Re: [Wikitech-l] Language variants

2009-09-15 Thread Jared Williams
Doesn't having geographically located page caches reduce the doubling effect in any given location? Squids located in the US should be caching more en-US than en-GB, and those in Europe should have more en-GB than en-US. Jared > -Original Message- > From: wikitech-l-boun...@lists.wikim

[Wikitech-l] Usability initiative

2009-09-15 Thread Dmitriy Sintsov
Hi! I've read that usability is important for MediaWiki. Why don't integrate wikitext syntax highlighting then? That will greatly improve editing of the pages. There is Extension:WikEd which has most of the work implemented already. http://www.mediawiki.org/wiki/File:WikEd_screenshot.png I know

Re: [Wikitech-l] Usability initiative

2009-09-15 Thread Roan Kattouw
2009/9/15 Dmitriy Sintsov : > Hi! > I've read that usability is important for MediaWiki. Why don't integrate > wikitext syntax highlighting then? We're planning to do exactly that in our third release (Citron). Right now, we're working on bugfixing and deploying our second release (Babaco). > That

Re: [Wikitech-l] Usability initiative

2009-09-15 Thread Dmitriy Sintsov
* Roan Kattouw [Tue, 15 Sep 2009 13:34:07 +0200]: > We're planning to do exactly that in our third release (Citron). Right > now, we're working on bugfixing and deploying our second release > (Babaco). > What do these codenames mean? Citron is v1.16 and Babaco is v1.17 or it's something else? Wi

Re: [Wikitech-l] Usability initiative

2009-09-15 Thread Roan Kattouw
2009/9/15 Dmitriy Sintsov : > * Roan Kattouw [Tue, 15 Sep 2009 13:34:07 > +0200]: >> We're planning to do exactly that in our third release (Citron). Right >> now, we're working on bugfixing and deploying our second release >> (Babaco). >> > What do these codenames mean? Citron is v1.16 and Babaco

Re: [Wikitech-l] Language variants

2009-09-15 Thread Domas Mituzas
Jared, > Doesn't having geographically located page caches reduce the > doubling effect > in any given location? > > Squids located in the US should be caching more en-US than en-GB, > and those > in Europe should have more en-GB than en-US. It doesn't happen with LRU, object accessed 100 ti

Re: [Wikitech-l] Usability initiative

2009-09-15 Thread Lane, Ryan
> I've read that usability is important for MediaWiki. Why > don't integrate > wikitext syntax highlighting then? That will greatly improve > editing of > the pages. There is Extension:WikEd which has most of the work > implemented already. > http://www.mediawiki.org/wiki/File:WikEd_screenshot

[Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Chad
On Tue, Sep 15, 2009 at 1:38 PM, Gregory Kohs wrote: > I was sort of surprised to learn today that Mediawiki software has had 37 > security holes identified: > > http://akahele.org/2009/09/false-sense-of-security/ > > Are most of these patched now, or are they still open?  If still open, is > the

[Wikitech-l] WMF decommissions servers

2009-09-15 Thread Mike.lifeguard
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello, I wanted to let folks know that WMF is decommissioning some 35 servers, and is willing to accept requests from users interested in using them for Wikimedia-related purposes. If you can ship a server from Tampa to where you are, and if you can p

Re: [Wikitech-l] Usability initiative

2009-09-15 Thread Dmitriy Sintsov
* "Lane, Ryan" [Tue, 15 Sep 2009 12:41:26 -0500]: > See: http://usability.wikimedia.org/wiki/Releases > > This is listed as one of the features of the Citron release. > Thanks. I've figured out that will be http://www.mediawiki.org/wiki/Extension:UsabilityInitiative then probably moved to core. I

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Roan Kattouw
2009/9/15 Chad : > On Tue, Sep 15, 2009 at 1:38 PM, Gregory Kohs wrote: >> I was sort of surprised to learn today that Mediawiki software has had 37 >> security holes identified: >> >> http://akahele.org/2009/09/false-sense-of-security/ >> >> Are most of these patched now, or are they still open?

Re: [Wikitech-l] Usability initiative

2009-09-15 Thread Sergey Chernyshev
Are these releases in any way connected to MediaWiki releases though? I understand that all that gets release on Wikimedia projects, but it'll be great to have the rest of MW user base benefit from these as well (I have personal interest here as you can imagine ;)). Thank you, Sergey -

Re: [Wikitech-l] Usability initiative

2009-09-15 Thread Lane, Ryan
> Are these releases in any way connected to MediaWiki releases though? > > I understand that all that gets release on Wikimedia > projects, but it'll be > great to have the rest of MW user base benefit from these as > well (I have > personal interest here as you can imagine ;)). > AFAIK the r

Re: [Wikitech-l] Usability initiative

2009-09-15 Thread Roan Kattouw
2009/9/15 Lane, Ryan : >> Are these releases in any way connected to MediaWiki releases though? >> >> I understand that all that gets release on Wikimedia >> projects, but it'll be >> great to have the rest of MW user base benefit from these as >> well (I have >> personal interest here as you can i

Re: [Wikitech-l] Usability initiative

2009-09-15 Thread Robert Rohde
On Tue, Sep 15, 2009 at 12:17 PM, Roan Kattouw wrote: > 2009/9/15 Lane, Ryan : >>> Are these releases in any way connected to MediaWiki releases though? >>> >>> I understand that all that gets release on Wikimedia >>> projects, but it'll be >>> great to have the rest of MW user base benefit from t

Re: [Wikitech-l] Usability initiative

2009-09-15 Thread Roan Kattouw
2009/9/15 Robert Rohde : > Is there a road map somewhere for features you plan to include but > haven't gotten to yet? > http://usability.wikimedia.org/wiki/Releases Roan Kattouw (Catrope) ___ Wikitech-l mailing list Wikitech-l@lists.wikimedia.org https

[Wikitech-l] Archive of visitor stats

2009-09-15 Thread Lars Aronsson
Are visitor stats (as produced by Domas) safely archived somewhere, for example on the toolserver, where development projects can easily access them for analysis? I have made my own copies of the files (I guess my plan was to use them, but this hasn't started yet), but now I'm running out of

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Aryeh Gregor
On Tue, Sep 15, 2009 at 2:21 PM, Roan Kattouw wrote: > This has been addressed on foundation-l already, but I'll make it > extra clear here: all these vulnerabilities reported by these database > are only in there because we discovered, fixed and reported them > first. The affected versions of Med

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Benjamin Lees
On Tue, Sep 15, 2009 at 1:38 PM, Gregory Kohs wrote: > > http://akahele.org/2009/09/false-sense-of-security/ > > My favorite part of that article: "Even the open source MediaWiki software has more than its fair share of security vulnerabilities." As written, this suggests that there are unpatc

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Anthony
On Tue, Sep 15, 2009 at 6:36 PM, Benjamin Lees wrote: > On Tue, Sep 15, 2009 at 1:38 PM, Gregory Kohs > wrote: > > > > > http://akahele.org/2009/09/false-sense-of-security/ > > > > > My favorite part of that article: "Even the open source MediaWiki software > has more than its fair share of sec

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Andrew Garrett
On 15/09/2009, at 11:40 PM, Anthony wrote: >> My favorite part of that article: "Even the open source MediaWiki >> software >> has more than its fair share of security vulnerabilities." As >> written, >> this >> suggests that there are unpatched security vulnerabilities > > There are. You di

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Chad
On Tue, Sep 15, 2009 at 6:36 PM, Benjamin Lees wrote: >  On Tue, Sep 15, 2009 at 1:38 PM, Gregory Kohs wrote: > >> >> http://akahele.org/2009/09/false-sense-of-security/ >> >> > My favorite part of that article: "Even the open source MediaWiki software > has more than its fair share of security v

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Anthony
On Tue, Sep 15, 2009 at 7:17 PM, Andrew Garrett wrote: > > On 15/09/2009, at 11:40 PM, Anthony wrote: > >> My favorite part of that article: "Even the open source MediaWiki > >> software > >> has more than its fair share of security vulnerabilities." As > >> written, > >> this > >> suggests that

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Chad
On Tue, Sep 15, 2009 at 7:26 PM, Anthony wrote: > On Tue, Sep 15, 2009 at 7:17 PM, Andrew Garrett wrote: > >> >> On 15/09/2009, at 11:40 PM, Anthony wrote: >> >> My favorite part of that article: "Even the open source MediaWiki >> >> software >> >> has more than its fair share of security vulnerab

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Brian
On Tue, Sep 15, 2009 at 5:26 PM, Anthony wrote: > On Tue, Sep 15, 2009 at 7:17 PM, Andrew Garrett >wrote: > > > > > On 15/09/2009, at 11:40 PM, Anthony wrote: > > >> My favorite part of that article: "Even the open source MediaWiki > > >> software > > >> has more than its fair share of security

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Anthony
On Tue, Sep 15, 2009 at 7:33 PM, Chad wrote: > Well thankfully the majority of 3rd party users have a better feeling > about reporting bugs when they find them. > I'm not sure where you got the statistics for that statement, but hey, you should publicize it. "Mediawiki - more than half of disco

[Wikitech-l] Software updates Wednesday morning

2009-09-15 Thread brion
I've been spending much of the last few work days tidying up an update to our deployed codebase, which has been several weeks behind development for most components. I'll want to start deploying this in the morning (Pacific time), so we'll have most of the day to poke around and fix up any problem

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread jidanni
> "AG" == Aryeh Gregor writes: AG> Compare to WordPress, where if you don't keep up-to-date you can get AG> your server taken over and used to send spam Mediawiki/Wordpress is like Linux/Microsoft. It will always be an uphill battle to keep WordPress secure. Never content to just answer HTTP

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread George Herbert
On Tue, Sep 15, 2009 at 4:40 PM, Anthony wrote: > On Tue, Sep 15, 2009 at 7:33 PM, Chad wrote: > >> Well thankfully the majority of 3rd party users have a better feeling >> about reporting bugs when they find them. >> > > I'm not sure where you got the statistics for that statement, but hey, you

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Q
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Anthony wrote: > On Tue, Sep 15, 2009 at 7:33 PM, Chad wrote: > >> Well thankfully the majority of 3rd party users have a better feeling >> about reporting bugs when they find them. >> > > I'm not sure where you got the statistics for that stateme

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Domas Mituzas
Hi! > Asking open source developers for Now that we got to ethics, I was wondering if it would be ethical for me to inject bugs around the software, and then ask for bounties to identify them! :-) Cheers and good night, Domas ___ Wikitech-l mailin

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread brion
On Tue, 15 Sep 2009 13:51:48 -0400, Chad wrote: > I'm pretty sure a lot of this has been fixed (I vaguely remember Tim doing > some cleanup to the installer for XSS issues), but I can't say for sure. > Forwarding to wikitech-l, this is more of a tech issue than Foundation > one. Please don't both

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Chad
On Tue, Sep 15, 2009 at 7:40 PM, Anthony wrote: > On Tue, Sep 15, 2009 at 7:33 PM, Chad wrote: > >> Well thankfully the majority of 3rd party users have a better feeling >> about reporting bugs when they find them. >> > > I'm not sure where you got the statistics for that statement, but hey, you

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread Anthony
On Tue, Sep 15, 2009 at 7:49 PM, George Herbert wrote: > On Tue, Sep 15, 2009 at 4:40 PM, Anthony wrote: > > On Tue, Sep 15, 2009 at 7:33 PM, Chad wrote: > > > >> Well thankfully the majority of 3rd party users have a better feeling > >> about reporting bugs when they find them. > >> > > > > I'm

[Wikitech-l] Speed of parsing messages (was: how to chang {{SITENAME}})

2009-09-15 Thread Tisza Gergő
Domas Mituzas gmail.com> writes: > Anyway, we have to ensure, that most of wikis (at least top20 ones) > have got ridden of curly braces and any other expensive parser stuff > in these messages, as that costs them up to 10 milliseconds per > pageview (if anyone writes a bot to do this automa

Re: [Wikitech-l] Usability initiative

2009-09-15 Thread brion
On Tue, 15 Sep 2009 13:34:07 +0200, Roan Kattouw wrote: > There's still quite a few issues with FCKeditor, and as far as I know > it's been decided that the usability project is not gonna cover > WYSIWYG; I'm not entirely sure of the official stance here, you'd have > to ask Naoko. Full wysiwyg h

Re: [Wikitech-l] Fwd: [Foundation-l] Security holes in Mediawiki

2009-09-15 Thread John Vandenberg
On Wed, Sep 16, 2009 at 9:26 AM, Anthony wrote: > On Tue, Sep 15, 2009 at 7:17 PM, Andrew Garrett wrote: >> I think the appropriate expression here is "put up or shut up". >> >> If you are aware of unpatched security vulnerabilities in MediaWiki, >> report them to secur...@wikimedia.org, and to th