I just checked a wiki, and the "MediaWiki:Common.js" page there was read-only, even for wikisysop users.
Wikipedia was in read-only mode following mass admin account compromise
211–220 of 405 posts
Re: Wikipedia was in read-only mode following mass admin account compromise
#212This was only a matter of time. The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago... Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presenta…
> Based on the fact user scripts are globally disabled now I'm guessing this was a vector. Disabled at which level? Browsers still allow for user scripts via tools like TamperMonkey and GreaseMonkey, and that's not enforceable (and arguably, not even trivially visible ) to sites, including Wikipedia. As I say that out loud, I figure there's a separate ecosystem of Wikipedia-specific user scripts, but arguably the sam…
As in, user can upload whatever they wish and it will be shown to them and ran, as JS, fully privileged and all.
Re: Wikipedia was in read-only mode following mass admin account compromise
#213Earlier quoted context omitted.
> edit: lol downvoted with no counterpoint, is it hitting a nerve? I have upvoted ya fwiw and I don't understand it either why people would try to downvote ya. I mean, if websites work for you while disabling js and you are fine with it. Then I mean JS is an threat vector somewhat. Many of us are unable to live our lives without JS. I used to use librewolf and complete and total privacy started feeling a little too u…
What is uncomfortable about Librewolf? I thought it was basically FF without telemetry and UBO already baked in?
That being said, Once again, Librewolf is amazing software. I can see myself using it again but I just find zen easier in the sense of something which I can recommend plus ubO obv
Personally these are more aesthetic changes more than anything. I just really like how zen looks and feels.
The answer is sort of, Just personal preference that's all.
Re: Wikipedia was in read-only mode following mass admin account compromise
#214Earlier quoted context omitted.
There is nothing to do, the incident was not caused by a vulnerability in mediawiki. Basically someone who had permissions to alter site js, accidentally added malicious js. The main solution is to be very careful about giving user accounts permission to edit js. [There are of course other hardening things that maybe should be done based on lessons learned]
Well, admins (or anybody other than the developers / deployment pipeline) having permissions to alter the JS sounds like a significant vulnerability. Maybe it wasn't in the early 2000s, but unencrypted HTTP was also normal then.
The account in question had "staff" rights which gave him basically all rights on all wikis.
Re: Wikipedia was in read-only mode following mass admin account compromise
#215Earlier quoted context omitted.
[flagged]
I don't think voting with your wallet constitutes virtue signaling, especially at a time when end user boycotting is one of the universally known methods of protest.
By doing nothing, you are allowing a malicious actor to buy the domain. In fact I am sure they would love for everyone else to be paralyzed by purity tests for a $1 domain.
All things being equal, yeah don’t buy a .ru domain. But they are not equal.
Re: Wikipedia was in read-only mode following mass admin account compromise
#216This was only a matter of time. The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago... Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presenta…
> Based on the fact user scripts are globally disabled now I'm guessing this was a vector. Disabled at which level? Browsers still allow for user scripts via tools like TamperMonkey and GreaseMonkey, and that's not enforceable (and arguably, not even trivially visible ) to sites, including Wikipedia. As I say that out loud, I figure there's a separate ecosystem of Wikipedia-specific user scripts, but arguably the sam…
You can also upload scripts to be shared and executed by other users.
Re: Wikipedia was in read-only mode following mass admin account compromise
#217Earlier quoted context omitted.
Yeah, basemetrika.ru is free now. Should we occupy it? ;)
Namecheap won’t sell it which is great because it made me pause and wonder whether it's legal for an American to send Russians money for a TLD.
Re: Wikipedia was in read-only mode following mass admin account compromise
#218Earlier quoted context omitted.
Yes, you can have your own JS/CSS that’s injected in every page. This is pretty useful for widgets, editing tools, or to customize the website’s apparence.
It sounds very dangerous to me but who am I to judge.
Re: Wikipedia was in read-only mode following mass admin account compromise
#219Re: Wikipedia was in read-only mode following mass admin account compromise
#220Earlier quoted context omitted.
[flagged]
Wikipedia admins are not IT admins, they're more like forum moderators or admins on a free phpBB 2 hosting service in 2005. They don't have "admin" access to backend systems. Those are the WMF sysadmins.
A certain number of "community" admins maintain that right to this day after it was realized this was a massive security hole.