Live data from Hacker News

Wikipedia was in read-only mode following mass admin account compromise

wikimediastatus.net

191–200 of 405 posts

Re: Wikipedia was in read-only mode following mass admin account compromise

#191

Earlier quoted context omitted.

How does 2FA prevent this here?

If they required 2FA every time you wanted to modify JS then it couldn't propagate automatically. Just requiring 2FA when you first log in wouldn't help, of course.

2FAs also may require a level of KYC that Wikipedia isn't after and advocating for 2FA might indirectly advocate for a lot more things than just 2FA.

Re: Wikipedia was in read-only mode following mass admin account compromise

#192

Earlier quoted context omitted.

It means giving money to the Russian government, so no. If anyone from the Russian government is reading this, get the fuck out of Ukraine. Thank you.

[flagged]

If anyone is genuinely curious about this, they were indeed letting Russian gas through and stopped in 2025:

> On 1 January 2025, Ukraine terminated all Russian gas transit through its territory, after the contract between Gazprom and Naftohaz signed in 2019 expired. [...] It is estimated that Russia will lose around €5bn a year as a result.

https://en.wikipedia.org/wiki/Russia%E2%80%93Ukraine_gas_dis...

Re: Wikipedia was in read-only mode following mass admin account compromise

#193

Additional context: https://wikipediocracy.com/forum/viewtopic.php?f=8&t=14555 https://en.wikipedia.org/wiki/Wikipedia:Village_pump_(techni... https://old.reddit.com/r/wikipedia/comments/1rllcdg/megathre... Apparent JS worm payload: https://ru.wikipedia.org/w/index.php?title=%D0%A3%D1%87%D0%B...

Thanks - we've added the first 3 links to the toptext. Not sure about the 4th.

Re: Wikipedia was in read-only mode following mass admin account compromise

#194

I completely understand marking the software that controls drinking water as critical infrastructure- but at some point a state based cyber attack that just wipes wikipedia off the net is deeply damaging to our modern society’s ability to agree on common facts … Just now thought “if Wikipedia vanished what would it mean … and it’s not on the level of safe drinking water, but it is a level.

Don't worry, I personally have an offline backup of the English on my phone.

Re: Wikipedia was in read-only mode following mass admin account compromise

#195

There's thousands of copies of the whole wikipedia in sql form though, IIRC it's just like 47GB.

Correct. Not sure about a sql archive, but the kiwix ZIM archive of the top 1M English articles including (downsized but not minimized) images is 43GiB: https://download.kiwix.org/zim/wikipedia/

And the entire English wikipedia with no images is, interestingly, also 43GiB.

Re: Wikipedia was in read-only mode following mass admin account compromise

#196

This was only a matter of time. The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago... Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presenta…

    > Based on the fact user scripts are globally disabled now I'm guessing this was a vector.
Disabled at which level?

Browsers still allow for user scripts via tools like TamperMonkey and GreaseMonkey, and that's not enforceable (and arguably, not even trivially visible) to sites, including Wikipedia.

As I say that out loud, I figure there's a separate ecosystem of Wikipedia-specific user scripts, but arguably the same problem exists.

Re: Wikipedia was in read-only mode following mass admin account compromise

#197

Additional context: https://wikipediocracy.com/forum/viewtopic.php?f=8&t=14555 https://en.wikipedia.org/wiki/Wikipedia:Village_pump_(techni... https://old.reddit.com/r/wikipedia/comments/1rllcdg/megathre... Apparent JS worm payload: https://ru.wikipedia.org/w/index.php?title=%D0%A3%D1%87%D0%B...

Check https://web.archive.org/web/20260305155250/https://ru.wikipe... for the payload (safe to view)

Re: Wikipedia was in read-only mode following mass admin account compromise

#198
post #86

GOD am I thankful to my old self for disabling js by default. And sticking with it. edit: lol downvoted with no counterpoint, is it hitting a nerve?

> edit: lol downvoted with no counterpoint, is it hitting a nerve? I have upvoted ya fwiw and I don't understand it either why people would try to downvote ya. I mean, if websites work for you while disabling js and you are fine with it. Then I mean JS is an threat vector somewhat. Many of us are unable to live our lives without JS. I used to use librewolf and complete and total privacy started feeling a little too u…

> I mean, if websites work for you while disabling js and you are fine with it. Then I mean JS is an threat vector somewhat

It's also been torture, I definitely don't prescribe it. :P Like you say, it's a sanity / utility / security tradeoff. I just happen to be willing to trade off sanity for utility and security.

And yes, unfortunately I have to enable JS for some sites -- the default is to leave it disabled. And of course with cloudflare I have to whitelist it specifically for their domains (well, the non analytics domains). But thankfully wikipedia is light and spiffy without the javascript.

Re: Wikipedia was in read-only mode following mass admin account compromise

#199

This was only a matter of time. The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago... Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presenta…

> Based on the fact user scripts are globally disabled now I'm guessing this was a vector. Disabled at which level? Browsers still allow for user scripts via tools like TamperMonkey and GreaseMonkey, and that's not enforceable (and arguably, not even trivially visible ) to sites, including Wikipedia. As I say that out loud, I figure there's a separate ecosystem of Wikipedia-specific user scripts, but arguably the sam…

Yeah, wikipedia has its own user script system, and that was what was disabled.

Re: Wikipedia was in read-only mode following mass admin account compromise

#200

Earlier quoted context omitted.

My understanding is that Wikipedia receives more donations than they need, surely they have the resources to fix it themselves?

You would first need to realzie it's a problem.

Maybe this is the reason for this worm. Someone is angry because they don't got it in another way...
Post reply on HN