Skip to main content

This is a new website theme. Help me improve it and give your feedback (opens in a new tab).

Debian

Spoofing commits to repositories on GitHub

The following has already been reported to GitHub via HackerOne. Someone from GitHub has closed the report as “informative” but told me that it’s a known low-risk issue. As such, while they haven’t explicitly said so, I figure they don’t mind me blogging about it. Check out this commit in torvalds’ linux.git on GitHub. In case this is fixed, here’s a screenshot of what I see when I look at this link:

Free Software Efforts (2018W33)

I’m writing this weekly report early this week as I won’t be around tomorrow to post it. I will be mostly offline next week as I will be at ACM SIGCOMM 2018 in Budapest, Hungary. Here’s what I’ve been up to: Tor Project Lots of Onionoo and Debian packaging this week. Onionoo Graph History Documents On Monday, we released Onionoo 1.16.1 and deployed this to the official Onionoo instances. This fixed the issue with the serialization of Graph History documents that was breaking history graphs on Relay Search.

Free Software Efforts (2018W31)

Here’s what I’ve been up to: Tor Project This week has been more reviews than writing code. Onionoo history periods change To simplify the Onionoo codebase and remove redundant data from the documents, the 3-month graphs will now become 6-month graphs and the 1-month graphs will be dropped. I have been reviewing changes for this in Onionoo and ensuring that Relay Search is prepared for the changes. Tor Metrics News via Twitter I’ve been exploring syndicating the Tor Metrics news feed via Twitter using Huginn.