Live data from Hacker News

Wikipedia was in read-only mode following mass admin account compromise

wikimediastatus.net

161–170 of 405 posts

Re: Wikipedia was in read-only mode following mass admin account compromise

#162
post #76

Earlier quoted context omitted.

Yeah, basemetrika.ru is free now. Should we occupy it? ;)

Namecheap won’t sell it which is great because it made me pause and wonder whether it's legal for an American to send Russians money for a TLD.

Pretty sure it is, however, the reverse is actually illegal (for US citizens to provide professional services to anyone residing in Russia) as of like 2022-ish

Re: Wikipedia was in read-only mode following mass admin account compromise

#163
post #37

Earlier quoted context omitted.

I'm half-tempted to try and claim it myself for fun and profit, but I think I'll leave it for someone else. What should we put there, anyway?

A JavaScript call to window.alert to pause the JavaScript VM.

Looks like someone other from the hackernews community has bought the domain https://news.ycombinator.com/item?id=47263323#47265499

Re: Wikipedia was in read-only mode following mass admin account compromise

#164

They have no incentive to improve the site, because they’re a for-profit entity. Despite the constant screeching for donations, the entire site is owned by a company with shareholders. All the “donations” go to them. They already met their funding needs for the next century a long time ago, this is all profit.

That's a serious accusation. Can you elaborate? What is the name of the company? Why does the Wikimedia Foundation claim ownership? And if you're referring to the Wikimedia Foundation, then what do you mean by "shareholders"?

Re: Wikipedia was in read-only mode following mass admin account compromise

#165
post #32
post #12

Earlier quoted context omitted.

Wikipedia probably actively wastes $100m per year

On what? I'd be curious to read more (documented sources)

Depends how you define waste if you agree. But you could cut $100m yearly and core Wikipedia would still run great.

https://en.wikipedia.org/wiki/User:Guy_Macon/Wikipedia_has_C...

Re: Wikipedia was in read-only mode following mass admin account compromise

#166

This was only a matter of time. The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago... Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presenta…

[flagged]

Wikipedia admins are not IT admins, they're more like forum moderators or admins on a free phpBB 2 hosting service in 2005. They don't have "admin" access to backend systems. Those are the WMF sysadmins.

Re: Wikipedia was in read-only mode following mass admin account compromise

#167
post #86

GOD am I thankful to my old self for disabling js by default. And sticking with it. edit: lol downvoted with no counterpoint, is it hitting a nerve?

> edit: lol downvoted with no counterpoint, is it hitting a nerve?

I have upvoted ya fwiw and I don't understand it either why people would try to downvote ya.

I mean, if websites work for you while disabling js and you are fine with it. Then I mean JS is an threat vector somewhat.

Many of us are unable to live our lives without JS. I used to use librewolf and complete and total privacy started feeling a little too uncomfortable

Now I am on zen-browser fwiw which I do think has some improvements over stock firefox in terms of privacy but I can't say this for sure but I mainly use zen because it looks really good and I just love zen.

Re: Wikipedia was in read-only mode following mass admin account compromise

#168
post #92

> Hitting MediaWiki:Common.js is the absolute nightmare scenario for MediaWiki deployments because that script gets executed by literally every single visitor ...except for us security wonks who have js turned off by default, don't enable it without good reason, disable it ASAP, and take a dim view of websites that require it. Not too many years ago this behavior was the domain of Luddites and schizophrenics. Today i…

It warms my heart that there's basically a 0% chance that they ever approach this camp's viewpoint based on the Herculean effort it took to switch over to a slightly more modern frontend a few years back. I'm glad you don't think of yourself of a Luddite, but I think you're vastly overstating how open people are to a purely-static web. Also, FWIW: Wikipedia is "specialsnowflake". If it isn't, that's merely because it…

Ok, fair point. I presumed that this crowd would be far more familiar with the capabilities of HTML5 and dynamic pages sans js than most. (Surely more familiar than I, who only dabble in code by comparison.)

No, I'm not suggesting we all go back to purely-static web pages, imagemap gifs and server side navigation. But you're going to have a hard time convincing me that I really truly need to execute code of unknown provenance in my this-app-does-everything-for-me process just to display a few pages of text and 5 jpegs.

And for the record, I've called myself a Technologist for almost 30 years now. If I were a closet Luddite I'd be one of the greatest hypocrites of human history. :-)

Re: Wikipedia was in read-only mode following mass admin account compromise

#170

I’m not saying that this is related to Wikipedia ditching archive.is but timing in combination with Russian messages is at least…weird.

The script was uploaded in 2024, and triggered today because of an accident

https://en.wikipedia.org/wiki/Wikipedia:Village_stocks#Scott...

Post reply on HN