Earlier quoted context omitted.
Yes, you can have your own JS/CSS that’s injected in every page. This is pretty useful for widgets, editing tools, or to customize the website’s apparence.
It sounds very dangerous to me but who am I to judge.
Wikipedia was in read-only mode following mass admin account compromise
361–370 of 405 posts
Re: Wikipedia was in read-only mode following mass admin account compromise
#362Earlier quoted context omitted.
Ok, fair point. I presumed that this crowd would be far more familiar with the capabilities of HTML5 and dynamic pages sans js than most. (Surely more familiar than I, who only dabble in code by comparison.) No, I'm not suggesting we all go back to purely-static web pages, imagemap gifs and server side navigation. But you're going to have a hard time convincing me that I really truly need to execute code of unknown p…
I think the Luddites were Technologists too, and that put them in the best position to understand the downsides of tech. Same goes for you.
Re: Wikipedia was in read-only mode following mass admin account compromise
#363[flagged]
https://stats.wikimedia.org/#/all-wikipedia-projects/reading...
Re: Wikipedia was in read-only mode following mass admin account compromise
#364Earlier quoted context omitted.
I think the Luddites were Technologists too, and that put them in the best position to understand the downsides of tech. Same goes for you.
Big thanks for the recognition. Going against the hype colossus makes one feel like a lone voice in the wilderness.
Re: Wikipedia was in read-only mode following mass admin account compromise
#365Earlier quoted context omitted.
In the average real world, the staff engineer learns nothing, regardless of whether they get to lose or keep their job. Some time down the line, they make other careless mistakes. Eventually they retire, having learned nothing. This is more common than you'd think.
I was able to run some stats at scale on this and people who make mistakes are more likely to make more mistakes, not less. Essentially sampling from a distribution of a propensity for mistakes and this dominated any sign of learning from mistakes. Someone who repeatedly makes mistakes is not repeatedly learning, they are accident prone.
Re: Wikipedia was in read-only mode following mass admin account compromise
#366Earlier quoted context omitted.
Didn't realise this was some historic evil script and not some active attacker who could change tack at any moment. That makes the fix pretty easy. Write a regex to detect the evil script, and revert every page to a historic version without the script.
Letting ancient evil code run? Have we learned nothing from A Fire Upon the Deep ?!
Re: Wikipedia was in read-only mode following mass admin account compromise
#367Re: Wikipedia was in read-only mode following mass admin account compromise
#368Re: Wikipedia was in read-only mode following mass admin account compromise
#369Earlier quoted context omitted.
I agree, but it's not a shoestring budget. They also seem to run a surplus every year: The Wikimedia Foundation (WMF) maintains a significant financial surplus and a growing, healthy balance sheet, with net assets reaching approximately $271.5 million in the 2023–2024 fiscal year. This surplus is largely driven by consistent, high-volume, small-dollar donations, with total annual revenue often exceeding $180 million.
Surplus is a good thing right? Long term stability, responsible financial management, healthy margins? If they said one year "You know what? We're good on donations this year." it would never be restarted.
Re: Wikipedia was in read-only mode following mass admin account compromise
#370Earlier quoted context omitted.
It's nothing. For the global ones that need admin permissions to edit, it's no different from all the other code of mediawiki itself like the php. For the user scripts, it's no worse than the fact that you can run tampermonkey in your browser and have it modify every page from evry site in whatever way your want.
Well it has just been shown it's not nothing