Tempted to call the motion detector in my office „senpai“ because it frequently doesn’t notice me


@hacksilon@infosec.exchange
Sr. Security Specialist at iteratec // alumni // Member of CCC // Crypto means cryptography.
tfr.
For the #selfhosted / #homelab people running #Hister (https://github.com/asciimoo/hister): you should update to version v0.4.0 ASAP. I reported a vulnerability in the previous version that allows any website to download your entire database due to missing CORS enforcement. The author responded very quickly to the disclosure and had a new release ready within a few hours, excellent work on his part.
Sadly, Hister is currently not packaged and does not auto-update, so people will have to manually download a new release, or be vulnerable.
CC , since he included it as a spotlight in this week's newsletter.
GitHub
GitHub - asciimoo/hister: Web history on steroidsWeb history on steroids. Contribute to asciimoo/hister development by creating an account on GitHub.