[02:54:17] New patchset: Hydriz; "Deploying Extension:Labeled Section Transclusion to hydrizwiki." [labs/incubator] (master) - https://gerrit.wikimedia.org/r/24684 [02:56:17] Change merged: Hydriz; [labs/incubator] (master) - https://gerrit.wikimedia.org/r/24684 [05:49:19] Change on 12mediawiki a page Developer access was modified, changed by Jeremyb link https://www.mediawiki.org/w/index.php?diff=586206 edit summary: /* User:Gerx03 */ done [17:05:57] 09/23/2012 - 17:05:57 - Updating keys for stwalkerster at /export/keys/stwalkerster [18:44:02] I'm still unable to gain sudo root access on stock instance builds -- does this work as expected for others? [18:44:51] at least on ubuntu-12.04-precise, puppet config is adding files into /etc/sudoers.d/ so there's that [18:46:52] * GChriss just found https://bugzilla.wikimedia.org/show_bug.cgi?id=39788 [18:48:28] ...if passwordless sudo aren't enabled, how does one get root access to instances? [18:56:18] GChriss: reload the bug [18:57:13] oh. [18:57:15] that works. [18:57:23] but way less secure than I was expecting [18:57:53] so you're root? [18:58:30] yes [18:58:37] good ;) [18:59:33] DQ|sleep: timezone? [18:59:47] I'm guilty of using a fairly simple password for all public wikis (e.g., WMF universal signon), but use a strong password for anything SSH-based [18:59:59] Eastern, I know, my sleep is messed up [19:00:02] and by extension gerrit and labsconsole [19:00:07] haha! [19:00:36] so to have a weak password be blended into the ssh-stuff, well... it's not ideal [19:00:46] GChriss: well there is the 2 factor thing. but yeah, i brought up this very topic long ago [19:01:14] it would be better if this was explicitly spelled out in the signup process, so at least people know [19:02:06] know to use a strong password? that's a separate issue. i was talking about not using a sudo password that's the same password that can be used to get even more power than sudo [19:02:22] and that's where the idea of going passwordless came from [19:03:12] but re making it strong: if they have (or can guess or whatever) your labsconsole password then they can just add their own key to your account [19:03:30] so regardless of sudo it should be strong anyway [19:05:31] agreed, but not immediately obvious to newbies (like me). labsconsole looks a lot like the all the other WMF wikis [19:11:53] GChriss: well feel free to suggest wording or where to put it ;) [19:12:04] Thehelpfulone: ^^ [19:38:32] editing now [19:50:10] GChriss: There are sudo policies per project so in bots for example not everyone can access the sql servers etc. [19:50:19] By default anyone can sudo to anything though [19:50:31] And you should use a secure password regardless, otherwise you're open to escalation attacks [19:51:12] * Damianz thinks we should document how sudo-ldap is setup probably [20:01:44] updated [[Help:Sudo_Policies]] [20:03:02] yup, just got the secure password part [20:04:32] although all of this is only as strong as 'E-mail new password' [20:05:38] which is much better than the Apple ID/Amazon attack [20:33:50] It's sorta why 2 facter auth is there [20:33:58] It's actually required for some higher level functions (admin level) [20:34:15] Which is annoying on the dev site, I have a stupid amount of keys on my phone heh