Live data from Hacker News

Wikipedia was in read-only mode following mass admin account compromise

wikimediastatus.net

61–70 of 405 posts

Re: Wikipedia was in read-only mode following mass admin account compromise

#61

Earlier quoted context omitted.

Also the language that runs half of the web. Also the language that has made me millions over my career with no degree. Also the language that allows people to be up and running in seconds (with or without AI). I could go on.

The language is not what makes you nor the product. You could've written the same thing in RoR, PHP was just first and it's why it still exists

PHP performance is significantly better than Ruby on Rails, which I think plays a part in its continued popularity.

Re: Wikipedia was in read-only mode following mass admin account compromise

#62
post #13

Earlier quoted context omitted.

PHP is the language where "return flase" causes it to return true. https://danielc7.medium.com/remote-code-execution-gaining-do...

FWIW this was fixed in 2020

I've not used PHP in anger in well over a decade, but if the general environment out there is anything like it was back then there are likely a lot of people, mostly on cheap shared hosting arrangements, running PHP versions older than that and for the most part knowing no better.

That isn't the fault of the language of course, but a valid reason for some of the “ick” reaction some get when it is mentioned.

Re: Wikipedia was in read-only mode following mass admin account compromise

#63
I completely understand marking the software that controls drinking water as critical infrastructure- but at some point a state based cyber attack that just wipes wikipedia off the net is deeply damaging to our modern society’s ability to agree on common facts …

Just now thought “if Wikipedia vanished what would it mean … and it’s not on the level of safe drinking water, but it is a level.

Re: Wikipedia was in read-only mode following mass admin account compromise

#64
Another reason to make the default disabling JS on all websites, and the website should offer a service without JS, especially those implemented in obsolete garbage tech. If it's not an XSS from a famous website, it will be an exploit from a sketchy website.

Re: Wikipedia was in read-only mode following mass admin account compromise

#65
A theory on phab: "Some investigation was made in Russian Wikipedia discord chat, maybe it will be useful.

1. In 2023, vandal attacks was made against two Russian-language alternative wiki projects, Wikireality and Cyclopedia. Here https://wikireality.ru/wiki/РАОрг is an article about organisators of these attacks.

2. In 2024, ruwiki user Ololoshka562 created a page https://ru.wikipedia.org/wiki/user:Ololoshka562/test.js containing script used in these attacks. It was inactive next 1.5 years.

3. Today, sbassett massively loaded other users' scripts into his global.js on meta, maybe for testing global API limits: https://meta.wikimedia.org/wiki/Special:Contributions/SBasse... . In one edit, he loaded Ololoshka's script: https://meta.wikimedia.org/w/index.php?diff=prev&oldid=30167... and run it."

Re: Wikipedia was in read-only mode following mass admin account compromise

#66
post #13

Earlier quoted context omitted.

PHP is the language where "return flase" causes it to return true. https://danielc7.medium.com/remote-code-execution-gaining-do...

Also the language that runs half of the web. Also the language that has made me millions over my career with no degree. Also the language that allows people to be up and running in seconds (with or without AI). I could go on.

Try not to take criticisms of tools personally. Phillips head screws are shit for a great many applications, while simultaneously being involved in billions of dollars of economic activity, and being a driver that everyone has available.

Re: Wikipedia was in read-only mode following mass admin account compromise

#67

Earlier quoted context omitted.

care to elaborate?

If I had to guess it's the typical "people with power behaving like dicks".

Absolutely. We know plenty of examples where these arseholes trash genuinely valuable contributions from volunteers just on a whim.

Re: Wikipedia was in read-only mode following mass admin account compromise

#69
post #54
post #32

Earlier quoted context omitted.

On what? I'd be curious to read more (documented sources)

Where and how they spent their money is on p. 21 of this PDF [1] which can be obtained from this official source [2]. This is just a high-level breakdown, but it does illustrate that, for example, more than twice as much is spent on "Donation processing expenses" ($7.5M) as "Internet hosting" ($3.1M), and that the largest line item, by far, is "Salaries and benefits" ($106M). [1]: https://wikimediafoundation.org/wp-c…

Well obviously salaries will be the highest expense in any organization like this. The more interesting question is if it's salaries to security programmers or teachers at an african womens' coding bootcamp (yes they did spend money on that, and yes it's probably useful, but hardly what people think of when they see those "donate now to keep wikipedia alive" banners). A big percentage probably goes to their CEO who does who knows what.

Re: Wikipedia was in read-only mode following mass admin account compromise

#70

This was only a matter of time. The Wikipedia community takes a cavalier attitude towards security. Any user with "interface administrator" status can change global JavaScript or CSS for all users on a given Wiki with no review. They added mandatory 2FA only a few years ago... Prior to this, any admin had that ability until it was taken away due to English Wikipedia admins reverting Wikimedia changes to site presenta…

[flagged]
Post reply on HN