Live data from Hacker News

Wikipedia was in read-only mode following mass admin account compromise

wikimediastatus.net

231–240 of 405 posts

Re: Wikipedia was in read-only mode following mass admin account compromise

#231
post #130

Earlier quoted context omitted.

If you're using wikipedia to "agree on common facts" I think you might have bigger problems...

Not the GP, and I don't believe in the existence of "common facts" in general, but Wikipedia is indeed a good place to figure out what other people might agree as common facts...

Well, I'm not sure either what the term "common facts" is supposed to mean, but wikipedia is not a good place to look for what "other people" think, unless if by "other people" you mean a small set of wikipedia powerusers. Just like traditional newspapers are controlled by a small set of editors who decide what's worth publishing, so is wikipedia.

https://en.wikipedia.org/wiki/Wikipedia:What_Wikipedia_is_no...

Re: Wikipedia was in read-only mode following mass admin account compromise

#232

Earlier quoted context omitted.

Could you point to where you found the details of the exploit? It’s not in the linked page. Really interested. Especially the part about modifying it and the other users propagating it?

The fact of this obvious LLM slop being at the top of this discussion is incredibly insidious . The "facts" it mentions are made up. Has this vapid style finally become so normalized that nobody is seeing it anymore?

The facts are not made up--check the incident reports.

Most claims of LLM authorship are erroneous.

Re: Wikipedia was in read-only mode following mass admin account compromise

#233

I completely understand marking the software that controls drinking water as critical infrastructure- but at some point a state based cyber attack that just wipes wikipedia off the net is deeply damaging to our modern society’s ability to agree on common facts … Just now thought “if Wikipedia vanished what would it mean … and it’s not on the level of safe drinking water, but it is a level.

> but at some point a state based cyber attack that just wipes wikipedia off the net is deeply damaging to our modern society’s ability to agree on common facts Haven't we hit that point already with bad faith (and potentially government-run) coordinated editing and voting campaigns, as both Wales and Sanger have been pointing out for a while now? See, for example, * Sanger: https://en.wikipedia.org/wiki/User:Larry_S…

> Haven't we hit that point already with bad faith (and potentially government-run) coordinated editing […] campaigns,

Yes, this is a real phenomenon. See, for instance, https://en.wikipedia.org/wiki/Timeline_of_Wikipedia%E2%80%93...: the examples from 2006 are funny, and the article's subject matter just gets sadder and sadder as the chronology goes on.

> and voting campaigns

I'm not sure what you mean by this. Wikipedia is not a democracy.

> as both Wales and Sanger have been pointing out

{{fv}}. Neither of those essays make this point. The closest either gets is Sanger's first thesis, which misunderstands the "support / oppose" mechanism. Ironically, his ninth thesis says to introduce voting, which would create the "voting campaign" vulnerability!

These are both really bad takes, which I struggle to believe are made in good faith, and I'm glad Wikipedians are mostly ignoring them. (I have not read the third link you provided, because Substack.)

Re: Wikipedia was in read-only mode following mass admin account compromise

#234
post #128

Earlier quoted context omitted.

The fact of this obvious LLM slop being at the top of this discussion is incredibly insidious . The "facts" it mentions are made up. Has this vapid style finally become so normalized that nobody is seeing it anymore?

I didn't even notice it until you pointed it out, but I checked that account's comment history and it uses em dashes. Also, "the database history itself is the active distribution vector" Is just semantic nonsense. I still have a basic assumption that if something I'm reading doesn't make much sense to me, I probably just don't understand it. Over the last few years I've had to get used to the new assumption that it'…

It's not semantic nonsense, it's the truth per the incident reports ... go read the links that have been added up top.

Re: Wikipedia was in read-only mode following mass admin account compromise

#235
post #172

This was only a matter of time. The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago... Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presenta…

Seems like a good time to donate one's resources to fix it. The internet is super hostile these days. If Wikipedia falls... well...

Wikipedia doesn't even spend donation of Wikipedia anymore.

Re: Wikipedia was in read-only mode following mass admin account compromise

#236

Earlier quoted context omitted.

The nuke might be legitimate?

That's not a lot of state lost. Destructive operations are easier to replay than constructive ones.

Is Wikimedia overreacting then?

Re: Wikipedia was in read-only mode following mass admin account compromise

#237
post #125

See the public phab ticket: https://phabricator.wikimedia.org/T419143 In short, a Wikimedia Foundation account was doing some sort of test which involved loading a large number of user scripts. They decided to just start loading random user scripts, instead of creating some just for this test. The user who ran this test is a Staff Security Engineer at WMF, and naturally they decided to do this test under their highly…

Didn't realise this was some historic evil script and not some active attacker who could change tack at any moment. That makes the fix pretty easy. Write a regex to detect the evil script, and revert every page to a historic version without the script.

Letting ancient evil code run? Have we learned nothing from A Fire Upon the Deep?!

Re: Wikipedia was in read-only mode following mass admin account compromise

#238
post #8
post #4

Woah this looks like an old school XSS worm https://meta.wikimedia.org/wiki/Special:RecentChanges?hidebo... I’ve always thought the fact that MediaWiki sometimes lets editors embed JavaScript could be dangerous.

Also, I’m also surprised an XSS attack like hasn’t yet been actually used to harvest credentials like passwords through browser autofill[0]. It seems like the worm code/the replicated code only really attacks stuff on site. But leaking credentials (and obviously people reuse passwords across sites) could be sooo much worse. [0] https://varun.ch/posts/autofill/

[flagged]

Re: Wikipedia was in read-only mode following mass admin account compromise

#239

[flagged]

> [...] is incredibly insidious. It really exposes the foundational danger of [...] My LLM sense is tingling.

I opened his post history and scrolled down a bit and literally the first thing I saw was a comment starting with "You're absolutely right" lol

Re: Wikipedia was in read-only mode following mass admin account compromise

#240
post #76

Earlier quoted context omitted.

Namecheap won’t sell it which is great because it made me pause and wonder whether it's legal for an American to send Russians money for a TLD.

Namecheap is Ukrainian, of course they won't sell you a .ru domain.

Is it? Wikipedia says:

> Namecheap is a U.S. based domain name registrar and web hosting service company headquartered in Phoenix, Arizona.

and in 2025 they were purchased by:

> CVC Capital Partners plc is a Jersey-based private equity and investment advisory firm

Post reply on HN