Live data from Hacker News

Wikipedia globally blocks Apple Private Relay IP ranges from editing

meta.wikimedia.org

51–60 of 98 posts

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#51

Earlier quoted context omitted.

> Surely they are aware that this is basically all IPs nowadays...? There are indeed many classes of IP address which multiplex large numbers of users (mobile network exits, VPN exits, ISPs with CGNAT, some corporate web filtering systems, shared public wifi, tor, satellite ground station exits, residential proxies, ...). However, claiming that "basically all" IPs are multiplexed is definitely wrong. A home or small…

Is that true? I've worked at two ISPs and we never made an effort to make the IPs ephemeral. (OK, at the second ISP we didn't even have DHCP servers. We made everyone set up every device on their own!) My current home broadband setup gives me the same IP address for months at a time, across router reboots. Advertisers love it, I'm sure.

That's a great point and very fairly made. For my own ISP (BT in the UK), I get a new IP on each router reboot. I understand that for some others like Virgin, the IP is very stable over long periods.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#52
post #3

Quoted post unavailable.

Between this and the T-Mobile IP ban, why not just say "Only registered users can edit pages" and be done with it? When you're blocking millions from unregistered editing, just go full tilt.

Because blocking millions out of billions can still be a reasonable tradeoff, if majority of abuse comes from those millions.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#53

I'm finding it a bit hard to follow the structure of this document so forgive me if this is what's being discussed, but wouldn't it make the most sense to block Anonymous editing from Apple Private Relay IP ranges? Once signed in, there is again a way to track the editor, and a way to deal with bad actors.

I'm regularly blocked from editing because I'm on a VPN. I don't get it, as long as I'm logged in then what's the problem? I'd love to know.

That doesn't work because Wikipedia doesn't store your IP forever if you have an account. If they allowed what you described, then you could make a bunch of accounts with your real IP, wait 90 days for the IP you made it from to be forgotten, then vandalize with them all over VPNs, and they couldn't do anything about it other than reactively blocking each account individually.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#54

Earlier quoted context omitted.

> Because that seems to be what the people in charge actually want but are half-assing in the name of optics. Most certainly not. The people in charge actually want it to be open. You are simply watching those ambitions splinter somewhat as they are beset by the crashing waves of the harsh reality that is the Internet.

"Want it to be open" but ban mobile network IP addresses, which basically guarantees people below a certain socioeconomic status can't contribute. Loads of people don't have a desktop/laptop, or even internet service at home - just cell service.

They can thank abusers for that.

But note that requiring authentication to edit doesn’t necessarily change anything about abuse, yet this thread seems to suggest that people think it does.

Just means you need to farm a POST /register. You can attach a one time use account to every abusive edit and it’s no big deal.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#55
post #40

Earlier quoted context omitted.

The reasoning here just seems perverse. WP wants to allow contributions by anonymous users, which seems noble. But it also realizes that it needs to be able to block some people from anonymous contribution "to protect itself". The implementation of the blocking mechanism is IP addresses/ranges, which is imprecise (to say the least). But now you have to worry about abusive users bypassing your technical control by obs…

Not blocking anything is infeasible due to abuse, requiring registration is effectively blocking anonymous editing access for everyone. If you want anonymous editing, providing it to some is strictly better than providing it to none. Your argument is as flawed as saying we shouldn't have email because spammers must be blocked.

Actually: if your premise is that you're an open access facility, then having arbitrary treatment of different users is a really excellent way of undermining that premise.

For example, as was pointed out elsewhere on this discussion, having blocking controls that tend to create a higher bar for people without home internet access means you're discriminating against groups that can only afford a personal mobile device, or only have internet access at a library, or come from a particular national origin, etc.

If you care about anonymous editing, creating underclasses that cannot have it seems an unlikely way to further your mission. It's effectively a form of red-lining.

I don't understand what your email analogy is getting at, so I'm going to leave that alone.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#56
post #26

Stupid and disappointing. Wikipedia and others should move decisively away from using IP addresses as any form of unique ID and address the actual problem in a way that still preserves the option for useful pseudonymity and participation. The basic issue with moderation is the balance between the time/resource cost of moderation and the time/resource cost of evading it times the quantity of bad actor interest. Like i…

>It's not possible to build back up another token before the ban expires.

I think you fail to realize how slow low end devices that can use wikipedia is compared to the latest high performance processors.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#57
post #40

Earlier quoted context omitted.

The reasoning here just seems perverse. WP wants to allow contributions by anonymous users, which seems noble. But it also realizes that it needs to be able to block some people from anonymous contribution "to protect itself". The implementation of the blocking mechanism is IP addresses/ranges, which is imprecise (to say the least). But now you have to worry about abusive users bypassing your technical control by obs…

Not blocking anything is infeasible due to abuse, requiring registration is effectively blocking anonymous editing access for everyone. If you want anonymous editing, providing it to some is strictly better than providing it to none. Your argument is as flawed as saying we shouldn't have email because spammers must be blocked.

>>If you want anonymous editing, providing it to some is strictly better than providing it to none.

Objectively: Not always. You're creating a tiered society. The argument is saying "Why do some people deserve freedom but not others?" It's great if you're part of the in-group, but exceedingly unjust if you're non-vandal bycatch due to the blanket bans. You can't have some democracy, it's all or none.

I'm unable to anonymously edit by default because I have T-mobile for my phone and internet services and there is a blanket ban on T-mobile IPs. This is the 3rd largest telcom in the US with about 108 million users. I'm going to assume that less than 1/10th of them are Wikipedia vandals, but a blanket ban has been put in place.

Explain how it's "good" that a random AT&T user can make an edit, but I (or another random T-mobile user) can't? Follow up, explain why making everyone who wants to edit register an account is a net bad if it's the only choice for millions of people?

*edited for typos

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#58

Is the premise over at Wikipedia still that an IP address meaningfully identifies a single editor? I think that ship sailed.

> an IP address meaningfully identifies a single editor

I'm fairly certain that the GDPR believes an IP address is PII and imposes a bunch of fairly onerous restrictions on how network administrators are able to log and analyze them. So it doesn't seem like that ship has sailed at all. If anything it's been reinforced by actual law that it _does_ meaningfully identify someone.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#59

Earlier quoted context omitted.

I'm regularly blocked from editing because I'm on a VPN. I don't get it, as long as I'm logged in then what's the problem? I'd love to know.

That doesn't work because Wikipedia doesn't store your IP forever if you have an account. If they allowed what you described, then you could make a bunch of accounts with your real IP, wait 90 days for the IP you made it from to be forgotten, then vandalize with them all over VPNs, and they couldn't do anything about it other than reactively blocking each account individually.

Then grade accounts by more than one metric. I've my account for years and made plenty of edits but it's treated like some newbie account that may be a bot? Because I value my privacy?

I use Britannica for anything that isn't celebrity/pop culture based now, I thought Wikipedia had killed off "proper" dictionaries but they're going in reverse. I enjoy the irony of that.

Re: Wikipedia globally blocks Apple Private Relay IP ranges from editing

#60

Is the premise over at Wikipedia still that an IP address meaningfully identifies a single editor? I think that ship sailed.

"I cannot stress this enough, and I think it's important to frame this debate correctly when it comes to discussing these blocks. I have made somewhere around 1200 rangeblocks of webhosting providers in the last 5 weeks or so. Not one of them was targeted at a user." — [[User:Blablubbs]] in linked page Wikipedia doesn't block to punish individuals. It blocks to protect itself. There are plenty of ways around most blo…

yes, but it is way to broad. hosting service ranges are blocked even though individual servers have static IPs. it is possible to get an IP unblocked, but then someone else blocks another range with that IP again. it's impossible to keep up.

the problem with accounts is that the editing history is public, making it impossible to keep even a pseudo-anonymous identity because everyone would know who i am based on what i edit.

didn't jimmy wales himself say that the editing and viewing history is sensitive personal data?

i don't mind wikipedia itself knowing my identity, just like i don't mind hackernews admins knowing who i am, but i'd like wikipedia to help me keep my identity hidden from the public.

Post reply on HN