Live data from Hacker News

Wikipedia was in read-only mode following mass admin account compromise

wikimediastatus.net

211–220 of 405 posts

Re: Wikipedia was in read-only mode following mass admin account compromise

#212

This was only a matter of time. The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago... Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presenta…

> Based on the fact user scripts are globally disabled now I'm guessing this was a vector. Disabled at which level? Browsers still allow for user scripts via tools like TamperMonkey and GreaseMonkey, and that's not enforceable (and arguably, not even trivially visible ) to sites, including Wikipedia. As I say that out loud, I figure there's a separate ecosystem of Wikipedia-specific user scripts, but arguably the sam…

This is apparently not done browser side but server side.

As in, user can upload whatever they wish and it will be shown to them and ran, as JS, fully privileged and all.

Re: Wikipedia was in read-only mode following mass admin account compromise

#213

Earlier quoted context omitted.

> edit: lol downvoted with no counterpoint, is it hitting a nerve? I have upvoted ya fwiw and I don't understand it either why people would try to downvote ya. I mean, if websites work for you while disabling js and you are fine with it. Then I mean JS is an threat vector somewhat. Many of us are unable to live our lives without JS. I used to use librewolf and complete and total privacy started feeling a little too u…

What is uncomfortable about Librewolf? I thought it was basically FF without telemetry and UBO already baked in?

I appreciate librewolf but when I used to use it, IIRC its fingerprinting features were too strict for some websites IIRC and you definitely have to tone it down a bit by going into the settings. Canvases don't work and there were some other features too.

That being said, Once again, Librewolf is amazing software. I can see myself using it again but I just find zen easier in the sense of something which I can recommend plus ubO obv

Personally these are more aesthetic changes more than anything. I just really like how zen looks and feels.

The answer is sort of, Just personal preference that's all.

Re: Wikipedia was in read-only mode following mass admin account compromise

#214
post #57

Earlier quoted context omitted.

There is nothing to do, the incident was not caused by a vulnerability in mediawiki. Basically someone who had permissions to alter site js, accidentally added malicious js. The main solution is to be very careful about giving user accounts permission to edit js. [There are of course other hardening things that maybe should be done based on lessons learned]

Well, admins (or anybody other than the developers / deployment pipeline) having permissions to alter the JS sounds like a significant vulnerability. Maybe it wasn't in the early 2000s, but unencrypted HTTP was also normal then.

That's a fair point, but keep in mind normal admin is not sufficient. For local users (the account in question wasn't local) you need to be an "interface admin", of which there are only 15 on english wikipedia.

The account in question had "staff" rights which gave him basically all rights on all wikis.

Re: Wikipedia was in read-only mode following mass admin account compromise

#215

Earlier quoted context omitted.

[flagged]

I don't think voting with your wallet constitutes virtue signaling, especially at a time when end user boycotting is one of the universally known methods of protest.

I am a pragmatist so maybe I will never understand this line of thinking. But in my mind, there are no perfect options, including doing nothing.

By doing nothing, you are allowing a malicious actor to buy the domain. In fact I am sure they would love for everyone else to be paralyzed by purity tests for a $1 domain.

All things being equal, yeah don’t buy a .ru domain. But they are not equal.

Re: Wikipedia was in read-only mode following mass admin account compromise

#216

This was only a matter of time. The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago... Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presenta…

> Based on the fact user scripts are globally disabled now I'm guessing this was a vector. Disabled at which level? Browsers still allow for user scripts via tools like TamperMonkey and GreaseMonkey, and that's not enforceable (and arguably, not even trivially visible ) to sites, including Wikipedia. As I say that out loud, I figure there's a separate ecosystem of Wikipedia-specific user scripts, but arguably the sam…

The sitewide JavaScript/CSS is an editable Wiki page.

You can also upload scripts to be shared and executed by other users.

Re: Wikipedia was in read-only mode following mass admin account compromise

#217
post #76

Earlier quoted context omitted.

Yeah, basemetrika.ru is free now. Should we occupy it? ;)

Namecheap won’t sell it which is great because it made me pause and wonder whether it's legal for an American to send Russians money for a TLD.

Namecheap is Ukrainian, of course they won't sell you a .ru domain.

Re: Wikipedia was in read-only mode following mass admin account compromise

#218
post #205

Earlier quoted context omitted.

Yes, you can have your own JS/CSS that’s injected in every page. This is pretty useful for widgets, editing tools, or to customize the website’s apparence.

It sounds very dangerous to me but who am I to judge.

That is how Mediawiki works. Everything is a page, including CSS and JS. It is not really different than including JS in a webpage anywhere else.

Re: Wikipedia was in read-only mode following mass admin account compromise

#219

Earlier quoted context omitted.

Why would nuked pages matter? Snapshots capture everything and are not part of wikimedia software.

The nuke might be legitimate?

That's not a lot of state lost. Destructive operations are easier to replay than constructive ones.

Re: Wikipedia was in read-only mode following mass admin account compromise

#220

Earlier quoted context omitted.

[flagged]

Wikipedia admins are not IT admins, they're more like forum moderators or admins on a free phpBB 2 hosting service in 2005. They don't have "admin" access to backend systems. Those are the WMF sysadmins.

This is half true, because Wikipedia admins had the ability to edit sitewide JavaScript until 2018.

A certain number of "community" admins maintain that right to this day after it was realized this was a massive security hole.

Post reply on HN