5 ms·
GitHub hands out your repo visitors IP like candy who ask for it politely
- Beaver117 3y agoLast two digits are censored. So country/state are given but not exact location
- matthews2 3y agoGiven the partial IP address and request time, the ISP could identify the customer.
- News-Dog 3y agoVPN and Tor Browser?
- jrootabega 3y agoLet's not get so distracted that we forget the main point of the post: should GitHub be providing this information so readily?
- chatmasta 3y agoYou can just put a JPG hosted on your server in the readme and get their full IP.
- jrootabega 3y agoYes, and that is something that will always be possible between the author and the reader, but this is about a third party, GitHub, providing this information to a possible fourth party. That's what the Twitter post wanted to get across.
- chatmasta 3y agoOh right, I missed that because the post linked to the middle tweet in the thread. Still doesn't sound too outrageous. At least, it's not unprecedented and is in line with the existing practices of companies responding to law enforcement requests.
- rtldg 3y agoGithub proxies images so this shouldn't be possible https://github.blog/2014-01-28-proxying-user-images/ https://github.blog/2014-01-28-proxying-user-images/
- chatmasta 3y agoOh wow TIL. Very interesting. And since 2014 too? Nice. They must have done that around the same time Google did it for GMail. I wonder if it's still true. I imagine they have some Content-Security-Policy preventing it so you can't do hacks like embedding an external URL in an SVG.
- rtldg 3y agoTheir CSP does seem to prevent an svg I threw in a readme from loading a png so that's good to see. And a test png in the readme was proxied too. content-security-policy: default-src 'none'; img-src data:; style-src 'unsafe-inline'
- deleted 3y ago[deleted]