New revelations on NSA capabilities yesterday in the New York Times: see
https://www.schneier.com/blog/archives/2013/09/the_nsa_is_brea.html for a
jumping off point.
The bottom line seems to be:
1) don't use RC4 (we're already working toward that goal, I believe)
2) don't use the Dual_EC_DRBG PRNG (see
http://crypto.stackexchange.com/questions/10189/who-uses-dual-ec-drbg)
Can someone take a look at our SSL configuration and see if we have
Dual_EC_DRBG enabled? (And if so, turn it off and use a better PRNG!)
--scott
ps. apparently Dual_EC_DRBG is built-in to Windows (!). A good reason not
to run your security-critical servers on Windows, I guess...
pps. if we're throwing stones, the Debian PRNG flaw is a big glass
window....
ppps.
http://blog.cryptographyengineering.com/2012/02/random-number-generation-il…
pppps. router/switch/firewall compromises have also been a big part of the
NSA story. Has anyone looked at our internal network infra closely?
--
(http://cscott.net)
Hello and welcome to the latest update of the deployment schedule for
the WMF server cluster.
Full schedule available on the wiki, and is the place to look for any
changes:
https://wikitech.wikimedia.org/wiki/Deployments#Week_of_September_9th
Of special note: Next week all WMF staff will be in San Francisco for
the "Tech Days" on Tues/Wed and the "All Hands" on Thurs/Friday. As
such, some changes have been made to the normal deploy calendar (most
notably, no deploys on Thursday due to All Hands).
== Monday ==
* MediaWiki deploy of 1.22wmf16 to all non-wikipedia project sites
(Commons, Witionary, etc)
* The Language team will be rolling out some EventLogging work.
* Probably a deploy of a fix to CentralNotice to accommodate multiple
needs (by eg WLM).
== Tuesday ==
* Nothing as of yet
== Wednesday ==
* Wikipedia Zero updates
* MediaWiki deploy of 1.22wmf17 to test wikis, and 1.22wmf16 everywhere
else
* E3 deploy of some GettingStarted changes.
== Thursday ==
no deploys
== Friday ==
no deploys
As always, questions/comments welcome.
Greg
--
| Greg Grossmeier GPG: B2FA 27B1 F7EB D327 6B8E |
| identi.ca: @greg A18D 1138 8E47 FAC8 1C7D |
The day we have all equally hoped for and dreaded is come to pass: Etherpad
Lite has now replaced Etherpad "Classic" in production, and the labs instance
is on its way out.
This is my as-wide-as-possible email warning to say that everything on the
labs instance, as really should have been expected, is going to be gone soon.
Not immediately - we intend to give you two weeks to get your important data
off the instance and onto the new one at https://etherpad.wikimedia.org/ -
but you should _absolutely_ be moving things as soon as possible. We will
also keep a data dump around, in case anything else needs to get pulled out
of the pads, but I would suggest not relying on that if you don't have to.
And in the future: If a URL has "wmflabs.org" in it...don't put anything,
ANYTHING, important there. The purpose of labs is to let us experiment with
new technology without having to worry about reliability.
Thanks so much for your help and understanding in the course of this
migration.
tl;dr: http://etherpad.wmflabs.org is going down in 2 weeks, get yer stuff
off it.
--
Mark Holmquist
Software Engineer, Multimedia
Wikimedia Foundation
mtraceur(a)member.fsf.org
https://wikimediafoundation.org/wiki/User:MHolmquist
Hey guys!
This hook appears to be the proper way to pass my extension setting
variables to javascript. [1] I don't get how it works. I mean, saw the
examples in Semantic Result Formats and get what PHP side should look
like. Still I have no idea how to access those variables in
javascript. Please help me to figure this out.
[1] https://www.mediawiki.org/wiki/Manual:Hooks/ResourceLoaderGetConfigVars
-----
Yury Katkov, WikiVote
On Fri, Sep 6, 2013 at 3:40 AM, James Forrester <jforrester(a)wikimedia.org>wrote:
> All,
>
> We also added a set of keyboard shortcuts for setting the block
> formatting: Ctrl+0 sets a block as a paragraph; Ctrl+1 up to Ctrl+6 sets
> it as a Heading 1 ("Page title") to Heading 6 ("Sub-heading 4"); Ctrl+7 sets
> it as pre-formatted (bug 33512<https://bugzilla.wikimedia.org/show_bug.cgi?id=33512>).
> The help/'beta' menu now exposes the build number next to the "Leave
> feedback" link, so users can give better reports about issues they
> encounter (bug 53050<https://bugzilla.wikimedia.org/show_bug.cgi?id=53050>
> ).
>
Here it is! I have some characters assigned to the third layer (via
Ctrl+Alt/AltGr), and they conflict with the new keyboard shortcuts. It's
very very annoying and makes VE almost unusable. Is there a way to
distinguish Ctrl and Ctrl+Alt?
> If you have any questions, please do ask.
>
> Yours,
> --
> James D. Forrester
> Product Manager, VisualEditor
> Wikimedia Foundation, Inc.
>
> jforrester(a)wikimedia.org | @jdforrester
>
> _______________________________________________
> Wikitech-ambassadors mailing list
> Wikitech-ambassadors(a)lists.wikimedia.org
> https://lists.wikimedia.org/mailman/listinfo/wikitech-ambassadors
>
>
--
З павагай,
Павел Селіцкас/Pavel Selitskas
Wizardist @ Wikimedia projects
Hi, all
I am trying to add some jquery mobile components to my wiki site, to
give it a more beautiful look on Android app. The app is the official
mediawiki mobile client, which can be downloaded from the following link.
https://github.com/wikimedia/WikipediaMobile
Now, there is no problem for me to include the jquery mobile javascript
and css to this little phonegap-based project. If the contents grabbed
from the mediawiki website (by mobilefrontend) contains jquery mobile
components, they can be shown properly on my android phone.
However, the wiki site look quite different if it is accessed from a PC.
All the jquery mobile contents do not load properly. So I added the
jquery.mobile-1.3.2.min.js to mediawiki common.js, and the
jquery.mobile-1.3.2.min.css to mediawiki common.css. But the whole site
looks a mess. All the buttons and links are shown as jquery mobile
buttons, and cannot be clicked. I wonder whether there is a graceful
method to apply the jquery.mobile js and css just to the wiki contents
(in particular, to div#content), without affecting the surrounding
parts, like the edit page button, save page button, etc.
Thanks for casting some light onto this issue.
Best
Shawn
Hi all,
Just a friendly reminder that we're taking down Gerrit in about 30 minutes
for a planned
migration to a new (bigger) server. We've allotted an hour for the
changeover but I'm not
expecting it to take that long.
I'll be sure to let everyone know when it's back up and running.
-Chad