Live data from Hacker News

Wikipedia was in read-only mode following mass admin account compromise

wikimediastatus.net

121–130 of 405 posts

Re: Wikipedia was in read-only mode following mass admin account compromise

#122

Earlier quoted context omitted.

Yeah, basemetrika.ru is free now. Should we occupy it? ;)

It means giving money to the Russian government, so no. If anyone from the Russian government is reading this, get the fuck out of Ukraine. Thank you.

Well done, it's finally over

Re: Wikipedia was in read-only mode following mass admin account compromise

#123

Earlier quoted context omitted.

Could you point to where you found the details of the exploit? It’s not in the linked page. Really interested. Especially the part about modifying it and the other users propagating it?

The fact of this obvious LLM slop being at the top of this discussion is incredibly insidious . The "facts" it mentions are made up. Has this vapid style finally become so normalized that nobody is seeing it anymore?

Perhaps we're at last watching the internet die.

Re: Wikipedia was in read-only mode following mass admin account compromise

#124
post #113

We should be using federated organizational architectures when appropriate. For Wikipedia, consider a central read-only aggregated mirror that delegates the editorial function to specialized communities. Common, suggested tooling (software and processes) could be maintained centrally but each community might be improved with more independence. This separation of concerns may be a better fit for knowledge collection a…

Exactly. Wikipedia should be used on ipfs

Re: Wikipedia was in read-only mode following mass admin account compromise

#125
See the public phab ticket: https://phabricator.wikimedia.org/T419143

In short, a Wikimedia Foundation account was doing some sort of test which involved loading a large number of user scripts. They decided to just start loading random user scripts, instead of creating some just for this test.

The user who ran this test is a Staff Security Engineer at WMF, and naturally they decided to do this test under their highly-privileged Wikimedia Foundation staff account, which has permissions to edit the global CSS and JS that runs on every page.

One of those random scripts was a 2 year old malicious script from ruwiki. This script injects itself in the global Javascript on every page, and then in the userscripts of any user that runs into it, so it started spreading and doing damage really fast. This triggered tons of alerts, until the decision was made to turn the Wiki read-only.

Re: Wikipedia was in read-only mode following mass admin account compromise

#126

Earlier quoted context omitted.

Nah, you can snapshot every 15 minutes. The snapshot interval depends on the frequency of changes and their capacity, but it's up to them how to allocate these capacities... but it's definitely doable and there are real reasons for doing so. You can collapse deltas between snapshots after some time to make them last longer. I'd be surprised if they don't do that. As an aside, snapshotting would have prevented a good…

Nowadays I refuse to do any serious work that isn't in source control anywhere besides my NAS that takes copy-on-write snapshots every 15 minutes. It has saved my butt more times than I can count.

Yeah same here. Earlier I had a sync error that corrupted my .git, somehow. no problem; I go back 15 minutes and copy the working version.

Feels good to pat oneself in the back. Mine is sore, though. My E&O/cyber insurance likes me.

Re: Wikipedia was in read-only mode following mass admin account compromise

#127

Earlier quoted context omitted.

Could you point to where you found the details of the exploit? It’s not in the linked page. Really interested. Especially the part about modifying it and the other users propagating it?

The fact of this obvious LLM slop being at the top of this discussion is incredibly insidious . The "facts" it mentions are made up. Has this vapid style finally become so normalized that nobody is seeing it anymore?

That user, epicprogrammer's comment history suggests alignment with the Musk/Thiel/Anduril/DoW/anti-Anthropic crowd who are incessantly trying to damage Wikipedia's reputation to push a "Grokipedia" where they can define the narrative.

I wouldn't be surprised if that group were the origin of this attack too.

Re: Wikipedia was in read-only mode following mass admin account compromise

#128

Earlier quoted context omitted.

Could you point to where you found the details of the exploit? It’s not in the linked page. Really interested. Especially the part about modifying it and the other users propagating it?

The fact of this obvious LLM slop being at the top of this discussion is incredibly insidious . The "facts" it mentions are made up. Has this vapid style finally become so normalized that nobody is seeing it anymore?

I didn't even notice it until you pointed it out, but I checked that account's comment history and it uses em dashes. Also, "the database history itself is the active distribution vector" Is just semantic nonsense.

I still have a basic assumption that if something I'm reading doesn't make much sense to me, I probably just don't understand it. Over the last few years I've had to get used to the new assumption that it's because I'm reading LLM output.

Re: Wikipedia was in read-only mode following mass admin account compromise

#129

Earlier quoted context omitted.

Yeah, basemetrika.ru is free now. Should we occupy it? ;)

It means giving money to the Russian government, so no. If anyone from the Russian government is reading this, get the fuck out of Ukraine. Thank you.

[flagged]

Re: Wikipedia was in read-only mode following mass admin account compromise

#130

I completely understand marking the software that controls drinking water as critical infrastructure- but at some point a state based cyber attack that just wipes wikipedia off the net is deeply damaging to our modern society’s ability to agree on common facts … Just now thought “if Wikipedia vanished what would it mean … and it’s not on the level of safe drinking water, but it is a level.

If you're using wikipedia to "agree on common facts" I think you might have bigger problems...

Not the GP, and I don't believe in the existence of "common facts" in general, but Wikipedia is indeed a good place to figure out what other people might agree as common facts...
Post reply on HN