8 ms·
Wikipedia globally blocks Apple Private Relay IP ranges from editing
- mistrial9 4y agoWikipedia appears to be living proof that "no good deed goes unpunished" today.. coincidentally on Good Friday in this part of the world
- bannedbybros 4y ago[dead]
- h2odragon 4y ago
- moate 4y agoBetween this and the T-Mobile IP ban, why not just say "Only registered users can edit pages" and be done with it? When you're blocking millions from unregistered editing, just go full tilt.
- drivebycomment 4y agoBecause blocking millions out of billions can still be a reasonable tradeoff, if majority of abuse comes from those millions.
- moate 4y agoMy whole point is "reasonable" is an opinion, and really easy to justify when you're not part of the out-group. The stakes on this (who can edit one website that represents the de-facto knowledge on the internet) are either very high or very low depending on who you ask. The idea that people want to protect that makes sense. What I feel does not make sense is pretending that you're "open" when you stifle millions of (innocent) people. To show the escalation, there are people who would gladly round up millions out of billions to throw in jail or murder for the sake of the safety of the rest of the group. And it would be reasonable to them because it provides the billions with safety. But I think its extremely reasonable for the millions (and in particular the innocent among them) to complain that "this isn't really the open, free, democratic society you promised and maybe you should admit that at this point". TL;dr- Let's stop pretending Wikipedia is open to all and isn't about Wikipedians controlling Wikipedia.
- mardifoufs 4y agoI don't think you realize the amount of vandalism that used to occur before wider IP range bans were put in place. It was just insane, and even now it is sometimes still hard to manage.
- NovemberWhiskey 4y agoIs the premise over at Wikipedia still that an IP address meaningfully identifies a single editor? I think that ship sailed.
- fennecfoxen 4y ago"I cannot stress this enough, and I think it's important to frame this debate correctly when it comes to discussing these blocks. I have made somewhere around 1200 rangeblocks of webhosting providers in the last 5 weeks or so. Not one of them was targeted at a user." — [[User:Blablubbs]] in linked page Wikipedia doesn't block to punish individuals. It blocks to protect itself. There are plenty of ways around most blocks, like simply creating an account.
- jhugo 4y agoAFAIK their policy is to block IPs that "obscure individual users". Another commenter quoted: > Communities typically block edits from IP addresses that obscure individual users. Surely they are aware that this is basically all IPs nowadays...? If that's genuinely the policy then it should be almost equivalent to just requiring an account for all edits, so why not just do that?
- gnfargbl 4y ago> Surely they are aware that this is basically all IPs nowadays...? There are indeed many classes of IP address which multiplex large numbers of users (mobile network exits, VPN exits, ISPs with CGNAT, some corporate web filtering systems, shared public wifi, tor, satellite ground station exits, residential proxies, ...). However, claiming that "basically all" IPs are multiplexed is definitely wrong. A home or small office broadband line typically gets a dynamic-but-ephemerally-unique IP, same as it always did. The effect of IPv6 on this isn't totally clear to me yet. If anything, as IPv6 deployment among ISPs increases, the trend seems to be for less multiplexing and not more.
- jrockway 4y ago
- vmoore 4y agoWhere does this end? Like if the end goal is to block every IP that has a bad reputation score, why not go all in and block every Tor exit IP and every popular VPN exit node too? If you're gonna do something, do it right. That said, there's nothing stopping me hacking a residential router to make my (anonymous) Wikipedia edits.
- criddell 4y agoI think it ends with flipping from default open to default closed. Want to edit Wikipedia? Register and provide your identification.
- Kim_Bruning 4y agoA lot of smaller sites based on wiki-technology do that already. The only reason wikipedia can stay (semi) open is because it has enough people to do regular patrols. As usual it's a small misbehaving minority in the world who make it difficult to Have Nice Things.
- Semaphor 4y ago> why not go all in and block every Tor exit IP and every popular VPN exit node too? If you're gonna do something, do it right. Everything sounds like that is already the case? Is it not? > Communities typically block edits from IP addresses that obscure individual users.
- perryprog 4y agoOpen proxies and Tor exit nodes are very often blocked on sight already on the English Wikipedia; see https://en.wikipedia.org/wiki/Wikipedia:Open_proxies https://en.wikipedia.org/wiki/Wikipedia:Open_proxies.
- kube-system 4y agoA lot of websites do just that.
- sarsway 4y agoIt not going to end. AI will make bots indistinguishable from humans, it's already a problem, and will become a major challenge for online services, the internet, all digital content in general. Proof of Human is something that has to be solved sooner or later. The solution is already being explored, governments will have to issue citizens ID-Tokens on some new blockchain, specifically made for that purpose. That way, all content will be signed, and can be verified as genuine. Complete anonymity will be a thing of the past, but I don't think there's really any other way.
- mfer 4y agoThere are malicious editors out there. For example, someone repeatedly edited the Kubernetes page on Wikipedia to make some changes that were not true and contradicted by the reference that was used. This is just one example. There is a very real problem, even in technical circles, of wrong information being put on there. In this example, it was always by an anonymous account. How does the Wikimedia foundation attempt to handle this? I'm not suggesting I have ideas on what to do. But, this is a real debatable question they have to wrestle with.
- KennyBlanken 4y agoWikipedia is dominated not by the truth, but by two things: - people who treat articles like their own fiefdoms and have obsessively memorized every sentence of policy and can drown an edit they don't like with subjective assertions that an edit violates a particular policy - no-life basement neckbeards who do thousands and thousands of edits on subjects they couldn't possibly have knowledge or experience on and respond instantly to edits to "their" pages Further, in disputes, it essentially comes down to who the rest of the community likes more. The ultimate ad hominem is that some random IP address vs an established 'wikipedian', even if the 'wikipedian' is full of shit? The wikipedian wins. The page for AA is a great example. There's a dude who is completely unhinged and suppresses any negative information about AA, such as the problems with abuse, predation, and sexual assault. Or studies showing poor efficacy compared to science-based treatment. I posted a HN comment as such and was more than a little surprised to come across a reply made barely a few hours later, apparently from that dude, accusing me of being someone he'd had a tiff with on wikipedia. You look at the edit history and his behavior is clearly gatekeeping and enforcing a particular viewpoint. Yet, curiously, he's never been subject to any censure?
- oceanplexian 4y agoWikipedia was awesome some time before 2015/2016. Look up anything even mildly controversial, e.g Gender, Marxism, Capitalism, Globalism, Election Laws, Freedom of Speech, Racism, and then compare 10 years ago to today, using archive.org or by looking at edit history. It feels like a parallel universe, as if history was totally re-written.
- deleted 4y ago[deleted]
- sammy2244 4y ago
- ushakov 4y agocan someone explain why an account isn't a requirement to contribute to Wikipedia?
- Kim_Bruning 4y agoI'll let Aaron Swartz explain. http://www.aaronsw.com/weblog/whowriteswikipedia http://www.aaronsw.com/weblog/whowriteswikipedia It turns out the long tail of anonymous editors is actually a force to be reckoned with. Or was at the time of writing, at least!
- Kinrany 4y agoWhy should it be?
- moate 4y agoBecause that seems to be what the people in charge actually want but are half-assing in the name of optics. IDGAF one way or the other, but if you're going to be banning millions of users from editing via their IP, just commit to saying "We need to be able to identify you vandals, and a user account is the easiest way". You're either true to a mission statement, or you should stop virtue signaling beliefs you don't hold with your mission statement.
- fennecfoxen 4y ago> Because that seems to be what the people in charge actually want but are half-assing in the name of optics. Most certainly not. The people in charge actually want it to be open. You are simply watching those ambitions splinter somewhat as they are beset by the crashing waves of the harsh reality that is the Internet.
- KennyBlanken 4y ago"Want it to be open" but ban mobile network IP addresses, which basically guarantees people below a certain socioeconomic status can't contribute. Loads of people don't have a desktop/laptop, or even internet service at home - just cell service.
- danielktdoranie 4y agoClearly Wikipedia doesn't need my annual donation anymore.
- SheinhardtWigCo 4y agoIndeed they don't: https://upload.wikimedia.org/wikipedia/foundation/1/1e/Wikimedia_Foundation_FY2020-2021_Audit_Report.pdf https://upload.wikimedia.org/wikipedia/foundation/1/1e/Wikim...
- xoa 4y agoStupid and disappointing. Wikipedia and others should move decisively away from using IP addresses as any form of unique ID and address the actual problem in a way that still preserves the option for useful pseudonymity and participation. The basic issue with moderation is the balance between the time/resource cost of moderation and the time/resource cost of evading it times the quantity of bad actor interest. Like if it costs the site two cumulative human minutes and paying for that somehow ($2 at $60/hour, or limited volunteer resources that should still be valued) to make a moderation decision but bad actors can evade in seconds for free then the site will eventually suffer from resource exhaustion if there is enough attacker interest. Conversely if it the cost on the site side is two minutes/$2 but hours/$10+ on the attacker side the site is going to win. At some level of imbalance even the best funded attacker will run out first. IP addresses have been used as an extremely clumsy and increasingly bad proxy for cost, because it takes some level of effort/time/expertise to evade it. But as well as evasion being automatable and growing worse (hard to see how IPv6 won't be the final nail in the coffin there at long last) the side effects against innocent and important usage are very bad too. Some sites use money as a proxy (SomethingAwful's (in)famous 10bux say) and that can work in some niche cases, but is also less than ideal for anything that aspires to be global and widely inclusive given gross inequalities in income. It's impossible in most cases to set a level that isn't simultaneously a blocker for many while not even being a speedbump for others. Instead it's way past time they just attacked the problem directly with some flavor of more formalized cryptographic representation of time. Like just give new users a number to do prime factorization on tuned to a desired target, then sign the result. Ensure they need to do a few hours/days/whatever of crunching (could be graduated, a few hours gets you initial editing rights then you're expected to crunch a bit more over the following months to reach full user level). Scale over time with increasing processing power. Near zero cost to verify. Now even with hacked routers and so on it still always takes some time. For people who don't get banned it's a one-time cost, no problem, amortized over years/decades (Wikipedia is 21 years old now, and there are other older forums still around too). Anyone in the world can participate no money required, just a computer. But for attackers it's a constant burn. And it changes to calculations for things like soft bans too. If you've got a token representing a week's worth of compute built up over a few years and get a 48 hour ban, the incentive against ban evasion is high. It's not possible to build back up another token before the ban expires. It's a shame there isn't some standard for this, no reason in principle a handful of authorities couldn't make chrono-tokens that any site could recognize and keep their own DB of. No permanent identity involved, no law enforcement, always the chance to start fresh, every site can choose whether to worry about other sites' bans or not (or contribute back their own or not). A token need not be tied to any account at all in fact. And no algorithms involved either, humans can take the driver's seat again because the cost equation is firmly back in moderators' favor and they have a dynamic tool to respond to abuse (they can just temporarily increase the time req during an attack surge as high as needed to quench it while not hurting long time users or even stopping new ones from signing up then lower it smoothly back down to let new people start faster as whatever caused the attack winds down). It stinks we're into the 2020s and moderation doesn't really seem much different than the 90s.
- TameAntelope 4y agoI'm finding it a bit hard to follow the structure of this document so forgive me if this is what's being discussed, but wouldn't it make the most sense to block Anonymous editing from Apple Private Relay IP ranges? Once signed in, there is again a way to track the editor, and a way to deal with bad actors.
- brigandish 4y agoI'm regularly blocked from editing because I'm on a VPN. I don't get it, as long as I'm logged in then what's the problem? I'd love to know.
- josephcsible 4y agoThat doesn't work because Wikipedia doesn't store your IP forever if you have an account. If they allowed what you described, then you could make a bunch of accounts with your real IP, wait 90 days for the IP you made it from to be forgotten, then vandalize with them all over VPNs, and they couldn't do anything about it other than reactively blocking each account individually.
- brigandish 4y agoThen grade accounts by more than one metric. I've my account for years and made plenty of edits but it's treated like some newbie account that may be a bot? Because I value my privacy? I use Britannica for anything that isn't celebrity/pop culture based now, I thought Wikipedia had killed off "proper" dictionaries but they're going in reverse. I enjoy the irony of that.
- deleted 4y ago[deleted]
- lotsofpulp 4y agoI assume the website owner intends to want to show ads or track me for marketing or other data harvesting purchases if they try to do further verification than password + 2FA code. They are forcing CAPTCHAs because they want to make it inconvenient enough such that I disable content blockers on their website.
- Shadonototra 4y ago
- mc4ndr3 4y agoEven for authenticated users?
- Kim_Bruning 4y agoShouldn't the link be to https://meta.wikimedia.org/wiki/Apple_iCloud_Private_Relay https://meta.wikimedia.org/wiki/Apple_iCloud_Private_Relay ? Now it's linking to the discussion page. Which is definitely very interesting and useful, but probably not the page that was intended?
- currysausage 4y agoWhile we're talking about Private Relay: with it enabled (on an iPhone), Google won't show me search suggestions. Both google.com and Safari's address/search bar are affected. It's a small feature, but a feature that I rely on often, so it's quite the dealbreaker for me.
- sparqlittlestar 4y agoThanks, related to Safari and privacy: on my iPhone I couldn’t load HN comment pages, unless I turned off”hide ip from trackers and webistes”.
- diebeforei485 4y agoJust require an account for edits, blocking IP addresses is very strange.
- unstatusthequo 4y agoAre they blocking Apple Private Relay IP donations too?