Live data from Hacker News

Wikipedia globally blocks Apple Private Relay IP ranges from editing

meta.wikimedia.org

41–50 of 98 posts

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#41
post #26

Stupid and disappointing. Wikipedia and others should move decisively away from using IP addresses as any form of unique ID and address the actual problem in a way that still preserves the option for useful pseudonymity and participation. The basic issue with moderation is the balance between the time/resource cost of moderation and the time/resource cost of evading it times the quantity of bad actor interest. Like i…

Using hashcash and other proof-of-work schemes to limit spam and similar abuse sounds appealing, but I don't see how you can make it work in practice.

1. Defenders use standard PCs and mobile phones. Attackers use GPUs, FPGAs and ASIC and run them in places where electricity is cheap.

For traditional hash algorithms this gives the attacker a thousandfold or so advantage. There has been some work on closing the gap in the context of crypto currencies, but I don't know how close they got.

2. It takes a phone (or even a PC) a long time to burn through $2.

3. Attackers have large botnets and don't pay for the electricity consumed by these.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#43
post #15

Earlier quoted context omitted.

AFAIK their policy is to block IPs that "obscure individual users". Another commenter quoted: > Communities typically block edits from IP addresses that obscure individual users. Surely they are aware that this is basically all IPs nowadays...? If that's genuinely the policy then it should be almost equivalent to just requiring an account for all edits, so why not just do that?

> Surely they are aware that this is basically all IPs nowadays...? There are indeed many classes of IP address which multiplex large numbers of users (mobile network exits, VPN exits, ISPs with CGNAT, some corporate web filtering systems, shared public wifi, tor, satellite ground station exits, residential proxies, ...). However, claiming that "basically all" IPs are multiplexed is definitely wrong. A home or small…

Is that true? I've worked at two ISPs and we never made an effort to make the IPs ephemeral. (OK, at the second ISP we didn't even have DHCP servers. We made everyone set up every device on their own!)

My current home broadband setup gives me the same IP address for months at a time, across router reboots. Advertisers love it, I'm sure.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#44
post #19

can someone explain why an account isn't a requirement to contribute to Wikipedia?

In practice, I believe the reason is historical: that's how Wikipedia started and it hasn't changed. But there's pretty compelling evidence that it provides Wikipedia some unique benefits relative to an account-locked alternative:

Hill, B. M. and Shaw, A. (2021) ‘The Hidden Costs of Requiring Accounts: Quasi-Experimental Evidence From Peer Production’, Communication Research, 48(6), pp. 771–795. doi: 10.1177/0093650220910345.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#45
post #27

Earlier quoted context omitted.

Because that seems to be what the people in charge actually want but are half-assing in the name of optics. IDGAF one way or the other, but if you're going to be banning millions of users from editing via their IP, just commit to saying "We need to be able to identify you vandals, and a user account is the easiest way". You're either true to a mission statement, or you should stop virtue signaling beliefs you don't h…

> Because that seems to be what the people in charge actually want but are half-assing in the name of optics. Most certainly not. The people in charge actually want it to be open. You are simply watching those ambitions splinter somewhat as they are beset by the crashing waves of the harsh reality that is the Internet.

This is a semantics debate, and a good faith read of each our comments seems to show agreement in our understanding of the situation. "Want" does a lot of lifting, and they want 2 contradictory things (no vandals, anyone can edit) and are prioritizing those wants.

I'm saying that by prioritizing the want of "no vandals" you are making want of "open to everyone" untenable. I'm sure their actual top priority is "the best, most accurate listing of information" and everything else is in service of that goal, but I don't really care.

My point stands: If you want anyone to be able to edit anywhere at any time, you can have that but you make trade-offs. Saying "vandals are bad and need to be stopped" is actually not an objective fact, it's a choice about what information you hold valuable.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#46
post #28

Earlier quoted context omitted.

The tragedy of the commons that happens when you can't establish the reputation of your visitors because regular users are indistinguishable from malicious actors when signals like IPs are intentionally obscured.

That's only because they're using weak authentication. If they required users to use something like WebAuthn, the bot problems would be significantly easier to deal with.

True, but that would significantly increase the barrier for contributions, especially at the long tail. As always, it's a trade-off, not a black-or-white situation.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#48
post #15

Earlier quoted context omitted.

"I cannot stress this enough, and I think it's important to frame this debate correctly when it comes to discussing these blocks. I have made somewhere around 1200 rangeblocks of webhosting providers in the last 5 weeks or so. Not one of them was targeted at a user." — [[User:Blablubbs]] in linked page Wikipedia doesn't block to punish individuals. It blocks to protect itself. There are plenty of ways around most blo…

AFAIK their policy is to block IPs that "obscure individual users". Another commenter quoted: > Communities typically block edits from IP addresses that obscure individual users. Surely they are aware that this is basically all IPs nowadays...? If that's genuinely the policy then it should be almost equivalent to just requiring an account for all edits, so why not just do that?

> AFAIK their policy is to block IPs that "obscure individual users". Another commenter quoted:

> > Communities typically block edits from IP addresses that obscure individual users.

> Surely they are aware that this is basically all IPs nowadays...?

> If that's genuinely the policy then it should be almost equivalent to just requiring an account for all edits, so why not just do that?

With the shortage of IPv4 addresses and the lack of progression to IPv6 from many ISPs, we're likely going to see users unable to anonymously edit if they start blocking those behind a CGNAT.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#49
post #28

Earlier quoted context omitted.

The tragedy of the commons that happens when you can't establish the reputation of your visitors because regular users are indistinguishable from malicious actors when signals like IPs are intentionally obscured.

That's only because they're using weak authentication. If they required users to use something like WebAuthn, the bot problems would be significantly easier to deal with.

How come? Last I checked there was a devtool to create virtual authenticators. Unless there’s a way for wikipedia to permit only certain vendors like Yubico, akin to browsers trusting certain CAs, I don’t see how one couldn’t make a bot register thousands of accounts with virtual authenticators.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#50

I'm finding it a bit hard to follow the structure of this document so forgive me if this is what's being discussed, but wouldn't it make the most sense to block Anonymous editing from Apple Private Relay IP ranges? Once signed in, there is again a way to track the editor, and a way to deal with bad actors.

I'm regularly blocked from editing because I'm on a VPN. I don't get it, as long as I'm logged in then what's the problem? I'd love to know.
Post reply on HN