pull down to refresh

I was checking some feature I did not notice before on GitHub called "Audit log". It registers all the events that happen in a GitHub organization.

And it shows you the location of the contributor!

In this case it was the VPN exit hop. But not everyone uses VPNs, and when you contribute long enough to a project, one day you'll have the VPN off.

I'm sure many people that have contributed to open source projects were not aware of the maintainers being able to see their location. I definitely wasn't.

But there's more! Maintainers can enable collection of IP addresses from the contributors!

I can tell you that it's off for JoinMarket NG, but you would have to trust me about it, because I can't prove it. Same goes for all other organizations you've ever contributed to.

An alternative is https://gitworkshop.dev/npub1w3vaxva0vcrx7pnvlpmede5smvafdl69xnu7ma82kaxl9us89zdsht4c5c/relay.ngit.dev/joinmarket-ng were things like this don't happen by design.

But the fact that Nostr relays and grasp servers don't share your IP with the repo maintainers, does not mean that they themselves can't see where you are connecting from. Of course they can.

Github is not a good place to develop Bitcoin Core or any Bitcoin related projects.

reply
1215 sats \ 1 reply \ @optimism 4 Aug

Yeah. I raised this a while back too #894013

reply

Oh! Missed that one... Wish I saw it earlier.

reply

K00b don’t doxx me plz

reply
230 sats \ 4 replies \ @Kruw 4 Aug

By "contributor", you mean anyone whose commits get merged? Or are commentors exposed as well?

reply

It's even worse... Organization owners can see the location where any action was made from. Including:

  • PRs (open, close, comment, ...)
  • Issues (same)
  • Actions, pushes, ...

Every "write" action that you do under an organization basically.

reply

But ironically, what you can't see, not even in audit logs: someone made a PR on your repo and you have been discussing this for a month. Then they in all their wisdom go onto another completely unrelated repo and say a bad word. Github suspends that account.

Your discussion is gone. No trace anywhere. Only way to figure it out is to contact support and they'll tell you: the user is suspended for reasons we are not disclosing.

reply
231 sats \ 1 reply \ @m0wer OP 4 Aug

Wonderful. So if you ever need to introduce a vulnerability somewhere, just do, and then spread some hate speech in other repos to get your records cleaned up👍

reply

Exactly. Everything will be gone except the raw commit author, so make sure you set that to someone you dislike.

reply

what else would you expect?

reply

For them to keep those logs to themselves. Wouldn't you?

reply

I would not keep logs at all, but hey, I don't work for microzoz and that's user-generated data, pure gold in the information age we currently are.

reply

Sure. I think them collecting that data is to be expected. The surprise is them sharing user data with other users.

reply

Erasing the gh repo and just leave a link to the new nGit one would be the best you can do to drive people in the anon side

reply

idk... I like providing both options. But it's not like the IP collection problem goes away with ngit (nostr relays and grasp servers still might).

reply
10 sats \ 1 reply \ @anon 5 Aug

Why was Jam removed from the latest Start9 OS?

reply

Was it? No idea. I'll ask tbk. We're working on a beta release of jam v2 for start9 that should be ready soon.

reply