[Wikitech-l] Passwd auth on mobile site fubar, or me?

2014-03-31 Thread George William Herbert
Just got fail to authenticate to m.en including getting it to send me a temp password in case I forgot it. It it me or a site problem? -george william herbert george.herb...@gmail.com Sent from Kangphone ___ Wikitech-l mailing list Wikitech-l

Re: [Wikitech-l] Gerrit Commit Wars

2014-03-10 Thread George William Herbert
have complained, it is a bug, regardless of what reasonable developer expectations were. Yes, it sucks. But, this is what having real users (versus idealized ones) brings... -george william herbert george.herb...@gmail.com Sent from Kangphone On Mar 10, 2014, at 11:05 AM, Tyler Romeo wrote: >

Re: [Wikitech-l] MediaWiki performance analysis

2013-11-15 Thread George William Herbert
le a lot...). -george william herbert george.herb...@gmail.com Sent from Kangphone ___ Wikitech-l mailing list Wikitech-l@lists.wikimedia.org https://lists.wikimedia.org/mailman/listinfo/wikitech-l

Re: [Wikitech-l] 2013 Datacenter RFP - open for submissions

2013-10-21 Thread George William Herbert
This is the RFP, not contract. It's industry typical for information needed to decide if followup and then site visit are called for, for particular potential vendors. -george william herbert george.herb...@gmail.com Sent from Kangphone On Oct 21, 2013, at 7:56 AM, Jay Ashworth

Re: [Wikitech-l] 2013 Datacenter RFP - open for submissions

2013-10-19 Thread George William Herbert
is luck, not extra robustness). Every time I site survey a "tier 4" I can find vulnerabilities. -george william herbert george.herb...@gmail.com Sent from Kangphone ___ Wikitech-l mailing list Wikitech-l@lists.wikimedia.org https://lists.wikimed

Re: [Wikitech-l] Persian Wikipedia stance on SSL

2013-09-10 Thread George William Herbert
On Sep 10, 2013, at 12:49 AM, Amir Ladsgroup wrote: > and problem of internet > access becomes even worse when the government makes speed of internet on > SSL so low that time of opening a simple page becomes like 4 times higher > when people try to use SSL, We are not proposing to shut of h

Re: [Wikitech-l] HTTPS for logged in users on Wednesday August 21st

2013-08-21 Thread George William Herbert
If it was six months ago, I would suggest we hand over a unique random cookie with the redirect and verify on the HTTPS side that the cookie showed up, to make sure that it worked. And then only keep a success/fail log for IP block, perhaps, no user data. That would seem privacy neutral. Too

Re: [Wikitech-l] HTTPS for logged in users on Wednesday August 21st

2013-08-20 Thread George William Herbert
On Aug 20, 2013, at 9:43 PM, Greg Grossmeier wrote: > Additionally, to see if any changes have a major effect on the ability > of people to log in, we've started parsing out the successful > centralauth autentications and will have a nice Ganglia graph tomorrow. > We also parsed out some hist

Re: [Wikitech-l] HTTPS for logged in users on Wednesday August 21st

2013-08-20 Thread George William Herbert
+foundation-l On Aug 20, 2013, at 1:20 PM, Brion Vibber wrote: > This is an acceptable trade-off which we've allowed the Chinese government > to make for us before, and here we're talking about a much smaller effect > (on contributors only). > > Again, it's not our business to fix China. China

Re: [Wikitech-l] HTTPS for logged in users on Wednesday August 21st

2013-08-20 Thread George William Herbert
On Aug 20, 2013, at 12:57 PM, Brion Vibber wrote: > IMO it's simply unacceptable to leak authentication tokens or account > passwords in cleartext; allowing any form of login over HTTP is dinosaur > behavior and we'd be crazy to let it continue, whether for "some sites" > only or all. We should

Re: [Wikitech-l] HTTPS for logged in users on Wednesday August 21st

2013-08-20 Thread George William Herbert
On Aug 20, 2013, at 12:03 PM, James Alexander wrote: > Yeah, this seems to contradict what I thought Ryan was saying above and > what I was under the impression for. The bad use case for here (as describe > by Risker for example) is a mainland china user from zhWiki logging in > (through http)