Brion Vibber wrote:
The biggest privacy problem in Wikipedia has always been the permanent public exposure of casual editors' IP addresses.
Secondarily, we store logged-in editors' IP addresses for a limited time, exposing all editors' IP addresses to access by staff and volunteer accounts which could be stolen or misused as well as to any potential attacker who gains sufficient access to the database systems.
I would like to suggest that the Wikimedia editor community, along with the Wikimedia Foundation as steward of the software and servers, have a serious consultation about committing to fix this:
- Eliminate IP address exposure for non-logged-in editors. Those editors
should be either given a random, truly anonymous identifier, or required to create a pseudonym as a login.
- Seriously think about how this will affect workflows tracking and
fighting vandalism, and provide tools that do not depend on public exposure of network addresses.
- Avoid public exposure or long-term logging of any other
location-specific or network-specific information about anonymous users.
There are some notes here: https://www.mediawiki.org/wiki/?curid=428113. Any effort to expand these notes would be welcome.
MZMcBride