Earlier quoted context omitted.
How does 2FA prevent this here?
If they required 2FA every time you wanted to modify JS then it couldn't propagate automatically. Just requiring 2FA when you first log in wouldn't help, of course.
Wikipedia was in read-only mode following mass admin account compromise
191–200 of 405 posts
Re: Wikipedia was in read-only mode following mass admin account compromise
#192Earlier quoted context omitted.
It means giving money to the Russian government, so no. If anyone from the Russian government is reading this, get the fuck out of Ukraine. Thank you.
[flagged]
> On 1 January 2025, Ukraine terminated all Russian gas transit through its territory, after the contract between Gazprom and Naftohaz signed in 2019 expired. [...] It is estimated that Russia will lose around €5bn a year as a result.
https://en.wikipedia.org/wiki/Russia%E2%80%93Ukraine_gas_dis...
Re: Wikipedia was in read-only mode following mass admin account compromise
#193Additional context: https://wikipediocracy.com/forum/viewtopic.php?f=8&t=14555 https://en.wikipedia.org/wiki/Wikipedia:Village_pump_(techni... https://old.reddit.com/r/wikipedia/comments/1rllcdg/megathre... Apparent JS worm payload: https://ru.wikipedia.org/w/index.php?title=%D0%A3%D1%87%D0%B...
Re: Wikipedia was in read-only mode following mass admin account compromise
#194I completely understand marking the software that controls drinking water as critical infrastructure- but at some point a state based cyber attack that just wipes wikipedia off the net is deeply damaging to our modern society’s ability to agree on common facts … Just now thought “if Wikipedia vanished what would it mean … and it’s not on the level of safe drinking water, but it is a level.
Re: Wikipedia was in read-only mode following mass admin account compromise
#195There's thousands of copies of the whole wikipedia in sql form though, IIRC it's just like 47GB.
And the entire English wikipedia with no images is, interestingly, also 43GiB.
Re: Wikipedia was in read-only mode following mass admin account compromise
#196This was only a matter of time. The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago... Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presenta…
> Based on the fact user scripts are globally disabled now I'm guessing this was a vector.
Disabled at which level?Browsers still allow for user scripts via tools like TamperMonkey and GreaseMonkey, and that's not enforceable (and arguably, not even trivially visible) to sites, including Wikipedia.
As I say that out loud, I figure there's a separate ecosystem of Wikipedia-specific user scripts, but arguably the same problem exists.
Re: Wikipedia was in read-only mode following mass admin account compromise
#197Additional context: https://wikipediocracy.com/forum/viewtopic.php?f=8&t=14555 https://en.wikipedia.org/wiki/Wikipedia:Village_pump_(techni... https://old.reddit.com/r/wikipedia/comments/1rllcdg/megathre... Apparent JS worm payload: https://ru.wikipedia.org/w/index.php?title=%D0%A3%D1%87%D0%B...
Re: Wikipedia was in read-only mode following mass admin account compromise
#198GOD am I thankful to my old self for disabling js by default. And sticking with it. edit: lol downvoted with no counterpoint, is it hitting a nerve?
> edit: lol downvoted with no counterpoint, is it hitting a nerve? I have upvoted ya fwiw and I don't understand it either why people would try to downvote ya. I mean, if websites work for you while disabling js and you are fine with it. Then I mean JS is an threat vector somewhat. Many of us are unable to live our lives without JS. I used to use librewolf and complete and total privacy started feeling a little too u…
It's also been torture, I definitely don't prescribe it. :P Like you say, it's a sanity / utility / security tradeoff. I just happen to be willing to trade off sanity for utility and security.
And yes, unfortunately I have to enable JS for some sites -- the default is to leave it disabled. And of course with cloudflare I have to whitelist it specifically for their domains (well, the non analytics domains). But thankfully wikipedia is light and spiffy without the javascript.
Re: Wikipedia was in read-only mode following mass admin account compromise
#199This was only a matter of time. The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago... Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presenta…
> Based on the fact user scripts are globally disabled now I'm guessing this was a vector. Disabled at which level? Browsers still allow for user scripts via tools like TamperMonkey and GreaseMonkey, and that's not enforceable (and arguably, not even trivially visible ) to sites, including Wikipedia. As I say that out loud, I figure there's a separate ecosystem of Wikipedia-specific user scripts, but arguably the sam…
Re: Wikipedia was in read-only mode following mass admin account compromise
#200Earlier quoted context omitted.
My understanding is that Wikipedia receives more donations than they need, surely they have the resources to fix it themselves?
You would first need to realzie it's a problem.