Comment on Wikipedia in read-only mode following mass admin account compromise
TheTechnician27@lemmy.world 1 day ago
Oh, fuck, this is going to be interesting to read about. Just to clarify: it seems like this wasn’t just Wikipedia but Wikimedia generally. So that’s also e.g. Wiktionary, Wikimedia Commons, Wikidata, etc.
Takapapatapaka@tarte.nuage-libre.fr 1 day ago
Shameless copy/paste of the main info if anyone wants to catch a glimpse without going to reddit :
Summary of events:
Post from WMF staff member on Discord:
thebestaquaman@lemmy.world 1 day ago
To be fair I would assume that it’s better to trigger something like this during a security review when people are actively “online” and focused on security risks than at some other time.
SnotFlickerman@lemmy.blahaj.zone 1 day ago
Absolutely and it helped prove why they needed to do this security review to begin with as well as will teach them the nature of how this user script worked so they can put up guardrails for this specific type of attack. An unfortunate event but as long as they are using it to learn from and strengthen their security, overall it’s a good thing.
Jack@lemmy.ca 5 hours ago
The NoScript extension in Firefox makes the web so much nicer. It turns out sites that don’t require JavaScript tend to made by vastly better humans than sites that do. More so for sites that require cross-site scripting and cookies to just show text.
Can’t search on google.com without allowing JavaScript, but it turns out Lite.DuckDuckGo does, and for me at least gives vastly better search results.
Wikipedia can be read and edited without allowing JavaScript, and I personally don’t like the crap that the scripts provide. It’s also usable without cookies, tho the idiotic UI options column on the right is a hassle without cookies.
Gullible@sh.itjust.works 1 day ago
That’s hilarious, and I cannot imagine how stressed out that employee is.
db2@lemmy.world 1 day ago
After that kind of learning experience that employee needs a reprimand and a raise in that order. You can be that shit won’t happen twice! 😆
crandlecan@mander.xyz 1 day ago
You want even more Management?? 😨
deacon@lemmy.world 1 day ago
Ironically it is comments like these that led to Reddit gold. But thank you kind stranger for saving me having to descend into The Depths for this.
TheTechnician27@lemmy.world 1 day ago
Danke. This should easily be fine for anyone who’s slightly-to-moderately interested; some of the nitty-gritty details like the edit diffs are excluded from this copy–paste for those who really know their stuff and want to learn more.
Sims@lemmy.ml 1 day ago
“The malicious script was created in 2023 to attack two Russian-language alternative wiki projects, Wikireality and Cyclopedia.”
So this was a US/Ukrainian attack on Russia that backfired ?? Weird ‘friendly fire’ situation…