Based on the history of communication with Gruber, they should probably assume no reply means it's NOT okay... but then no progress would be made, ever.
> commit history, push log, and all issues and pull requests
A force push will still show up in the log. Issues and PRs aren't deletable, so that lends a bit of credibility to this. Sure, said engineer probably has access to erase the push log and delete the issues or PRs directly from the database, but parties involved would likely still have email notifications related to it.
They never admitted to it being a response to the incident with Zed, but the timing was too convenient. That blog post was dated 05/31/2011. Zed's commits to the repo in question happened on 05/28/2011: https://github.com/moron5/dongml/commit/f4b8df910e4048202768...
It's not throwing him under the bus. It's distancing him from the investigation. That's both to protect him, in case things favor his story, and to protect the company, if it turns out he was in the wrong.
In both cases, they wouldn't want him having any potential influence on the investigation. To do that, his power within the company needs to be suspended until a conclusion is reached. The parties investigating (likely HR and the other founders) must be able to do their job without fear of retaliation from the accused founder, that would taint the decision.
How? Easily. If you're investigating the matter you want to distance all parties involved from the situation, so that they cannot influence the outcome. If Julie was still employed there, she would have certainly been put on leave as well.
This may sound extra paranoid, but I've locked myself out of 2FA'd accounts before and recovery is not fun, so I go out of my way to keep the recovery codes secured but available to me in case of catastrophe.
First, I make an encrypted disk image with a very strong, unique passphrase (easy on OSX, not sure about windows). In this I put the QR setup codes and my recovery codes. I put a copy of this on every device I own, every computer I own, stash it in my home directory on my server, and put it on dropbox. I then share the dropbox copy to two friends, and instruct them to hold on to it in case I lose access to all my devices. Any time I enable 2FA on a new account, like I did today, I update the image and redistribute it.
I previously kept a copy on github as well as dropbox, but now that both are behind 2FA I wouldn't be able to recover from those sources if I lost all my devices. Maybe I should push a copy to pages.github.io under some secret path that only I knew.
Oh, and check out BitTorrent Sync, it makes it really easy to distribute among my computers and phone without worrying about dropbox somehow losing my files or preventing my access.
When github says "We are disrupting how software is written in the enterprise", the very first thing that comes to my mind is not catering to companies that won't give up IE6.
When you are just starting out and have no real leverage in the deal, sure. But it sounds like the GitHub guys were the ones holding all the cards in this deal, maybe they made sure the terms of the deal excluded that "general rule".
Did you at least try to contact their support? If "someone is in on it" and they're all laughing at you already, yea, nothing would happen. But what if you're just making assumptions about them for no reason? it's hard to cry that they hate you and won't do anything if you didn't try official channels to get shit fixed.