analysis of Debian wiki security breach

2013-01-06 Thread Luca Filipozzi
Dear editors of the Debian wiki, Please recall our recent email regarding the moinmoin [1] vulnerability [2] and the penetration of Debian's wiki [3]. We have reset all password hashes and sent individual notification to all Debian wiki account holders with instructions on how to recover (and the

analysis of Debian wiki security breach

2013-01-06 Thread Luca Filipozzi
Dear editors of the Debian wiki, Please recall our recent email regarding the moinmoin [1] vulnerability [2] and the penetration of Debian's wiki [3]. We have reset all password hashes and sent individual notification to all Debian wiki account holders with instructions on how to recover (and the

Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Jeremy L. Gaddis
* Luca Filipozzi wrote: > Please recall our recent email regarding the moinmoin [1] vulnerability [2] > and > the penetration of Debian's wiki [3]. We have reset all password hashes and > sent individual notification to all Debian wiki account holders with > instructions on how to recover (and t

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Luca Filipozzi
On Sun, Jan 06, 2013 at 07:08:08PM -0500, Jeremy L. Gaddis wrote: > * Luca Filipozzi wrote: > > Please recall our recent email regarding the moinmoin [1] vulnerability [2] > > and > > the penetration of Debian's wiki [3]. We have reset all password hashes and > > sent individual notification to

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Charles Plessy
Le Mon, Jan 07, 2013 at 01:41:49AM +, Luca Filipozzi a écrit : > > OTOH, I'd argue that if one wishes to maintain content at wiki.debian.org, > then > one should understand the basics of PKI. What do you think? Hi Luca, how about Debian Single Sign On (https://sso.debian.org) ? Have a nic

Project Participants page: name errors.

2013-01-06 Thread Tae Wong
Joachim Breiter and Joachim Breitner have the same e-mail address. The correct one is Joachim Breitner. You might need to fix this error. -- To UNSUBSCRIBE, email to debian-www-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http:/

Re: wiki.debian.org password reset

2013-01-06 Thread Luca Filipozzi
On Mon, Jan 07, 2013 at 02:28:20AM +, Luca Filipozzi wrote: > On Mon, Jan 07, 2013 at 12:57:38PM +1100, Andrew McGlashan wrote: > > What I want to know is the following > > > > Do you perform hardening practices such as described at this page: > > > >http://crackstation.net/hashing-se

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Jeremy L. Gaddis
* Luca Filipozzi wrote: > On Sun, Jan 06, 2013 at 07:08:08PM -0500, Jeremy L. Gaddis wrote: > > Thanks, I just reset the password on my account only to realize that > > SSL is not being used by default on wiki.d.o. > > Yes. :/ > > > Surely this will be fixed in the very near future? > > DSA and

Re: Project Participants page: name errors.

2013-01-06 Thread David Prévot
Le 06/01/2013 22:19, Tae Wong a écrit : > You might need to fix this error. As already mentioned countless times to you via this list [0], and via private emails, THIS IS NOT THE PLACE TO MENTION SUCH ISSUE! PLEASE GO AWAY TIA David 0: http://lists.debian.org/debian-www/2012/12/msg0008

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Jeremy L. Gaddis
* Charles Plessy wrote: > Le Mon, Jan 07, 2013 at 01:41:49AM +, Luca Filipozzi a écrit : > > OTOH, I'd argue that if one wishes to maintain content at wiki.debian.org, > > then > > one should understand the basics of PKI. What do you think? > > how about Debian Single Sign On (https://sso.d

Re: Project Participants page: name errors.

2013-01-06 Thread victory
On Mon, 7 Jan 2013 11:19:48 +0900 Tae Wong wrote: > Joachim Breiter and Joachim Breitner have the same e-mail address. The > correct one is Joachim Breitner. You might need to fix this error. As already said repeatedly, www-team do NOT have permissions to fix those, you MUST talk such errors to

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Paul Wise
On Mon, Jan 7, 2013 at 8:08 AM, Jeremy L. Gaddis wrote: > Thanks, I just reset the password on my account only to realize that > SSL is not being used by default on wiki.d.o. As you found out, there is SSL available but not enforced. I strongly suggest installing xul-ext-https-everywhere and xul

Re: Lack of SSL for Debian Wiki login (was: Re: wiki.debian.org password reset)

2013-01-06 Thread Paul Wise
On Mon, Jan 7, 2013 at 9:41 AM, Luca Filipozzi wrote: > OTOH, I'd argue that if one wishes to maintain content at wiki.debian.org, > then > one should understand the basics of PKI. What do you think? Many of the Debian wiki editors are there to translate content to their own language. Some of t

Re: Project Participants page: name errors.

2013-01-06 Thread Tae Wong
As you look, the messages you delete have to be re-created. Chrissie Caulfield is the correct one and Christie Caulfield is the incorrect one. These both have the same e-mail, chris...@debian.org. -- To UNSUBSCRIBE, email to debian-www-requ...@lists.debian.org with a subject of "unsubscribe". Tr

Re: Project Participants page: name errors.

2013-01-06 Thread victory
On Mon, 7 Jan 2013 12:14:16 +0900 Tae Wong wrote: > As you look, the messages you delete have to be re-created. Chrissie > Caulfield is the correct one and Christie Caulfield is the incorrect > one. These both have the same e-mail, chris...@debian.org. As already said repeatedly, www-team do NOT

Re: wiki.debian.org password reset

2013-01-06 Thread Andrew McGlashan
Hi, On 7/01/2013 1:42 PM, Luca Filipozzi wrote: > On Mon, Jan 07, 2013 at 02:28:20AM +, Luca Filipozzi wrote: >> On Mon, Jan 07, 2013 at 12:57:38PM +1100, Andrew McGlashan wrote: >>> What I want to know is the following >>> >>> Do you perform hardening practices such as described at this p