From: "H. Langos" <henrik-dvb@prak.org>
To: Johannes Stezenbach <js@linuxtv.org>
Cc: linux-media@vger.kernel.org
Subject: Re: wiki on linixtv.org locked
Date: Tue, 28 Apr 2009 01:21:51 +0200 [thread overview]
Message-ID: <20090427232151.GP2895@www.viadmin.org> (raw)
In-Reply-To: <20090427221416.GA22707@linuxtv.org>
On Tue, Apr 28, 2009 at 12:14:16AM +0200, Johannes Stezenbach wrote:
> On Mon, Apr 27, 2009 at 10:29:25PM +0200, H. Langos wrote:
> >
> > the next step would be to update the mediwiki software to 1.11.1 if you have
> > $wgEnableAPI = true, that is. (i know it is only a XSS that hits internet
> > explorer users .. but hey, they are people, too ;-)
>
> I will update to 1.14.0. This is the current version, and it is
> also used by wiki.kernel.org (there is a secret plan to eventually
> move the wiki there). And all the shiny new anti-spam extensions
> don't seem to work with 1.11 anymore...
reCAPTCHA seems to work with anything newer than 1.7.
> > if i remember right, the linuxtv wiki only allows editing to registered
> > users. therefore you could simply temporarily disable new user registration
> > and enable editing again for registered users.
>
> I will do the update first.
>
> > then i'd suggest installing the reCAPTCHA extention. not only will it
> > prevent bots from registering, you also help to digitize old books.
> >
> > http://recaptcha.net/plugins/mediawiki/
>
> Looked at that and noticed they don't provide any statement
> regarding confidentiality / data protection. Who knows if
> they aren't creating a huge database of who did what in Wikis
> and Blogs around the net...
I'd rather take a look at the code to see what kind of data is sent
off-site. My guess is that there isn't any identification data involved at
all. but you are right. they could add that to their faq.
OTAH they are a university project and probably didn't approach the whole
thing with sufficient paranoia to think about such a question ;-)
> Besides that, this wouldn't have stopped the present attack
> since the bot used does a manual login assisted by a human user.
> To thwart that I'd have to enable the captcha for every page save...
hmm, manualy asisted bots are nasty. but maybe there is a way to lower the
limit of edits that can be done automatically. maybe a soft limit that would
trigger captcha usage way before hitting the hard limit that stoped the bot
this time....
cheers
-henrik
next prev parent reply other threads:[~2009-04-27 23:22 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-04-27 16:43 wiki on linixtv.org locked H. Langos
2009-04-27 17:37 ` Johannes Stezenbach
2009-04-27 20:29 ` H. Langos
2009-04-27 22:14 ` Johannes Stezenbach
2009-04-27 23:21 ` H. Langos [this message]
2009-04-28 8:20 ` Johannes Stezenbach
2009-04-28 8:25 ` H. Langos
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20090427232151.GP2895@www.viadmin.org \
--to=henrik-dvb@prak.org \
--cc=js@linuxtv.org \
--cc=linux-media@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.