Users' Diaries
Recent diary entries
Last quarter, a “getting to know you” survey was made available to the local OpenStreetMap (OSM) communities in the Philippines, to help us better understand the current state of the active contributor base of our community.
The original idea was to run it just for the membership of local YouthMapper Chapters (YMC), but eventually it was made available to anyone who contributes to OSM in the Philippines, here or abroad, regardless of citizenship or affiliations.
I’m sharing my observations from the responses made by the participants who participated in the survey, again, majority of whom comprised of local YMC respondents.
Click on the images, to open them in full resolution in a separate tab.
Are you physically present in the Philippines?
While 86% of the mappers reported that they are physically in the country, mappers coming from elsewhere at 14% was bigger than I expected.
Which of the following best describe your primary undertaking in the OSM project?
..
🍾 YouthMappers UFRJ celebrates its first year!
The YouthMappers UFRJ (Rio de Janeiro, Brasil) completed one year on March 14th, 2024.
And to celebrate this special date, we interviewed Dr. Rogério Luís R. Borba, analyst at the IBGE Foundation and manager of the Brazilian Geospatial Data Directory (“Diretório Brasileiro de Dados Geoespaciais, DBDG) of the Brazilian National Spatial Data Infrastructure (“Infraestrutura Nacional de Dados Geoespaciais”, INDE).
🎥 Watch on IVIDES.org’s YouTube channel.

Rogério talked to us about the importance of open data and how the collaborative mapping can helps Brazil in the production of official cartographic data. The interview was conducted by Dr. Raquel Dezidério Souto and all details can be found at:
🍾 YouthMappers UFRJ comemora 1 ano de registro!
O capítulo YouthMappers UFRJ (Rio de Janeiro, Brasil) completou, no dia 14 de março de 2024, 1 ano de registro internacional.
Para comemorar esta data especial, entrevistamos o Dr. Rogério Luís R. Borba, analista da Fundação IBGE e gerente do Diretório Brasileiro de Dados Geoespaciais (DBDG) da Infraestrutura Nacional de Dados Espaciais (INDE).
🎥 Assista no canal do IVIDES no YouTube.

Rogério conversou conosco sobre a importância dos dados abertos e como os mapeamentos colaborativos podem auxiliar o Brasil na produção de dados cartográficos. A entrevista foi conduzida pela Dra. Raquel Dezidério Souto e os detalhes podem ser conhecidos em:
Happy Burger 11309 Midlothian Turnpike Richmond, VA 23235
As part of my commitment to OpenStreetMap-NextGen migration, I undertook a comprehensive security review of the existing OpenStreetMap website. I followed the principles of coordinated vulnerability disclosure, working directly with the maintainers to responsibly report my findings. Today, I’m making the details of this process public and verifying the status of the fixes.
Disclosure Timeline
- 2023-11-04 - Contacted Ruby security maintainers & disclosed the timeline publicly
- 2023-11-08 - Maintainers acknowledged the report
- 2023-12-04 - Reported additional vulnerabilities with a 3-month deadline
- 2023-12-06 - Maintainers acknowledged the additional report
2024-03-02 - Publicize vulnerability details- 2024-03-15 - Publicize vulnerability details
1. Plain-Text Authentication Token Storage
Authorization tokens (oauth, session, user tokens) are stored in plain text. Read access to the database allows full impersonation of any user.
Status as of 2024-03-15: Partially vulnerable (oauth still depends on plain text storage)
NextGen Codebase Status: Fixed (all authorization tokens and credentials are hashed or encrypted for secure storage)
2. Insecure Email Reply Address Tokenization
The tokens used to ensure the authenticity of email replies are too short (24-bit), making them susceptible to brute-force attacks. An attacker could potentially guess the token and impersonate a legitimate user in email conversations. This vulnerability is especially dangerous if the attacker already has access to a conversation’s metadata (allowing for complete security bypass).
Status as of 2024-03-15: Fixed (now with 48-bit security)
NextGen Codebase Status: Fixed (128 or 256-bit security; undecided)
3. Unbounded GPX Extraction Denial of Service
Apparently, OSM in Vietnam is in a very poor condition. And one of the reasons would be the absence of several nature reserve areas, even compared to the two neighboring Indochinese brothers, Laos and Cambodia. Despite the fact that the Department of Forestry has published a document stating that there are 34 national parks and 56 nature reserves, until now (15 March) only half of them have been mapped to OSM.
Here’s the list:
National parks
- VQG Ba Bể/Ba Be NP
- VQG Ba Vì/Ba Vì NP
- VQG Bạch Mã/Bạch Mã NP
- VQG Bái Tử Long/Bái Tử Long NP
- VQG Bến En/Bến En NP
- VQG Bidoup - Núi Bà/Bidoup - Núi Bà NP
- VQG Bù Gia Mập/Bù Gia Mập NP
- VQG Cát Bà/Cát Bà NP
- VQG Cát Tiên/Cát Tiên NP
- VQG Chư Mom Ray/Chư Mom Ray NP
- VQG Chư Yang Sin/Chư Yang Sin NP
- VQG Côn Đảo/Côn Đảo NP
- VQG Cúc Phương/Cúc Phương NP
- VQG Du Già - Cao nguyên đá Đồng Văn/Du Già - Đồng Văn Karst Plateau NP
- VQG Hoàng Liên/Hoàng Liên NP
- VQG Kon Ka Kinh/Kon Ka Kinh NP
- VQG Lò Gò - Xa Mát/Lò Gò - Xa Mát NP
- VQG Mũi Cà Mau/Mũi Cà Mau NP
- VQG Núi Chúa/Núi Chúa NP
- VQG Phja Oắc - Phja Đén/Phja Oắc - Phja Đén NP
- VQG Phong Nha - Kẻ Bàng/Phong Nha - Kẻ Bàng NP
- VQG Phú Quốc/Phú Quốc NP
- VQG Phước Bình/Phước Bình NP
- VQG Pù Mát/Pù Mát NP
- VQG Sông Thanh/Sông Thanh NP
- VQG Tà Đùng/Tà Đùng NP
- VQG Tam Đảo/Tam Đảo NP
- VQG Tràm Chim/Tràm Chim NP
- VQG U Minh Hạ/U Minh Hạ NP
- VQG U Minh Thượng/U Minh Thượng NP
- VQG Vũ Quang/Vũ Quang NP
- VQG Xuân Sơn/Xuân Sơn NP
- VQG Xuân Thủy/Xuân Thủy NP
- VQG Yok Đôn/Yok Đôn NP
Nature reserves
Nature reserves with official “Nature Reserve” title
Official “Nature Reserve” title refers to the fact that these areas have their own management board (ban quản lý) and is usually a division of the provincial departments of agriculture and rural development (Sở Nông nghiệp và Phát triển Nông thôn). These includes:
Please also share/blast in your socials/network :)
—— 👂👀 Have you heard? 📢 We have launched 🚀 the #OSMFMembershipCampaign 2024!
Help us grow and diversify #OSMF members in regions 🌍🌏🌎 where there are no or very few OSMF members! You can support! 🎯 https://blog.openstreetmap.org/2024/03/12/call-to-action-help-us-grow-and-diversify-osmf-membership/
Join ✍️https://supporting.openstreetmap.org/#Membership-Categories
openstreetmap
presentation of the Mapeaia Belém project to the Brazilian Openstreetmap community

we present the Mapeia Belém project to the Brazilian openstreetmap community, which is an initiative of UMBRAOSM União dos Mapeadores Brasileiros do Openstreetmap and partners such as Meninas da GEO, Capitulos Youthmappers and other groups and in addition to the Brazilian Openstreetmap community and aims to update data in city of Belém for the Major Events that the city will host in 2024 and 2025 such as FOSS4G and COP 30.
Hallo zusammen,
ich habe auf der Arbeit die Aufgabe das Parken in Frankfurt mithilfe des Rapid Editors zu taggen. Dafür möchte und soll ich so präzise wie möglich vorgehen. In vielen Straßen kommt es aber vor, dass verschiedene Parkrichtlinien oder Ausrichtungen bestehen. Außerdem sind einige Straßen sehr lang in OSM.
Eine Möglichkeit ist, die Straßen mithilfe eines Punkts zu teilen, um verschiedene parktags einzufügen. Das zerstückelt aber oft die Straßen und es entstehen kleine Teilstücke mit verschiedenen ID’s. Die zuvor eingefügten Attribute bleiben aber bestehen.
Jetzt ist die Frage, welche Folgen es hat, die Straßen aufzuteilen, um präzise Parkangaben tätigen zu können, oder ob das keine wirkliche Rolle spielt. Viele Straßen sind ja sowieso schon sehr aufgestückelt.
Über eine Antwort würde ich mich sehr freuen.
Gruß Simon (Infra-Simon)
Está edição foi feita a edição em um dos únicos hospitais do município de Ponte Nova, é um hospital localizado no centro da cidade e recebe muitos pacientes.
Algumas mudanças feitas para quem vive em Contagem: coloquei a barraca do Tio toninho em frente a prefeitura, algo que está a anos e não se foi notado no mapa. E algumas coisas em torno de Minas Gerais. Vou fazendo mudanças as quais considero necessárias. Bom mapeamento a todos!
Some changes made for those who live in Contagem: I placed Tio Toninho’s tent in front of the city hall, something that has been around for years and was not noticed on the map. And some things around Minas Gerais. I’m making changes that I consider necessary. Good mapping everyone!
The key “name” is one of the 10 most frequently used characteristics of objects - according to Taginfo 100 million times. It is probably also the tag with the most errors. A random sample in my neighbourhood showed an error rate of 8.4% (N=1092). Possible reasons:
- lack of knowledge
- misunderstanding
- tag missing
The proposal relates to point 2, possible misunderstandings regarding the meaning of the “name” tag.
Current Wiki structure
The main article names lists 14 different keys of the proper name, differentiates them from each other and from non-proper names and gives many examples. The article is quite extensive with 29k characters.
Of the 14 keys, 5 keys do not have their own wiki page: int_name, loc_name, nat_name, reg_name and nickname.
The article on the key name is similar to the main article names, only somewhat shorter. It is still quite extensive with 18k characters. All other articles are short.
Issues Main article “names”
Readability.
The text is very extensive and therefore requires perseverance. However, it deals with all aspects of name keys in detail and consistently. Many examples illustrate the basic idea.
Issues key:name
Readability, redundancy, clarity.
The text for the key name is very long at 18k characters, the essentials are lost in the sea of words. Much of it is a repetition of information that is already available elsewhere:
- The “values” section is almost completely contained in the main article.
- The “Variants” table is already completely contained in the main article.
- The table of language subkeys covers more than 3 screen pages and is also fully covered on the “Multilingual names” page.
- The sections “Road names” and “Additional data” are also already included in the main article. Only the sentence with “strapline” is supplementary.
In addition to the high redundancy, the text is also blurred. The core - the proper name - is not mentioned at all. The explanations lead to problematic statements.
Did you hear?
We plan to bring StreetComplete to iOS!
For all that have been eagerly awaiting this to happen, there is more good news, however!
Prototype Fund
The OpenStreetMap Foundation had quite recently launched a worldwide membership campaign with the objective of growing and diversifying OSMF membership in regions where there are very low or no OSMF members. And I am proud to say that I was/am part of this campaign. I should say that it is also my very first time volunteering for the OpenStreetMap Foundation and the experience has been & continues to be very enriching to say the least. In late January, I had responded to a call for volunteers & campaigners to help grow OSMF membership on Slack & since then, I’ve been part of a very diverse, talented & committed group of campaigners & volunteers.
On the first few virtual meet-ups via Google meet, I had promptly signed up for the visual comms/mapmakers role as I believed I could use whatever little designing skills & experiences I had to aid in creating & designing comms material for the campaign. In doing so, I had been thrown into a mix of incredible volunteers from around the world. Our work as visual comms/mapmakers volunteers had revolved around creating posters, pubmats, infographics, maps, etc. and these materials feature a lot about the OpenStreetMap Foundation, testimonials, how to join, membership types, why join, etc. However, generating these materials wasn’t an easy feat as the process often involved planning, a lot of discussions, facilitating, reviewing, and amending the materials as per suggestions/recommendations from the OSMF Board.
I believe that this volunteering opportunity has helped me grow in ways I wouldn’t have imagined because in the short period of only two months, I have learnt a lot about community, having being part of a group with shared or common interest but also acknowledging the different ideas, strengths & capabilities that each one of us had & brought to the table allowed us to effectively work together to bring about the outputs we were tasked to deliver.
일단 동문1동의 학동 지점 건물 및 도로 추가 완료했습니다. 차기에는 서산제일감리교회 동편 지역, 그리고 서령로 남측 지역 추가… 점점 점진적으로 추가할 예정입니다.
빨라야 반 년 뒤에는 끝날 거 같네요.
이후에는 성연면 (서산테크노밸리), 인지면, 부석면, 해미면, 대산읍, 음암면, 운산면, 고북면, 지곡면 순으로 편집해나갈 예정입니다. 물론 해당 지역들은 바뀌어질 수도 있습니다. 길어야 5년은 될 거 같네요
A recent discussion on the osm-gb IRC channel was about how to map chapels within crematorium buildings.
I thought it was worth summarising some of that discussion. These notes pertain to crematoria in England and Wales. I have attended a funeral at that in Geneva, but that was twenty years ago.
One of the difficulties is that most visits to a crematorium are likely to be to attend a funeral service. This is not conducive to any kind of sophisticated micromanaging, but does allow a decent amount of basic observation. In addition I’m not aware of well-developed tagging standards for various features, as may become apparent by looking at some of my examples



