Showing posts with label OpenID. Show all posts
Showing posts with label OpenID. Show all posts

Saturday, September 07, 2013

Improving #privacy and #security

There is little privacy left and there is a lot of FUD about the extend our privacy and security has been compromised. On a mailing list there is even talk about the possibility that the Wikimedia Foundation may be forced to divulge information to one of the American Secret Security organisations.

The good news is that the security and privacy for most users of any of the projects has been improved substantially. As our commitment is first and foremost to bring knowledge to all the people of the world, the only exceptions have been made for people accessing our projects from China and Iran.

There is talk about implementing OpenID for use at the Wikimedia Foundation. Making OpenID available for all of our users would be really welcome given that the use of single sign-on has been largely usurped by companies like Google and Facebook. The Wikimedia Foundation is probably the only organisation that is not commercial that has a fighting chance to be accepted as a provider of single sign-on.

myOpenID.com announced that it will end its services in 2014. I would dearly love to have a replacement in the Wikimedia Foundation as my provider of a single sign-on service.
Thanks,
     GerardM

Tuesday, August 28, 2012

The need for both #OpenID and #OAuth

Many words have been used on the merits of OpenID and OAuth. There are many misconceptions and many of those have everything to do with perspective. In order to get a better understanding I asked on the Wikitech mailinglist a use case for OAuth. The answer I received helps.
OpenID is an identity management system. It allows users to authenticate to one site using another site as their identity. A use case for this is, for example, using your Facebook account to log in to Wikipedia. This may be useful, as it would allow users to more easily register for Wikipedia
OAuth is a third-party authentication and authorization system that allows outside applications to do stuff on behalf of a user. The reason for this is because currently toolserver applications, etc. authenticate to Wikipedia using a plaintext username and password, which is extremely insecure for a number of reasons I will not elaborate on here.
When you read the answer, there are some observations to make. The most obvious is how do you assure that the software that is to use OAuth will be secure. Given the power of many Toolserver tools how do you make sure that only trusted people make use of the Toolserver functionality.

Enter OpenID, it does provide identity management. OpenID is able to provide more information than just "this is indeed the indicated identity" as part of the "OpenID Attribute Exchange". When the Wikimedia Foundation implements OpenID as a service, it will be possible to identify the users that have a "bot flag" on the user profile. 

As it is, the Toolserver tools are not necessarily secure. With OAuth it will become even less secure to run the software because it will be the software itself that includes the authorisation to run, never mind its configuration, never mind how it is used or by whom. When OpenID authenticates users, it becomes possible to ensure that only people with a bot flag can run Toolserver software on the production Wikimedia projects.

To make the use of the Toolserver tools secure, it is necessary to complement OAuth with OpenID. Oauth in isolation will make the Toolserver tools easier to use but it does not make them more secure to run.
Thanks,
      GerardM

Tuesday, August 21, 2012

a #threat assessment for #Wikipedia

The people who take care of mail send to Wikipedia are often informed that Wikipedia is not secure; "everybody can edit Wikipedia". This is actually intentional because Wikipedia is the encyclopaedia that everybody can edit. The real risk is when people do not recognise they are invited to edit. This is a genuine issue and it is something that receives a lot of attention.

When you consider security for Wikipedia, the people most at risk are its editors. There are several threats they are exposed to. Several of these are issues computer security can deal with.
  • threat to the anonymity of a registered user
  • threat to user credentials
When the potential threats are evaluated, it is important to realise that the severity of these threats is not obvious. It matters considerably where you reside, what your ethnicity is or what your belief system is. It is important to minimise any threats because once people no longer feel free to contribute it will damage the "neutral point of view" that gives Wikipedia much of its relevance.

With the implementation of SSH it has become considerably more difficult to learn what a person is doing when working on Wikipedia. This has been a real improvement. However, user credentials and particularly passwords are considered not really secure. Read for instance what Wired had to say about them. It is explained that improvements can only be expected when changing the infrastructure of online security. This will probably do a whole lot more good than lecturing people about how they should change their behaviour.

The question is if the WMF is open for such considerations. So far the talk is about "Nascar" ?!?! to me this sounds remarkably like bikeshedding and is very much beside the point.
Thanks,
     GerardM

Monday, August 20, 2012

#OpenID for the USERS of #Wikipedia, PLEASE


Again a discussion about the use of OpenID for the Wikimedia projects flared up. From my perspective the one perspective missing is the one of a computer user who is fed up with the failed security that is provided by passwords.

The problem is that systemmanagers only consider security in isolation. It is the solution that is to be adopted for their system or systems. Obviously in a perfect world, a user will have a separate password for each website or program. The world is not perfect and most people use one or a few passwords for everything. The world is not perfect and passwords of many big websites have been uncovered by hackers. Consequently many passwords used by Wikimedia contributors can easily be guessed by the bad guy who are in the know.

The problem with passwords for a user is that they are unmanageable. Too many systems and websites, too many interfaces seriously impact the security wherever passwords are implemented to provide security. It is theatre and the fool is the part you have to play.

OpenID provides a serious alternative. It allows for a single place with a single password that authenticates to any and all websites and services that accept security in this way.  It is a serious alternative as long as any and all accept other OpenID. It will be really welcome when the WMF considers security for its 456 M users. It is obvious that a large percentage also frequent websites like LinkedIn and solidify the argument to implement OpenID.
Thanks,
     Gerard

Thursday, June 07, 2012

The use case for #OpenID indicated by the #LinkedIn hack

LinkedIn was hacked; all the passwords in use a few days ago are no longer secret. The advice people get is to change their password everywhere where they use the same password.

This blog post is not about LinkedIn. It is about the lack of security provided by passwords as seen from a user point of view. Any organisation that thinks it can not happen to them is delusional. From a user point of view, any website that wants you to create a user with a password that is maintained on that website is a potential security risk. A risk you are exposed to because any site can be hacked and, you do not remember passwords that are unique to each website.

For a user, it is more secure to rely on one place where all the authentication to any website is done. The advantage becomes clear when a website is hacked; there is no password for you to abuse. When the authentication server is hacked, all that is required is to change the password at that central server.

LinkedIn was compromised and as a result many people with a Wikimedia account have an account that is compromised as well. Many of these people will not change their password because they cannot be bothered or because they are not aware of the risk.

As a consequence disruption by "trusted users" is a potential and realistic scenario. This risk can be mitigated by accepting the use of authentication through an OpenID service.
Thanks,
     GerardM

Friday, June 01, 2012

#WMDEVDAYS - Single signon

One of the #Wikidata presentations posed a question: "We need a much improved single signon". For Wikidata it is important to be able to edit Wikidata itself while working at the same time on a Wikidata client. The presenter wanted to understand if this is an issue that needs to be addressed soon.

When you will be using Wikidata on one of the Wikimedia projects, you will typically use one user on all projects. This user is authenticated once when he signs on with his global user account and, this authentication serves him well when he works on other projects.

This will work well for Wikidata. The only issue left is that they also want to be usable and editable for users who use Wikidata from their own server. This however is an issue that they do not have to solve immediately.

There is existing functionality like OpenID that may provide a solution for this. It is great that the Wikidata people consider how the data can be used from outside the Wikimedia Foundation. It is wonderful that they provide a use case that makes a case for implementing OpenID.
Thanks,
     GerardM

Friday, May 11, 2012

The #OpenID challenge

At #Translatewiki.net a request was made to support OpenID. The beauty of OpenID is that it reduces the number of websites that store your password. This makes browsing the Internet arguably safer.

The translatewiki staff is hesitant to support yet another nice to have extension. It has been burned by accepting LiquidThreads in the past. LiquidThreads is a great idea and it provides a much better user experience but it has not been properly supported. There is a promise for a release somewhere in an unspecified future.

Wikinaut did take over the OpenID extension support. He provided patches updated the documentation and equally important, he runs it on his own MediaWiki wikis. The need for support seems to be fulfilled, the question is not only if translatewiki is interested but also if the WMF is interested in providing improved security.
Thanks,
     GerardM

Tuesday, April 12, 2011

Bringing a #Toolserver tool to the next level II

The #SVG translate tool is developing nicely; my pet peeve has been sort of solved. It now uses the Toolserver User Screening Control which is a tool that allows for checking if a user exists on a Wiki.

At best TUSC is a crutch;
  • it seems not to be aware of SUL
  • it introduces a new user with a new password
  • it clutters your talk page with some necessary gibberish
  • the upload is done by a bot anyway
The origin of all this is that the Toolserver is not a Wikimedia project with all its save guards. Add to this that while Wikimedia has SUL, it does not provide authentication services for Wikimedia movement projects like Toolserver. When MediaWiki were to support openID, we would not need additional passwords and have implicit authentication outside of the Toolserver.

This software already exists for MediaWiki for years.


The upload functionality however does work. Now for an invitation to do more localisations; maybe the template can provide information to find more untranslated SVG graphics.
Thanks,
       GerardM

Thursday, February 03, 2011

Use #SourceForge with #OpenID

I received an e-mail that passwords at SourceForge may have been compromised. Adequate action was taken because everyone had to reset his or her password.

This little drama does not affect those people who use OpenID for their authentication. When a website's security is compromised, there are no passwords to sniff or find in files when OpenID is used.
Thanks,
      GerardM

Monday, September 27, 2010

#Wikipedia goes #OpenID

The case for OpenID has been made often enough on this blog. Implementing it for the projects of the Wikimedia Foundation only makes sense when both the provider and the user functionality are implemented.

Ryan Lane writes on his blog that he is now a full time Operations Engineer. In the blog he writes several goals that he aims to achieve. Point 4 is the one about OpenID.

If there is one downside to this list, it is its ambition. There are more things that are really needed. One way of reading it is that it is a list of objectives for the Operations department. This means that Ryan will not be the only one caring for these goals.
Thanks,
      GerardM

Tuesday, September 21, 2010

A new #Wikimedia project waiting to happen..

This October will see the beginning of the "Account Creation Improvement Project". I love the premise; "it is the first time we really get into contact with a person and we should do the best we can". In a presentation there is a comparison with the Facebook account creation. It is no surprise that ours is more wordy.

True to form, there are charts that provide some metrics. How many new users for five Wikipedias but as important how many end up editing.


Even at this stage of what looks like a brainstorming phase, there are interesting ideas. The one that is a double edged sword proposes to connect Wikipedia's account to Facebook, YouTube and other social media sites. When this means that the Wikimedia Foundation starts supporting OpenID and these social media sites accept our credentials as well, I could not be more happy.


It would allow websites that are part of the Wikimedia movement (think Wikia, translatewiki.net, Wikihow..) to be connected. I doubt that the commercial social media sites dare to lose control of "their" users and without it being a two way street the privacy issues become overwhelming.

Getting the mix right is important. One of the stronger motivations to contribute to Wikipedia is ideology. Without reciprocal arrangements it will fall foul of what many consider acceptable.
Thanks,
      GerardM

Wednesday, June 09, 2010

Ideatorrent for #MediaWiki ideas

Early on in the #strategy project, there was the idea to make use of an ideatorrent. There were all kinds of reasons why this did not happen at the time including the fact that it did not make use of our SUL. It still does not but it does make use of OpenID a very welcome idea.

I have tried it, I have submitted an idea that is now waiting for moderator approval.


Maybe you want to give it a spin as well. It would be cool because there must be so many ideas that are worth considering.
Thanks,
      GerardM

Saturday, May 29, 2010

Why #Facebook, #Plaxo, #LinkedIn ...

A Facebook friend send me an invitation for new functionality. If anything, it is the last thing I am interested in.. Maybe not, it rates with FarmVille as a time waster.

Actually Facebook itself is very much a timesink. I tried it for some time but now I wish only for some of the nice bits to improve the whole Wiki experience.

I am GerardM some 460 times in the Wikimedia projects, I am registered as GerardM in many Wikia wikis, many other wikis. I wish they all allowed for OpenID so that I could manage my password once and well. I wish for a central place where I can assemble a public profile as well as maintain my private information. Such information could consist of bits and pieces from everywhere; as it is my persona that is fractured in what Facebook, LinkedIn, Google and many others publicly state about me. They mash all this for their private use anyway, why not have me make a mash out of it?

There are also these new functionalities where it makes sense to REALLY restrict who knows or may know... where I am for instance, it is not an invite to be burgled. I do want to control access to the people I trust but I do not care what applications they use, as long as these do not leak.

This is where Facebook has a problem; it has earned its reputation that they are cavalier with other people's data. They are leeches; it is their audacity that makes them "own" the private data of their clients so that they can sell it to their customers.

I would not mind aggravating Facebook's problems by federating information and profiles and only share what needs to be shared when it needs to be shared. Consider a game like Farmville in such a network.. When it is hot, it is available.. you spend your time and money without a Facebook overhead. It is for Facebook to add value and I find it wanting.
Thanks,
     GerardM

Tuesday, November 03, 2009

New at translatewiki.net ...


When Brion Vibber left the Wikimedia Foundation, he joined StatusNet and became their senior architect. Apparently he liked what we do at translatewiki.net because we can now localise the software behind their micro blogging service.

It is quite awesome to have Brion back, it is great to see more relevant applications that we can localise at translatewiki.net. StatusNet makes use of the "gettext" format so we will gain more experience supporting that format. With Brion at the other end, it will take effort but it will go smoothly.

One nice detail; StatusNet supports OpenID..
Thanks,
GerardM

Sunday, November 01, 2009

Support OpenID; a featured proposal


At the strategy Wiki, they asked for proposals. Many proposals were formulated and some of them are good enough to become a Featured Proposal.

I just learned that the "Support OpenID" proposal is featured. That is good news because it may mean that this is considered a worthwhile and doable proposal. The key to this proposal is that the Wikimedia Foundation can be trusted to administer OpenID because it is a staunch defender of privacy.


There are questions;
  • is there a process to select featured proposals
  • is it the working groups who featured them
  • what is the effect of a proposal being featured
Whatever the answers, I am happy; I made this proposal and now that it is featured it is more likely to get attention.
Thanks,
      GerardM

Wednesday, February 25, 2009

OpenID is a good idea, but how to use it really?

At the moment I am testing and documenting the Wikiation Extension Testing Environment (WETE). This means that I find myself installing all kinds of MediaWiki extensions and see to what extend I can install them.

Many of the extensions implement good ideas and particularly those good ideas I feel strongly about, I try to implement with the Wikiation Installer. When I can install them successfully, when the extensions can be tested successfully I can better argue why a particular extension is important.

OpenID is one idea that I think should be supported. I have my OpenID and, I have started to associate my profiles with my OpenID. I thank AboutUS, among others, for making my web presence more secure.
Thanks,
GerardM

Sunday, February 22, 2009

OpenID is a good idea, but how to use it really?

OpenID is a good idea; you log on once and once you are logged on, you are authenticated against your active credentials. The idea is simple and it makes the password hell manageable.

Passwords are a pain because there are too many places where you have to maintain them. When the Wikimedia Foundation introduced Single User Logon, it was great because it replaced 435 websites where I had a password with only one password.

I want to reduce the number of places where I have to enter a password because this provides me with more control over my profile and my security. I would prefer it if I could use my banks strong authentication to authenticate to my OpenID.

The problem is I cannot. I love it when the BBC writes: "Easy login plans gather pace" but for me the reality is different. I do not care that Yahoo, Paypal, IBM, Google are a supplier of OpenID, I want them to accept my credentials when I log on to their website(s).

Support of OpenID means first and foremost that you ACCEPT authentication. What I want is OpenID everywhere including Wikipedia because otherwise it is just a distraction.
Thanks,
GerardM

Wednesday, February 01, 2006

MediaWiki is secure software

MediaWiki, the software behind projects like Wikipedia and Wiktionary is software written with an eye for security. The practices that are employed prove that security is taken seriously. The point is that people do not always understand what security means and what security is provided.

Many of the MediaWiki implementations allow everybody to create and change articles. This is a conscious decision, it is part of the formula and consequently this is not a problem from a security point of view. As a consequence the problem of maintaining quality content and preventing people vandalising the content, is a management problem. The tools to manage this problem are diverse but many tools that are considered security tools are usable.

Often vandals do not know that what they do is useless. Often people add links to all kinds of websites in order to increase their Google-rating. The MediaWiki software indicates to the Google crawler NOT to include external websites for its ratings.

Blocking IP-ranges and users because of persistent vandalism is one. Trusting logged in users more than anonymous users is another. There are many Wikimedia projects and all of them still have at present their own users. In Februari, it is planned to develop single signon for the Wikimedia projects. Single login has been on the wishlist of many of the people who are active on multiple projects.

With single login, in essence a management issue with security implications, it becomes feasible to use this as a stepping stone for the implimentation of security features that help with the management of vandalism.

The feature that I would love best is to differentiate the strength of authentication based on where a user comes from. When a user comes from a school with a history of vandalism, it makes sense not to allow anonymous edits. There are many of these types of soft security measures possible.

On mailing lists about Wikimedia, there was talk about a patch that allows for logging in users who authenticate themselves with OpenID. The interesting thing was that people had two issues with this; first it would not allow me to use my MediaWiki ID as an OpenID. The second is that to some extend OpenID is going to fit into the YADIS framework (Yet Another Decentralized Identity Interoperability System).

Yadis is interesting because it is linked to the eXtensible Resource Identifier or XRI, a standard that is developped by OASIS. It is also linked to the W3C (YASB - yet another standard body :) ).

In the end it comes back to standards; when the WMF would support twoway YADIS authentication, it makes for a VERY relevant implementation of security related functionality. This could provide for better management in the fight against vandalism. It is however important that it is a standard that we provide. That is why I am of the opinion that the WMF should support standards.

Thanks,
GerardM