's verification system, I had to physically travel roughly 5 miles into the city simply to stand somewhere that the automated system considers sufficiently "university-like." and it still fails
I wasted half a day doing this.
And the verification still failed.
Then there is the university-name matching.
My university is UCL(University College London). It operates publicly and institutionally as UCL since 2003. It has done so for well over two decade. Yet the verification system complains that documents (id card and school letter) containing "UCL" do not contain the university full name because apparently it expects some different textual representation of the institution that is only used 23 years ago.
This is not fraud detection. This is bad string matching.
Then I am told to change my billing name to my complete legal name.
Then I am told to change my GitHub profile name to my complete legal name.
Then I provide official university documentation.
Then I provide location access.
Then I physically travel to the location your system wants.
And after handing over progressively more personal information, changing my account information to satisfy the verifier, and wasting hours of my time, the system still refuses to verify me.
At what point does somebody at GitHub recognise that this process is broken?
The most infuriating part is that there appears to be no meaningful route to individual review. When the automated system makes an obviously incorrect decision, there is seemingly no competent human being available to look at the evidence and say, "Yes, clearly this person is a student at this institution."
So GitHub has built a verification process that demands excessive personal information and location access, makes simplistic assumptions about university geography and naming conventions, and then provides users with no effective recourse when those assumptions fail.
That is an unacceptable combination.
If you are going to demand sensitive personal information from users, you have a responsibility to handle it proportionately and to build a verification system competent enough to justify collecting it in the first place. Requiring more and more information while producing a worse verification outcome is not security. It is irresponsible product design.
I once worked at Microsoft, and I remember GitHub Education being dramatically less hostile than this. The current experience is embarrassing.
At this point, experiences like this are yet another reason to move more of my work to alternatives such as Codeberg. I should not need to surrender my location, restructure my public profile around my passport name, alter billing information, travel across a region, and repeatedly upload institutional documents just to convince an automated system of something that could be established from a single piece of official university documentation.
Please fix this.
At minimum:
This verification process is not merely inconvenient. It is invasive, badly designed, and astonishingly disrespectful of users' time and privacy.
And after forcing users through all of that, it still does not work.
All reactions