I was checking some feature I did not notice before on GitHub called "Audit log". It registers all the events that happen in a GitHub organization.
And it shows you the location of the contributor!
In this case it was the VPN exit hop. But not everyone uses VPNs, and when you contribute long enough to a project, one day you'll have the VPN off.
I'm sure many people that have contributed to open source projects were not aware of the maintainers being able to see their location. I definitely wasn't.
But there's more! Maintainers can enable collection of IP addresses from the contributors!
I can tell you that it's off for JoinMarket NG, but you would have to trust me about it, because I can't prove it. Same goes for all other organizations you've ever contributed to.
An alternative is https://gitworkshop.dev/npub1w3vaxva0vcrx7pnvlpmede5smvafdl69xnu7ma82kaxl9us89zdsht4c5c/relay.ngit.dev/joinmarket-ng were things like this don't happen by design.
But the fact that Nostr relays and grasp servers don't share your IP with the repo maintainers, does not mean that they themselves can't see where you are connecting from. Of course they can.
Github is not a good place to develop Bitcoin Core or any Bitcoin related projects.
Yeah. I raised this a while back too #894013
Oh! Missed that one... Wish I saw it earlier.
K00b don’t doxx me plz
By "contributor", you mean anyone whose commits get merged? Or are commentors exposed as well?
It's even worse... Organization owners can see the location where any action was made from. Including:
Every "write" action that you do under an organization basically.
But ironically, what you can't see, not even in audit logs: someone made a PR on your repo and you have been discussing this for a month. Then they in all their wisdom go onto another completely unrelated repo and say a bad word. Github suspends that account.
Your discussion is gone. No trace anywhere. Only way to figure it out is to contact support and they'll tell you: the user is suspended for reasons we are not disclosing.
Wonderful. So if you ever need to introduce a vulnerability somewhere, just do, and then spread some hate speech in other repos to get your records cleaned up👍
Exactly. Everything will be gone except the raw commit author, so make sure you set that to someone you dislike.
what else would you expect?
For them to keep those logs to themselves. Wouldn't you?
I would not keep logs at all, but hey, I don't work for microzoz and that's user-generated data, pure gold in the information age we currently are.
Sure. I think them collecting that data is to be expected. The surprise is them sharing user data with other users.
Erasing the gh repo and just leave a link to the new nGit one would be the best you can do to drive people in the anon side
idk... I like providing both options. But it's not like the IP collection problem goes away with ngit (nostr relays and grasp servers still might).
Why was Jam removed from the latest Start9 OS?
Was it? No idea. I'll ask tbk. We're working on a beta release of jam v2 for start9 that should be ready soon.