Re: wiki.debian.org password reset

2013-01-09 Thread Steve McIntyre
On Tue, Jan 08, 2013 at 07:53:01PM +, Luca Filipozzi wrote: >On Tue, Jan 08, 2013 at 07:22:21PM +0100, Alexis-Emmanuel Haeringer wrote: >> Hello, >> Maybe I could expect an update on your site please. I was wondering if it >> was possible to NOT to register the IP address in a public way on yo

Re: wiki.debian.org password reset

2013-01-08 Thread Luca Filipozzi
Hi, These are questions for the Debian Wiki Administration Team (carbon copied). I'll let them reply to you. Regards, Luca On Tue, Jan 08, 2013 at 07:22:21PM +0100, Alexis-Emmanuel Haeringer wrote: > Hello, > Maybe I could expect an update on your site please. I was wondering if it > was possi

Re: wiki.debian.org password reset

2013-01-07 Thread Colin Watson
On Mon, Jan 07, 2013 at 10:54:19PM +, Steve McIntyre wrote: > On Mon, Jan 07, 2013 at 09:19:09PM +, Colin Watson wrote: > >On Sun, Jan 06, 2013 at 10:39:31PM +, Luca Filipozzi wrote: > >> Please recall our recent email regarding the moinmoin [1] vulnerability > >> [2] and > >> the pene

Re: wiki.debian.org password reset

2013-01-07 Thread Steve McIntyre
On Mon, Jan 07, 2013 at 09:19:09PM +, Colin Watson wrote: >On Sun, Jan 06, 2013 at 10:39:31PM +, Luca Filipozzi wrote: >> Please recall our recent email regarding the moinmoin [1] vulnerability [2] >> and >> the penetration of Debian's wiki [3]. We have reset all password hashes and >> se

Re: wiki.debian.org password reset

2013-01-07 Thread Colin Watson
On Sun, Jan 06, 2013 at 10:39:31PM +, Luca Filipozzi wrote: > Please recall our recent email regarding the moinmoin [1] vulnerability [2] > and > the penetration of Debian's wiki [3]. We have reset all password hashes and > sent individual notification to all Debian wiki account holders with

Re: wiki.debian.org password reset

2013-01-06 Thread Andrew McGlashan
Hi, On 7/01/2013 1:42 PM, Luca Filipozzi wrote: > On Mon, Jan 07, 2013 at 02:28:20AM +, Luca Filipozzi wrote: >> On Mon, Jan 07, 2013 at 12:57:38PM +1100, Andrew McGlashan wrote: >>> What I want to know is the following >>> >>> Do you perform hardening practices such as described at this p

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Paul Wise
On Mon, Jan 7, 2013 at 9:41 AM, Luca Filipozzi wrote: > OTOH, I'd argue that if one wishes to maintain content at wiki.debian.org, > then > one should understand the basics of PKI. What do you think? Many of the Debian wiki editors are there to translate content to their own language. Some of t

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Paul Wise
On Mon, Jan 7, 2013 at 8:08 AM, Jeremy L. Gaddis wrote: > Thanks, I just reset the password on my account only to realize that > SSL is not being used by default on wiki.d.o. As you found out, there is SSL available but not enforced. I strongly suggest installing xul-ext-https-everywhere and xul

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Jeremy L. Gaddis
* Charles Plessy wrote: > Le Mon, Jan 07, 2013 at 01:41:49AM +, Luca Filipozzi a écrit : > > OTOH, I'd argue that if one wishes to maintain content at wiki.debian.org, > > then > > one should understand the basics of PKI. What do you think? > > how about Debian Single Sign On (https://sso.d

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Jeremy L. Gaddis
* Luca Filipozzi wrote: > On Sun, Jan 06, 2013 at 07:08:08PM -0500, Jeremy L. Gaddis wrote: > > Thanks, I just reset the password on my account only to realize that > > SSL is not being used by default on wiki.d.o. > > Yes. :/ > > > Surely this will be fixed in the very near future? > > DSA and

Re: wiki.debian.org password reset

2013-01-06 Thread Luca Filipozzi
On Mon, Jan 07, 2013 at 02:28:20AM +, Luca Filipozzi wrote: > On Mon, Jan 07, 2013 at 12:57:38PM +1100, Andrew McGlashan wrote: > > What I want to know is the following > > > > Do you perform hardening practices such as described at this page: > > > >http://crackstation.net/hashing-se

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Charles Plessy
Le Mon, Jan 07, 2013 at 01:41:49AM +, Luca Filipozzi a écrit : > > OTOH, I'd argue that if one wishes to maintain content at wiki.debian.org, > then > one should understand the basics of PKI. What do you think? Hi Luca, how about Debian Single Sign On (https://sso.debian.org) ? Have a nic

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Luca Filipozzi
On Sun, Jan 06, 2013 at 07:08:08PM -0500, Jeremy L. Gaddis wrote: > * Luca Filipozzi wrote: > > Please recall our recent email regarding the moinmoin [1] vulnerability [2] > > and > > the penetration of Debian's wiki [3]. We have reset all password hashes and > > sent individual notification to

Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Jeremy L. Gaddis
* Luca Filipozzi wrote: > Please recall our recent email regarding the moinmoin [1] vulnerability [2] > and > the penetration of Debian's wiki [3]. We have reset all password hashes and > sent individual notification to all Debian wiki account holders with > instructions on how to recover (and t