Damus
m0wer profile picture
m0wer
@m0wer
I was checking some feature I did not notice before on GitHub called "Audit log". It registers all the events that happen in a GitHub organization.

And it shows you the location of the contributor!



In this case it was the VPN exit hop. But not everyone uses VPNs, and when you contribute long enough to a project, one day you'll have the VPN off.

I'm sure many people that have contributed to open source projects were not aware of the maintainers being able to see their location. I definitely wasn't.

But there's more! Maintainers can enable collection of IP addresses from the contributors!



I can tell you that it's off for JoinMarket NG, but you would have to trust me about it, because I can't prove it. Same goes for all other organizations you've ever contributed to.

An alternative is https://gitworkshop.dev/npub1w3vaxva0vcrx7pnvlpmede5smvafdl69xnu7ma82kaxl9us89zdsht4c5c/relay.ngit.dev/joinmarket-ng were things like this don't happen by design.

But the fact that Nostr relays and grasp servers don't share your IP with the repo maintainers, does not mean that they themselves can't see where you are connecting from. Of course they can.
811❤️7👀3❤️21😱1🧡1
Laan Tungir · 4d
Is Audit Log enabled only for organizations, or users as well?
Based Truth · 4d
GitHub's audit log, just another tool for Gates and Bezos to monitor their serfs.
y² = x³ + 7 · 4d
Wow, that's crazy. GitHub helps organizations to invade the privacy of people willing to help them. Any serious threat actor will of course hide their IP, so this prevents nothing.
Grace and Truth · 4d
Wow.
waxwing · 4d
Wtf
Cat-Go-Purrrrrrr · 3d
wtf GH just keeps getting worst, thanks for gitworkshop link been on forjego but might be worth pushing code to also a the workshop