Live data from Hacker News

Wikipedia globally blocks Apple Private Relay IP ranges from editing

meta.wikimedia.org

21–30 of 98 posts

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#21
post #6

Where does this end? Like if the end goal is to block every IP that has a bad reputation score, why not go all in and block every Tor exit IP and every popular VPN exit node too? If you're gonna do something, do it right. That said, there's nothing stopping me hacking a residential router to make my (anonymous) Wikipedia edits.

It not going to end. AI will make bots indistinguishable from humans, it's already a problem, and will become a major challenge for online services, the internet, all digital content in general. Proof of Human is something that has to be solved sooner or later. The solution is already being explored, governments will have to issue citizens ID-Tokens on some new blockchain, specifically made for that purpose. That way, all content will be signed, and can be verified as genuine. Complete anonymity will be a thing of the past, but I don't think there's really any other way.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#22

Is the premise over at Wikipedia still that an IP address meaningfully identifies a single editor? I think that ship sailed.

In my experience it's extremely effective to filter IP blocks where a lot of trouble seems to come from. Services that don't scrutinize their customers very carefully tend to accumulate questionable customers.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#25

Earlier quoted context omitted.

"I cannot stress this enough, and I think it's important to frame this debate correctly when it comes to discussing these blocks. I have made somewhere around 1200 rangeblocks of webhosting providers in the last 5 weeks or so. Not one of them was targeted at a user." — [[User:Blablubbs]] in linked page Wikipedia doesn't block to punish individuals. It blocks to protect itself. There are plenty of ways around most blo…

I find this all vaguely baffling; I'm by no means a WP expert. If they're not targeted at users, what are they targeted at? Bots?

The tragedy of the commons that happens when you can't establish the reputation of your visitors because regular users are indistinguishable from malicious actors when signals like IPs are intentionally obscured.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#26
Stupid and disappointing. Wikipedia and others should move decisively away from using IP addresses as any form of unique ID and address the actual problem in a way that still preserves the option for useful pseudonymity and participation. The basic issue with moderation is the balance between the time/resource cost of moderation and the time/resource cost of evading it times the quantity of bad actor interest. Like if it costs the site two cumulative human minutes and paying for that somehow ($2 at $60/hour, or limited volunteer resources that should still be valued) to make a moderation decision but bad actors can evade in seconds for free then the site will eventually suffer from resource exhaustion if there is enough attacker interest. Conversely if it the cost on the site side is two minutes/$2 but hours/$10+ on the attacker side the site is going to win. At some level of imbalance even the best funded attacker will run out first. IP addresses have been used as an extremely clumsy and increasingly bad proxy for cost, because it takes some level of effort/time/expertise to evade it. But as well as evasion being automatable and growing worse (hard to see how IPv6 won't be the final nail in the coffin there at long last) the side effects against innocent and important usage are very bad too. Some sites use money as a proxy (SomethingAwful's (in)famous 10bux say) and that can work in some niche cases, but is also less than ideal for anything that aspires to be global and widely inclusive given gross inequalities in income. It's impossible in most cases to set a level that isn't simultaneously a blocker for many while not even being a speedbump for others.

Instead it's way past time they just attacked the problem directly with some flavor of more formalized cryptographic representation of time. Like just give new users a number to do prime factorization on tuned to a desired target, then sign the result. Ensure they need to do a few hours/days/whatever of crunching (could be graduated, a few hours gets you initial editing rights then you're expected to crunch a bit more over the following months to reach full user level). Scale over time with increasing processing power. Near zero cost to verify. Now even with hacked routers and so on it still always takes some time. For people who don't get banned it's a one-time cost, no problem, amortized over years/decades (Wikipedia is 21 years old now, and there are other older forums still around too). Anyone in the world can participate no money required, just a computer. But for attackers it's a constant burn. And it changes to calculations for things like soft bans too. If you've got a token representing a week's worth of compute built up over a few years and get a 48 hour ban, the incentive against ban evasion is high. It's not possible to build back up another token before the ban expires.

It's a shame there isn't some standard for this, no reason in principle a handful of authorities couldn't make chrono-tokens that any site could recognize and keep their own DB of. No permanent identity involved, no law enforcement, always the chance to start fresh, every site can choose whether to worry about other sites' bans or not (or contribute back their own or not). A token need not be tied to any account at all in fact. And no algorithms involved either, humans can take the driver's seat again because the cost equation is firmly back in moderators' favor and they have a dynamic tool to respond to abuse (they can just temporarily increase the time req during an attack surge as high as needed to quench it while not hurting long time users or even stopping new ones from signing up then lower it smoothly back down to let new people start faster as whatever caused the attack winds down).

It stinks we're into the 2020s and moderation doesn't really seem much different than the 90s.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#27
post #20
post #19

can someone explain why an account isn't a requirement to contribute to Wikipedia?

Why should it be?

Because that seems to be what the people in charge actually want but are half-assing in the name of optics.

IDGAF one way or the other, but if you're going to be banning millions of users from editing via their IP, just commit to saying "We need to be able to identify you vandals, and a user account is the easiest way".

You're either true to a mission statement, or you should stop virtue signaling beliefs you don't hold with your mission statement.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#28

Earlier quoted context omitted.

I find this all vaguely baffling; I'm by no means a WP expert. If they're not targeted at users, what are they targeted at? Bots?

The tragedy of the commons that happens when you can't establish the reputation of your visitors because regular users are indistinguishable from malicious actors when signals like IPs are intentionally obscured.

That's only because they're using weak authentication. If they required users to use something like WebAuthn, the bot problems would be significantly easier to deal with.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#30
post #27
post #20

Earlier quoted context omitted.

Why should it be?

Because that seems to be what the people in charge actually want but are half-assing in the name of optics. IDGAF one way or the other, but if you're going to be banning millions of users from editing via their IP, just commit to saying "We need to be able to identify you vandals, and a user account is the easiest way". You're either true to a mission statement, or you should stop virtue signaling beliefs you don't h…

> Because that seems to be what the people in charge actually want but are half-assing in the name of optics.

Most certainly not. The people in charge actually want it to be open. You are simply watching those ambitions splinter somewhat as they are beset by the crashing waves of the harsh reality that is the Internet.

Post reply on HN