Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

301–310 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#301

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

> I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

Not only that. They do all this with amazing openness. Their records of incidents and deployments, who's in charge of what, rotation schedules are all public and shared in MediaWiki (although they're not that well organized). I can trace this back to circa 2005. Maybe this could be the largest knowledge base of devops that is public.

cf. https://wikitech.wikimedia.org/wiki/Category:Incident_docume... https://wikitech.wikimedia.org/wiki/Deployments/Archive/2019...

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#302
post #270

Earlier quoted context omitted.

There are multiple instances of them announcing them and implying they are follow-ups of previous discussions on 8chan. These include the Christchurch shootings, the Poway synagogue shooting and the El Paso Walmart shootin. The Christchurch shooter shared his Facebook stream to 8chan before the shooting started, and it was spread from there. The Poway shooter blamed/thanked 8chan for his views.

So FB's internet peers should depeer Facebook then in their routers, since the original material (the stream) was on FB? Or you prefer your justice selective?

I'm sure you already realize this, but to make it clear: FB has enormous utility for billions of people outside that and that is worth defending.

You are expanding a lot of effort defending 8chan here. Perhaps consider that it might not be worth defending.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#303
post #302

Earlier quoted context omitted.

So FB's internet peers should depeer Facebook then in their routers, since the original material (the stream) was on FB? Or you prefer your justice selective?

I'm sure you already realize this, but to make it clear: FB has enormous utility for billions of people outside that and that is worth defending. You are expanding a lot of effort defending 8chan here. Perhaps consider that it might not be worth defending.

8ch had a lot of very interesting and non-violent stuff. Have you been reading it regularly? I did.

I lived in a socialist country and you did not. Perhaps consider that you might not know where these current trends are pointing to.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#304
post #302

Earlier quoted context omitted.

I'm sure you already realize this, but to make it clear: FB has enormous utility for billions of people outside that and that is worth defending. You are expanding a lot of effort defending 8chan here. Perhaps consider that it might not be worth defending.

8ch had a lot of very interesting and non-violent stuff. Have you been reading it regularly? I did. I lived in a socialist country and you did not. Perhaps consider that you might not know where these current trends are pointing to.

[flagged]

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#305
post #304

Earlier quoted context omitted.

8ch had a lot of very interesting and non-violent stuff. Have you been reading it regularly? I did. I lived in a socialist country and you did not. Perhaps consider that you might not know where these current trends are pointing to.

[flagged]

you're not really engaging with his point. Effectively banning 8chan by removing network protection does not just restrict extremists; it restricts anyone who used that forum.

Ultimately, such matters should be prosecuted by courts. It is inappropriate for organisations like cloudflare to leverage their position within essential network infrastructure to start editorialising what passes through their network.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#306
post #271
post #19

Earlier quoted context omitted.

Extraordinary claims require extraordinary evidence, so by that symmetry this shouldn’t require much evidence.

if something is repeated a lot, it doesn't make it true. Though it does make it more believable to common folk according to Goebbels https://www.azquotes.com/author/5626-Joseph_Goebbels

Also, Napoleon. Repetition is really effective.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#307
post #271
post #19

Earlier quoted context omitted.

Extraordinary claims require extraordinary evidence, so by that symmetry this shouldn’t require much evidence.

if something is repeated a lot, it doesn't make it true. Though it does make it more believable to common folk according to Goebbels https://www.azquotes.com/author/5626-Joseph_Goebbels

Russian fake news is widespread and easy to find. How can this be controversial, and even downvoted on HN of all places? Russian military shot down a plane full of politicians over Ukraine, and boldly lied about it in the international press. This is just one of literally hundreds of such instances. Russia has been caught numerous times trying to sway elections across the world. How on earth is “Russia whitewashes its name on wikipedia” needing substantiation? It seems obvious, even.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#308
post #195
post #142

Earlier quoted context omitted.

The question is whether you feel good enough about that probability to be held liable if the malicious code was hidden good enough. Also, some cases might be obvious on Windows PCs, but I don't think that's necessarily the case with phones. Take note that websites can also send malicious packets. When you load a webpage, the code is downloaded and immediately executed. Are you OK with being held liable for visiting a…

I feel like you try very hard to establish a strawman. No one expects 100% perfection. Establishing and following industry standards is a good first step. Like no unencrypted local passwords. Individual default passwords for every individual device. Not using outdated version, especially once vulnerabilities are known. Including an update mechanism and providing updates for at least X years. And yes, trained speciali…

> I feel like you try very hard to establish a strawman.

This is the second time someone's told me that. Looking into what a strawman is again and reviewing my comments, I'm not sure I'm doing that. The examples I see on Wikipedia[1], at least, don't seem to have a strong relationship of implication. That is, the strawmen aren't directly implied from the proposals.

In this case, I do think that making one liable for damages their machine is causing to other people's machines does directly mean what I said, that one would be liable for behavior they cannot control as well as they can control the behavior of their car.

My intentions are to provide not strawmen, but counterexamples where the proposal fails.

> No one expects 100% perfection.

I do. I'm not really OK with laws where I don't have reasonable control of whether I break them or not. In this case, the only effective control I'd have is to not have an internet device, and that seems unreasonable.

I think we'd all like to think otherwise, but the traffic sent by our phones is very much out of our control because of the reasons I stated, and nobody reviews the javascript code received from an HTTP server before executing it. It seems crazy to be liable for whatever it does.

> And by the way, no one expects your car mechanic to [a] be perfect (you really never heard a story of a car breaking again just after leaving the shop?) or [b] be able to handle any kind of vehicle unknown to him.

I think the analogy isn't that strong. Visiting webpages is like changing car parts every second as the car is running. Malicious behavior of these car parts is not noticeable at all and they're not easy to spot from inspection either.

> The goal of rules like that is to punish the worst tier, thereby raising the bar. But this will probably be more hard to implement in the US with their everyone-sues-everyone mindset. Reminds me a lot of the great GDPR scare but now imo quite reasonable actual cases happening.

Well, there was a lot of things that scared people of GDPR, but I think I can assume your point is that a law can be broad and technically applicable to many people unfairly, but only applied to just cases in practice. I'm not sure I like that kind of law, though. Even if it works well in practice for the majority of cases, it seems like the kind of thing that lends itself well to abuse, the kind of law that everybody is guilty for, even if they're not all actively prosecuted.

[1] https://en.wikipedia.org/wiki/Straw_man#Examples

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#309
post #304

Earlier quoted context omitted.

[flagged]

you're not really engaging with his point. Effectively banning 8chan by removing network protection does not just restrict extremists; it restricts anyone who used that forum. Ultimately, such matters should be prosecuted by courts. It is inappropriate for organisations like cloudflare to leverage their position within essential network infrastructure to start editorialising what passes through their network.

It is inappropriate for organisations like cloudflare to leverage their position within essential network infrastructure to start editorialising what passes through their network.

No, I think it's entirely appropriate.

"Don't troll" and methods for dealing with trolls has been a thing all sites have done since the internet was invented. I don't see any difference here at all.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#310
post #275

Earlier quoted context omitted.

> no Matthew Prince selectively and benevolently enforcing CF neutrality. Is this a slippery slope argument. Because there is a world in difference from discontinuing a few extremists customers, to discontinuing service for something akin to Wikipedia. I'm not sure every slight compromise of principals is a slippery slope. It seems to me that CF generally aims at being neutral.

The argument made here is there is a chance (however minute) that the same can happen to something like Wikipedia because of some misplaced sense of morality, like say - we don't agree with wikipedia edits and editing process which we see if offending certain sections of X population. It does not matter how right their reason is. The fact that providers like cloud flare are in such position to take a moral high stanc…

I don't disagree, but has it ever been any different?
Post reply on HN