Live data from Hacker News

Wikipedia was in read-only mode following mass admin account compromise

wikimediastatus.net

201–210 of 405 posts

Re: Wikipedia was in read-only mode following mass admin account compromise

#201

Earlier quoted context omitted.

The problem isn't the granularity of the backup but since the worm silently nukes pages, it's virtually impossible to reconcile the state before the attack and the current state, so you have to just forfeit any changes made since then and ask the contributors to do the leg work of reapplying the correct changes

Why would nuked pages matter? Snapshots capture everything and are not part of wikimedia software.

The nuke might be legitimate?

Re: Wikipedia was in read-only mode following mass admin account compromise

#202
post #125

See the public phab ticket: https://phabricator.wikimedia.org/T419143 In short, a Wikimedia Foundation account was doing some sort of test which involved loading a large number of user scripts. They decided to just start loading random user scripts, instead of creating some just for this test. The user who ran this test is a Staff Security Engineer at WMF, and naturally they decided to do this test under their highly…

wait as a wikipedia user you can just put random JS to some settings and it will just... run? privileged?

this is both really cool and really really insane

Re: Wikipedia was in read-only mode following mass admin account compromise

#203

Earlier quoted context omitted.

I use it on the backends of my stuff. Works great, but, like any tool, usage matters. People who use tools badly, get bad results. I've always found the "Fishtank Graph" to be relevant: https://w3techs.com/technologies/history_overview/programmin...

People who use tools badly inflict bad results on other people, quite often far more so than they do so on themselves.

Yeah. It's funny how companies don't like to hire people that use tools correctly, but insist on creating tools that allow them to hire cheaper, less-qualified people.

PHP works fine, if you're a halfway decent programmer. Same with C++.

Re: Wikipedia was in read-only mode following mass admin account compromise

#205
post #125

See the public phab ticket: https://phabricator.wikimedia.org/T419143 In short, a Wikimedia Foundation account was doing some sort of test which involved loading a large number of user scripts. They decided to just start loading random user scripts, instead of creating some just for this test. The user who ran this test is a Staff Security Engineer at WMF, and naturally they decided to do this test under their highly…

wait as a wikipedia user you can just put random JS to some settings and it will just... run? privileged? this is both really cool and really really insane

Yes, you can have your own JS/CSS that’s injected in every page. This is pretty useful for widgets, editing tools, or to customize the website’s apparence.

Re: Wikipedia was in read-only mode following mass admin account compromise

#206
post #86

GOD am I thankful to my old self for disabling js by default. And sticking with it. edit: lol downvoted with no counterpoint, is it hitting a nerve?

> edit: lol downvoted with no counterpoint, is it hitting a nerve? I have upvoted ya fwiw and I don't understand it either why people would try to downvote ya. I mean, if websites work for you while disabling js and you are fine with it. Then I mean JS is an threat vector somewhat. Many of us are unable to live our lives without JS. I used to use librewolf and complete and total privacy started feeling a little too u…

What is uncomfortable about Librewolf? I thought it was basically FF without telemetry and UBO already baked in?

Re: Wikipedia was in read-only mode following mass admin account compromise

#207
post #125

See the public phab ticket: https://phabricator.wikimedia.org/T419143 In short, a Wikimedia Foundation account was doing some sort of test which involved loading a large number of user scripts. They decided to just start loading random user scripts, instead of creating some just for this test. The user who ran this test is a Staff Security Engineer at WMF, and naturally they decided to do this test under their highly…

wait as a wikipedia user you can just put random JS to some settings and it will just... run? privileged? this is both really cool and really really insane

It's a mediawiki feature: there's a set of pages that get treated as JS/CSS and shown for either all users or specifically you. You do need to be an admin to edit the ones that get shown to all users.

https://www.mediawiki.org/wiki/Manual:Interface/JavaScript

Re: Wikipedia was in read-only mode following mass admin account compromise

#208

Earlier quoted context omitted.

It means giving money to the Russian government, so no. If anyone from the Russian government is reading this, get the fuck out of Ukraine. Thank you.

[flagged]

I don't think voting with your wallet constitutes virtue signaling, especially at a time when end user boycotting is one of the universally known methods of protest.

Re: Wikipedia was in read-only mode following mass admin account compromise

#209
post #172

This was only a matter of time. The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago... Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presenta…

Seems like a good time to donate one's resources to fix it. The internet is super hostile these days. If Wikipedia falls... well...

It's a political issue. Editors are unwilling or unable to contribute to development of the features they need to edit.

Unfortunately, Wikipedia is run on insecure user scripts created by volunteers that tend to be under the age of 18.

There might be more editors trying to resume boost if editing Wikipedia under your real name didn't invite endless harassment.

Re: Wikipedia was in read-only mode following mass admin account compromise

#210
post #205

Earlier quoted context omitted.

wait as a wikipedia user you can just put random JS to some settings and it will just... run? privileged? this is both really cool and really really insane

Yes, you can have your own JS/CSS that’s injected in every page. This is pretty useful for widgets, editing tools, or to customize the website’s apparence.

It sounds very dangerous to me but who am I to judge.
Post reply on HN