Live data from Hacker News

Wikipedia was in read-only mode following mass admin account compromise

wikimediastatus.net

391–400 of 405 posts

Re: Wikipedia was in read-only mode following mass admin account compromise

#391

Earlier quoted context omitted.

Admin tasks are public in phabricator so it would be trivial to review chores and place malware in the chore's scope

Which only makes it that much more important to review everything you're running with a privileged account, right? And if it really is as trivial as you say it should be fixed ASAP.

I mean it's trivial for any attacker to discover admin tasks and know where to place malicious code for the admin tasks to execute it.

Re: Wikipedia was in read-only mode following mass admin account compromise

#392

Earlier quoted context omitted.

Can you elaborate? What scale? What kind of mistakes? This sounds quite interesting.

A decade of data from many hundreds of people, help desk type roll where all communication was kept, mostly chat logs and emails. Machine learning with manual validation. The goal was to put a dollar figure on mistakes made since the customers were much more likely to quit and never come back if it was our fault, but also many customers are nothing but a constant pain in the ass so it was important to distinguish who…

This sounds really interesting but possibly qualitatively different than programming/engineering where automated improvements/iterations are part of the job (and what's rewarded)

Re: Wikipedia was in read-only mode following mass admin account compromise

#393
post #125

See the public phab ticket: https://phabricator.wikimedia.org/T419143 In short, a Wikimedia Foundation account was doing some sort of test which involved loading a large number of user scripts. They decided to just start loading random user scripts, instead of creating some just for this test. The user who ran this test is a Staff Security Engineer at WMF, and naturally they decided to do this test under their highly…

>they decided to do this test under their

what language is this?

Re: Wikipedia was in read-only mode following mass admin account compromise

#394

Earlier quoted context omitted.

Aren’t staff part of engineering leadership?

At my job, I would just say they are in the ear of engineering leadership, but are not part of it.

That makes sense. I guess I usually think of developing policies for this kind of thing to be pretty much what staff would do. I don’t usually expect the CTO to make decisions about how to do testing. To the extent the engineering leadership are to blame, it’s that they were the ones who hired/retained this guy. The buck ultimately stops with them to be sure, but making these kinds of policies seems within the remit of a staff eng.

Re: Wikipedia was in read-only mode following mass admin account compromise

#395
post #265

Earlier quoted context omitted.

Link to the Prologue of Fire Upon the Deep : https://www.baen.com/Chapters/-0812515285/A_Fire_Upon_the_De... It's very short and from one of my favorite books. Increasingly relevant.

I swear, I respect Vinge more and more based on how well he seems to understand human tendencies to plot some plausible trajectories for our civilization.

I wish he could have seen the current state of GenAI. Several times in the book he talks about how the ship understands context clues and sarcasm, and that effective natural language translation requires near-sentience.

Re: Wikipedia was in read-only mode following mass admin account compromise

#396
post #237

Earlier quoted context omitted.

Letting ancient evil code run? Have we learned nothing from A Fire Upon the Deep ?!

\(^O^)/ zones of thought mentioned \(^O^)/

Do you remember the part where they built a machine in the Transcend that had to work at the Bottom of the Beyond?

The other day I was using Claude for a task, but it occurred to me, what if Claude is unreachable.

So, I told it to "encode your wisdom into this script in case you are not available"

That was my own version of that

Re: Wikipedia was in read-only mode following mass admin account compromise

#397

Earlier quoted context omitted.

[flagged]

Most admins on Wikipedia are competent in areas outside of webdev and security.

No, most admins are incompetent, full stop. I've been on the receiving end.

Re: Wikipedia was in read-only mode following mass admin account compromise

#398
post #76

Earlier quoted context omitted.

Namecheap won’t sell it which is great because it made me pause and wonder whether it's legal for an American to send Russians money for a TLD.

Pretty sure it is, however, the reverse is actually illegal (for US citizens to provide professional services to anyone residing in Russia) as of like 2022-ish

This is incorrect.

Re: Wikipedia was in read-only mode following mass admin account compromise

#399

Earlier quoted context omitted.

Pretty sure it is, however, the reverse is actually illegal (for US citizens to provide professional services to anyone residing in Russia) as of like 2022-ish

This is incorrect.

Only certain services?

Re: Wikipedia was in read-only mode following mass admin account compromise

#400

Earlier quoted context omitted.

This is a pretty egregious failure for a staff security engineer

As a staff, you don't even imagine what his salary is for screwing up like that. That being said, interesting to see how salaries skyrocketed over the years: https://meta.wikimedia.org/wiki/Wikimedia_Foundation_salarie... but not that much for engineering.

The highest non-severance number is $512,179 for the CEO in 2022. That's not particularly extreme. It's ~1/10 of what the Mozilla Foundation CEO makes.
Post reply on HN