Live data from Hacker News

Wikipedia was in read-only mode following mass admin account compromise

wikimediastatus.net

361–370 of 405 posts

Re: Wikipedia was in read-only mode following mass admin account compromise

#361
post #205

Earlier quoted context omitted.

Yes, you can have your own JS/CSS that’s injected in every page. This is pretty useful for widgets, editing tools, or to customize the website’s apparence.

It sounds very dangerous to me but who am I to judge.

It only affects your user; it’s just like adding random extensions to your browser.

Re: Wikipedia was in read-only mode following mass admin account compromise

#362
post #336

Earlier quoted context omitted.

Ok, fair point. I presumed that this crowd would be far more familiar with the capabilities of HTML5 and dynamic pages sans js than most. (Surely more familiar than I, who only dabble in code by comparison.) No, I'm not suggesting we all go back to purely-static web pages, imagemap gifs and server side navigation. But you're going to have a hard time convincing me that I really truly need to execute code of unknown p…

I think the Luddites were Technologists too, and that put them in the best position to understand the downsides of tech. Same goes for you.

Big thanks for the recognition. Going against the hype colossus makes one feel like a lone voice in the wilderness.

Re: Wikipedia was in read-only mode following mass admin account compromise

#364
post #336

Earlier quoted context omitted.

I think the Luddites were Technologists too, and that put them in the best position to understand the downsides of tech. Same goes for you.

Big thanks for the recognition. Going against the hype colossus makes one feel like a lone voice in the wilderness.

You're not alone, there are dozens of us left :)

Re: Wikipedia was in read-only mode following mass admin account compromise

#365
post #288

Earlier quoted context omitted.

In the average real world, the staff engineer learns nothing, regardless of whether they get to lose or keep their job. Some time down the line, they make other careless mistakes. Eventually they retire, having learned nothing. This is more common than you'd think.

I was able to run some stats at scale on this and people who make mistakes are more likely to make more mistakes, not less. Essentially sampling from a distribution of a propensity for mistakes and this dominated any sign of learning from mistakes. Someone who repeatedly makes mistakes is not repeatedly learning, they are accident prone.

Or they are working in a very badly designed system which consistently encourages them to make mistakes

Re: Wikipedia was in read-only mode following mass admin account compromise

#366
post #237

Earlier quoted context omitted.

Didn't realise this was some historic evil script and not some active attacker who could change tack at any moment. That makes the fix pretty easy. Write a regex to detect the evil script, and revert every page to a historic version without the script.

Letting ancient evil code run? Have we learned nothing from A Fire Upon the Deep ?!

Learning from fiction? Let's learn from the Dune then and start Butlerian jihad already.

Re: Wikipedia was in read-only mode following mass admin account compromise

#368
post #364

Earlier quoted context omitted.

Big thanks for the recognition. Going against the hype colossus makes one feel like a lone voice in the wilderness.

You're not alone, there are dozens of us left :)

Dozens of us!

Re: Wikipedia was in read-only mode following mass admin account compromise

#369
post #35

Earlier quoted context omitted.

I agree, but it's not a shoestring budget. They also seem to run a surplus every year: The Wikimedia Foundation (WMF) maintains a significant financial surplus and a growing, healthy balance sheet, with net assets reaching approximately $271.5 million in the 2023–2024 fiscal year. This surplus is largely driven by consistent, high-volume, small-dollar donations, with total annual revenue often exceeding $180 million.

Surplus is a good thing right? Long term stability, responsible financial management, healthy margins? If they said one year "You know what? We're good on donations this year." it would never be restarted.

Very prudent, but far from "operating on a shoestring".

Re: Wikipedia was in read-only mode following mass admin account compromise

#370

Earlier quoted context omitted.

It's nothing. For the global ones that need admin permissions to edit, it's no different from all the other code of mediawiki itself like the php. For the user scripts, it's no worse than the fact that you can run tampermonkey in your browser and have it modify every page from evry site in whatever way your want.

Well it has just been shown it's not nothing

No it hasn't.
Post reply on HN