Decide repository visibility and scrub host-specific detail #6

Closed
opened 2026-08-27 23:22:24 +00:00 by tiagoagueda · 1 comment
Owner

Resolved 2026-08-29. Decision: the repository stays public, with lab-specific detail genericised across the whole history. The issue understated the exposure — beyond the SSID, the notes carried six access-point BSSIDs, which geolocation services map to street-level coordinates. See the comment below and ARCHIVE.md.

The repo is public (private: false). Beyond the root password (tracked separately), it
publishes:

  • the WiFi SSID Vicimus (17-mmc1-investigation.md, 36-rescue-sd.md)
  • LAN addressing throughout: 192.168.27.44, .45, .46, gateway .1
  • the build host's username and directory layout
  • hostnames a80-debian, a80-rescue, ouranos
  • (not originally listed) six AP BSSIDs with signal strengths — the item that actually mattered

None of it is a secret on its own, and the port notes themselves are genuinely worth
publishing — this is real mainline work on a board nobody else has documented. The question is
whether the lab detail should ship with it.

Verified clean: no PSK or passphrase anywhere. Only a pointer to ~/a80/wifi.txt on
ouranos, which is correctly not in the repo.

Done when

  • a decision is recorded: keep public, make private, or split public notes from lab config
  • if it stays public, host-specific values are scrubbed or genericised
> **Resolved 2026-08-29.** Decision: the repository **stays public**, with lab-specific detail genericised across the whole history. The issue understated the exposure — beyond the SSID, the notes carried **six access-point BSSIDs**, which geolocation services map to street-level coordinates. See the comment below and [ARCHIVE.md](ARCHIVE.md). The repo is public (`private: false`). Beyond the root password (tracked separately), it publishes: - the WiFi SSID `Vicimus` (`17-mmc1-investigation.md`, `36-rescue-sd.md`) - LAN addressing throughout: `192.168.27.44`, `.45`, `.46`, gateway `.1` - the build host's username and directory layout - hostnames `a80-debian`, `a80-rescue`, `ouranos` - **(not originally listed)** six AP BSSIDs with signal strengths — the item that actually mattered None of it is a secret on its own, and the port notes themselves are genuinely worth publishing — this is real mainline work on a board nobody else has documented. The question is whether the *lab* detail should ship with it. Verified clean: **no PSK or passphrase anywhere.** Only a pointer to `~/a80/wifi.txt` on ouranos, which is correctly not in the repo. **Done when** - [x] a decision is recorded: keep public, make private, or split public notes from lab config - [x] if it stays public, host-specific values are scrubbed or genericised
Author
Owner

Decision: stays public, lab detail genericised — and the issue understated the exposure

Both boxes done. The decision is recorded in ARCHIVE.md ("What is deliberately not published") and, for anyone actually following the notes, in README.md.

What this issue missed

It lists the WiFi SSID. The notes also carried six access-point BSSIDs with signal strengths:

2c:93:fb:9e:b5:f0   2c:93:fb:9e:b5:f8
b8:be:f4:aa:66:cb   b8:be:f4:aa:66:cc
b8:be:f4:aa:68:56   b8:be:f4:aa:68:57

BSSIDs are what geolocation services key on. WiGLE, Google, Apple and Mozilla all map BSSID to coordinates, and unlike an SSID a BSSID is globally unique — a lookup returns a street-level position with no ambiguity. Six of them with RSSI also sketches the building's layout. That is a different order of exposure from a hostname or an RFC1918 address, and it is why the scrub covered history, not just the working tree: scrubbing current files alone is cosmetic, git log -p still shows everything.

What changed

genericised to
6 AP BSSIDs aa:bb:cc:*, radio pairing preserved
SSID Vicimus HomeNet
build-host account builder
LAN 192.168.27.x 192.0.2.x (RFC 5737, real last octet kept)
board MACs device bytes zeroed, OUI and derivation kept

Kept deliberately: hostnames ouranos / a80-debian / a80-rescue, ~/a80/... paths, and vendor default MACs (00:90:4c:c5:12:38, 43:39:00:00:1f:ac) which are not personal.

Board MACs keep their OUI and their arithmetic relationship because 40-bluetooth.md is about that relationship — the BD address is wlan0 plus one, p2p0 is the same address with the locally-administered bit set. Genericising them carelessly would have destroyed the finding. The reversed-byte form in the hcitool command was rewritten to match.

How, and how it was verified

git filter-repo across all 31 commits, then force-push. On the Forgejo server the pre-scrub objects were reflog-expired and gc --prune=now-ed, so the old history is gone rather than merely unreferenced — the previous head 6973024905e2… now returns could not get object info. Repo went 6.1M → 2.2M server-side. The same was done locally.

Verified after the rewrite:

  • zero occurrences of any scrubbed value anywhere in git rev-list --all
  • every changed file had insertions == deletions, so it was pure substitution with nothing lost
  • the diff contained no line that was not one of the 27 replacement rules

Caveats, stated rather than buried

  • Every SHA changed. Any existing clone has diverged and should be re-cloned.
  • 42 commands in the notes now carry a documentation-range address and will not work as written. README.md says so at the top of the Machines section; the mapping is deliberately not recorded in the repo.
  • A local bundle taken before the rewrite still holds the original values. It is a backup, outside the repository, and should be deleted once you are satisfied.
## Decision: stays public, lab detail genericised — and the issue understated the exposure **Both boxes done.** The decision is recorded in [ARCHIVE.md](ARCHIVE.md) ("What is deliberately not published") and, for anyone actually following the notes, in `README.md`. ### What this issue missed It lists the WiFi SSID. The notes also carried **six access-point BSSIDs with signal strengths**: ``` 2c:93:fb:9e:b5:f0 2c:93:fb:9e:b5:f8 b8:be:f4:aa:66:cb b8:be:f4:aa:66:cc b8:be:f4:aa:68:56 b8:be:f4:aa:68:57 ``` BSSIDs are what geolocation services key on. WiGLE, Google, Apple and Mozilla all map BSSID to coordinates, and unlike an SSID a BSSID is globally unique — a lookup returns a street-level position with no ambiguity. Six of them with RSSI also sketches the building's layout. That is a different order of exposure from a hostname or an RFC1918 address, and it is why the scrub covered **history**, not just the working tree: scrubbing current files alone is cosmetic, `git log -p` still shows everything. ### What changed | genericised | to | |---|---| | 6 AP BSSIDs | `aa:bb:cc:*`, radio pairing preserved | | SSID `Vicimus` | `HomeNet` | | build-host account | `builder` | | LAN `192.168.27.x` | `192.0.2.x` (RFC 5737, real last octet kept) | | board MACs | device bytes zeroed, OUI and derivation kept | Kept deliberately: hostnames `ouranos` / `a80-debian` / `a80-rescue`, `~/a80/...` paths, and vendor default MACs (`00:90:4c:c5:12:38`, `43:39:00:00:1f:ac`) which are not personal. Board MACs keep their OUI and their arithmetic relationship because `40-bluetooth.md` is *about* that relationship — the BD address is wlan0 plus one, `p2p0` is the same address with the locally-administered bit set. Genericising them carelessly would have destroyed the finding. The reversed-byte form in the `hcitool` command was rewritten to match. ### How, and how it was verified `git filter-repo` across all 31 commits, then force-push. On the Forgejo server the pre-scrub objects were reflog-expired and `gc --prune=now`-ed, so the old history is **gone rather than merely unreferenced** — the previous head `6973024905e2…` now returns `could not get object info`. Repo went 6.1M → 2.2M server-side. The same was done locally. Verified after the rewrite: - **zero** occurrences of any scrubbed value anywhere in `git rev-list --all` - every changed file had **insertions == deletions**, so it was pure substitution with nothing lost - the diff contained no line that was not one of the 27 replacement rules ### Caveats, stated rather than buried - Every SHA changed. Any existing clone has diverged and should be re-cloned. - 42 commands in the notes now carry a documentation-range address and **will not work as written**. `README.md` says so at the top of the Machines section; the mapping is deliberately not recorded in the repo. - A local bundle taken before the rewrite still holds the original values. It is a backup, outside the repository, and should be deleted once you are satisfied.
Sign in to join this conversation.
No description provided.