Live data from Hacker News

Wikipedia was in read-only mode following mass admin account compromise

wikimediastatus.net

41–50 of 405 posts

Re: Wikipedia was in read-only mode following mass admin account compromise

#41
This was only a matter of time.

The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago...

Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presentation (Mediaviewer).

But that's not all. Most "power users" and admins install "user scripts", which are unsandboxed JavaScript/CSS gadgets that can completely change the operation of the site. Those user scripts are often maintained by long abandoned user accounts with no 2 factor authentication.

Based on the fact user scripts are globally disabled now I'm guessing this was a vector.

The Wikimedia foundation knows this is a security nightmare. I've certainly complained about this when I was an editor.

But most editors that use the website are not professional developers and view attempts to lock down scripting as a power grab by the Wikimedia Foundation.

Re: Wikipedia was in read-only mode following mass admin account compromise

#42
post #13

Earlier quoted context omitted.

PHP is the language where "return flase" causes it to return true. https://danielc7.medium.com/remote-code-execution-gaining-do...

Also the language that runs half of the web. Also the language that has made me millions over my career with no degree. Also the language that allows people to be up and running in seconds (with or without AI). I could go on.

PHP is insanely great, and very fast. The hate has no clout.

Re: Wikipedia was in read-only mode following mass admin account compromise

#43
post #35

Earlier quoted context omitted.

What's the operating budget for other websites with comparable traffic? Without context $185 million seems like a lot , but compared to what? Reddit's operating budget for the same timeframe was $1.86 billion.

I agree, but it's not a shoestring budget. They also seem to run a surplus every year: The Wikimedia Foundation (WMF) maintains a significant financial surplus and a growing, healthy balance sheet, with net assets reaching approximately $271.5 million in the 2023–2024 fiscal year. This surplus is largely driven by consistent, high-volume, small-dollar donations, with total annual revenue often exceeding $180 million.

Surplus is a good thing right? Long term stability, responsible financial management, healthy margins? If they said one year "You know what? We're good on donations this year." it would never be restarted.

Re: Wikipedia was in read-only mode following mass admin account compromise

#45
post #37

Earlier quoted context omitted.

Yeah, basemetrika.ru is free now. Should we occupy it? ;)

I'm half-tempted to try and claim it myself for fun and profit, but I think I'll leave it for someone else. What should we put there, anyway?

I'd log requests and echo them back in the page

Re: Wikipedia was in read-only mode following mass admin account compromise

#46
post #17

Earlier quoted context omitted.

Also the language that runs half of the web. Also the language that has made me millions over my career with no degree. Also the language that allows people to be up and running in seconds (with or without AI). I could go on.

PHP is a fine language. It started my career. That said, it has a lot of baggage that can let you shoot yourself in the foot. Modern PHP is pretty awesome though.

Pretty sure we've seen people coding in essentially every other programming language also shoot themselves in the foot.

Re: Wikipedia was in read-only mode following mass admin account compromise

#47
post #30

In the early 2010’s I worked for a company whose primary income was subscriptions to site protection services - one of which included cleaning up malware-infected Wordpress installations. I worked on the team that did this job. This exact type of database-stored executable javascript was one of the most annoying types of infections to clean up.

Ok, so there are tons of mediawiki installations all over the internet. What do these operators do? Set their wikis to read-only mode, hang tight, and wait for a security patch?

Also, does this worm have a name?

Re: Wikipedia was in read-only mode following mass admin account compromise

#49
post #37

Earlier quoted context omitted.

Yeah, basemetrika.ru is free now. Should we occupy it? ;)

I'm half-tempted to try and claim it myself for fun and profit, but I think I'll leave it for someone else. What should we put there, anyway?

Go old school and have the script inject the "how did this get here im not good with computers" cat onto random pages
Post reply on HN