[01:44:17] Hi. How do I report what I think is a security/privacy bug? I'm not sure that you want this to be public in Bugzilla until it's fixed..... [01:45:00] It may not be a bug but it sure doesn't look right to me. [01:47:03] Pine: you want to run it by me? or you could send an email to a private list [01:48:54] Are you WMF? I would like to know your permissions before I send you details. [01:49:00] Some sort of verification would be good. [01:49:29] Pine: i'm a board member of NYC. i'm not an employee but i think a fair number of people will vouch for me [01:49:41] (the chapter) [01:50:07] That probably won't be good enough, sorry. But do you know any WMF devs who are here? [01:50:57] well can you describe it at all? or describe your criteria for good enough and how you reached those criteria? [01:51:26] hard to know who to poke if i don't know anything about it [01:51:47] there is now a dedicated employee on security matters [01:51:52] you could try him [01:51:56] It deals with something that I can do on EN that I'm not sure I should be able to do. [01:52:23] It's a bit of a hack. [01:52:40] It involves a bug that was marked closed but I'm thinking the bug still exists. [01:53:11] who is the dedicated employee? [01:53:18] chris steipp [01:53:24] he seems to be offline atm [01:54:27] Hm. Does WMF have any 24 hour tech staff? [01:55:06] no, but it has tech staff in at least 7 time zones [01:55:16] and people can be paged [01:56:40] also, people can go hiking with phones powered off! (and then can't be paged) [01:56:46] I see :) [01:56:51] they just don't all go hiking at once [01:57:18] I can vouch for jeremyb if it's actually needed [01:57:21] I've found an online WMF staffer. Hopefully they'll be able to direct me to someone who can look at my issue. [01:57:36] also if it's what I think it is, it's really not that big of a deal [01:57:37] Thanks though :) [01:57:38] ok, let us know the results [01:57:54] Yeah, it won't bring down the wiki, just something that I think isn't as it should be. [01:58:21] Pine, we got hundreds of "things that aren't as they should be" [01:58:40] XD okay [01:59:00] You can file a bug with the security setting so that only CC and devs can see it [01:59:12] ooh that is good to know [02:00:02] Snowolf: you can also group individual comments/attachments within a bug [02:00:54] jeremyb: that's interesting, had no idea you could [02:00:58] * jeremyb wonders who you found [02:08:40] It's nothing dramatic, just not right as far as I can tell, and something that devs thought they'd fixed. [02:10:18] jeremyb: say hi to Pharos for me :) [02:10:48] Pine: he's on IRC now ;) [02:11:00] I know, but you can say hi in person. [02:11:14] he's at least a mile away [02:11:15] * Pine creating random unnecessary work [02:11:35] and i'm sleepy [02:12:11] Snowolf: where's the security flag in the bugzilla report form? [02:12:20] under product I think [02:12:27] Mind adding me as CC? [02:12:34] oh, I see, yeah [02:12:41] No wonder I couldn't find it. [02:12:46] Sure, I'll add you. [02:12:54] * Pine has already discussed this with Snowolf [02:13:13] and /me ;) [02:13:17] Pine: if you type in snowolf, it should bring up my bugzilla email address, otherwise it's wikimedia.bugs@snowolf.eu [02:13:35] Snowolf: who'd you talk to get on auto for site reqs? [02:13:55] and how's that working out for you? ;P [02:14:17] !log LocalisationUpdate completed (1.20wmf4) at Tue Jun 5 02:14:17 UTC 2012 [02:14:23] Logged the message, Master [02:14:25] a) a bugzilla admin :PPP b) It's actually pretty nice, it's not even that much traffic [02:14:42] i wish you could subscribe to keywords [02:14:54] i suppose i could set up a whine [02:22:43] Snowolf: good news, I've done some more testing and this is not as bad as I first thought. I'm going to lower the severity rating quite a bit. [02:23:47] kaldari come, kaldari go ;P [02:36:45] !log LocalisationUpdate completed (1.20wmf3) at Tue Jun 5 02:36:44 UTC 2012 [02:36:49] Logged the message, Master [04:43:01] Before IPv6 gets live, be sure to set $wgBlockCIDRLimit's IPv6 entry to 32. [10:01:48] !log asher synchronized wmf-config/db.php 'putting es1 in production' [10:01:52] Logged the message, Master [11:28:00] [[Tech]]; Shiju; /* Adding a section to the "Special characters" portion of WikiEditor toolbar */ ; https://meta.wikimedia.org/w/index.php?diff=3812262&oldid=3802594&rcid=3334722 [12:33:04] * closedmouth eyes snitch [12:35:07] snitch :O [15:16:14] !log asher synchronized wmf-config/db.php 'pulling es2 for kernel+mysql upgrades' [15:16:18] Logged the message, Master [15:44:26] !g 10084 [15:44:26] https://gerrit.wikimedia.org/r/#q,10084,n,z [15:44:34] anyone want to do a shell req? [15:44:36] ^^^^ [15:44:47] !log asher synchronized wmf-config/db.php 'returning es2 to service' [15:44:51] Logged the message, Master [17:14:53] !log aaron synchronized php-1.20wmf4/includes/logging/LogEventsList.php 'deployed d9f146ac42f2884e76390d6bc979eb10032adf7f' [17:14:58] Logged the message, Master [19:49:43] !log catrope synchronized wmf-config/CommonSettings.php 'Fix notice in MobileFrontend config' [19:49:47] Logged the message, Master [20:16:35] !log mmullie Started syncing Wikimedia installation... : [20:16:40] Logged the message, Master [20:56:36] !log mmullie Finished syncing Wikimedia installation... : [20:56:41] Logged the message, Master [22:13:09] !log kaldari synchronized php-1.20wmf4/extensions/PageTriage/modules/ext.pageTriage.models/ext.pageTriage.article.js 'updating default PageTriage filters' [22:13:13] Logged the message, Master [22:33:37] !log catrope synchronized wmf-config/CommonSettings.php 'Temporarily allow uploading woff files on slwikisource' [22:33:41] Logged the message, Master [22:34:51] !log aaron synchronized php-1.20wmf4/includes/filerepo/file/LocalFile.php 'deployed 4791e3d25aebe9643a7cea91f2eb49e6b54593c5' [22:34:55] Logged the message, Master [22:35:07] RoanKattouw: ah, so you're finally fixing that :) [22:35:21] hoo: No not really [22:35:33] I need to upload two fonts to slwikisource , then I'll disable it again [22:35:49] It's because slwikisource is loading fonts from fonts.googleapi.com , which violates the WMF privacy policy [22:36:03] I know, I told you on Sunday :P [22:36:35] Oh that was you [22:36:41] * RoanKattouw failed to match up IRC nick and person there [22:37:02] Yeah I meant to fix the font thing on Sunday (or was it Saturday?) [22:37:23] Yeah... they should probably have nick names on thos signs [22:37:54] You told me what your nickname was [22:37:56] !log catrope synchronized wmf-config/CommonSettings.php 'Undo temporary woff whitelisting' [22:37:59] Well you said you were "hoo man" [22:38:00] Logged the message, Master [22:38:09] I somehow didn't match that up with the IRC nick 'hoo' [23:59:29] IPv6 day officially begins in less than half a minute. [23:59:50] 10 secs