Live data from Hacker News

Wikipedia was in read-only mode following mass admin account compromise

wikimediastatus.net

321–330 of 405 posts

Re: Wikipedia was in read-only mode following mass admin account compromise

#321
post #287

Earlier quoted context omitted.

That's a fair point, but keep in mind normal admin is not sufficient. For local users (the account in question wasn't local) you need to be an "interface admin", of which there are only 15 on english wikipedia. The account in question had "staff" rights which gave him basically all rights on all wikis.

> For local users (the account in question wasn't local) you need to be an "interface admin", of which there are only 15 on english wikipedia. It used to be all "admin" accounts, of which there were many more. Restricting it to "interface admin" only is a fairly recent change.

> Restricting it to "interface admin" only is a fairly recent change.

Its been 8 years!

Re: Wikipedia was in read-only mode following mass admin account compromise

#322
post #125

See the public phab ticket: https://phabricator.wikimedia.org/T419143 In short, a Wikimedia Foundation account was doing some sort of test which involved loading a large number of user scripts. They decided to just start loading random user scripts, instead of creating some just for this test. The user who ran this test is a Staff Security Engineer at WMF, and naturally they decided to do this test under their highly…

300 million dollar organization btw

aka tiny, relatively speaking, compared to similar sites with the same user base

Re: Wikipedia was in read-only mode following mass admin account compromise

#323

Earlier quoted context omitted.

If it was a native app it wouldn't be grabbing one of the hosted files and running it as code.

Have you never seen a native app's auto-update get hijacked by malware? It happened (yet again) last month [0] Tons of native apps also have plugins or addons, which (surprise surprise) is just code downloaded from some central repo, and run with way less sandboxing than JS. [0] https://www.bleepingcomputer.com/news/security/notepad-plus-...

That's pretty far from hosting the program in the same spot the content it manages is hosted, and also installing fresh versions instantly.

Re: Wikipedia was in read-only mode following mass admin account compromise

#324

[flagged]

People automatically assume knowledge comes from Wikipedia.

I got accused by someone of getting my information on a certain subject from Wikipedia. I told them it was the other way round: I had written most of the Wikipedia article myself in the first place.

Re: Wikipedia was in read-only mode following mass admin account compromise

#326
post #288

Earlier quoted context omitted.

It's either a a Career Limiting Event, or a Career Learning event. In the case of a Learning event, you keep your job, and take the time to make the environment more resilient to this kind of issue. In the case of a Limiting event, you lose your job, and get hired somewhere else for significantly better pay, and make the new environment more resilient to this kind of issue. Hopefully the Wikimedia foundation is the f…

In the average real world, the staff engineer learns nothing, regardless of whether they get to lose or keep their job. Some time down the line, they make other careless mistakes. Eventually they retire, having learned nothing. This is more common than you'd think.

I was able to run some stats at scale on this and people who make mistakes are more likely to make more mistakes, not less. Essentially sampling from a distribution of a propensity for mistakes and this dominated any sign of learning from mistakes. Someone who repeatedly makes mistakes is not repeatedly learning, they are accident prone.

Re: Wikipedia was in read-only mode following mass admin account compromise

#327
post #265
post #237

Earlier quoted context omitted.

Letting ancient evil code run? Have we learned nothing from A Fire Upon the Deep ?!

Link to the Prologue of Fire Upon the Deep : https://www.baen.com/Chapters/-0812515285/A_Fire_Upon_the_De... It's very short and from one of my favorite books. Increasingly relevant.

I swear, I respect Vinge more and more based on how well he seems to understand human tendencies to plot some plausible trajectories for our civilization.

Re: Wikipedia was in read-only mode following mass admin account compromise

#328
post #265

Earlier quoted context omitted.

Link to the Prologue of Fire Upon the Deep : https://www.baen.com/Chapters/-0812515285/A_Fire_Upon_the_De... It's very short and from one of my favorite books. Increasingly relevant.

I swear, I respect Vinge more and more based on how well he seems to understand human tendencies to plot some plausible trajectories for our civilization.

There's a little throwaway thing in the book (or maybe it was in the prequel) that I always liked, re understanding human tendencies. They're still using Unix time, starting in Jan 1st 1970, but given that their culture is so space-travel-focused they assume the early humans set it to coincide with man's first trip to the moon.

Re: Wikipedia was in read-only mode following mass admin account compromise

#329
post #288

Earlier quoted context omitted.

In the average real world, the staff engineer learns nothing, regardless of whether they get to lose or keep their job. Some time down the line, they make other careless mistakes. Eventually they retire, having learned nothing. This is more common than you'd think.

I was able to run some stats at scale on this and people who make mistakes are more likely to make more mistakes, not less. Essentially sampling from a distribution of a propensity for mistakes and this dominated any sign of learning from mistakes. Someone who repeatedly makes mistakes is not repeatedly learning, they are accident prone.

What if you define a hard rule from this statistics that « you must fire anyone on error one »? Won’t your company be empty in a rather short timeframe? [or will be composed only of doingNothing people?]

Re: Wikipedia was in read-only mode following mass admin account compromise

#330
post #329

Earlier quoted context omitted.

I was able to run some stats at scale on this and people who make mistakes are more likely to make more mistakes, not less. Essentially sampling from a distribution of a propensity for mistakes and this dominated any sign of learning from mistakes. Someone who repeatedly makes mistakes is not repeatedly learning, they are accident prone.

What if you define a hard rule from this statistics that « you must fire anyone on error one »? Won’t your company be empty in a rather short timeframe? [or will be composed only of doingNothing people?]

Why would you do that? You’re sampling from a distribution, a single sample only carries a small amount of information, repeat samples compound though.
Post reply on HN