Page MenuHomePhabricator

Phabricator needs to stop allowing other websites to cache content including website
Closed, DeclinedPublic

Description

Steps to reproduce

Which I found by using google for searching something unrelated

Actual results

  • It is also a replica of phabricator.wikimedia.org

Expected results

They should not be able to replicate any data unless you agree to it.

This also puts a security risk on a users account if they login through there by mistake. Also it seems to be a Chinese website spamming.

Event Timeline

That website can probally steal any information that users enter in the login form.

You can't stop that from happening... if you can access it from the browser, you can copy/replicate it...

decline?

Also, that's not a replication of the website. It's a proxy.

Data replication/scraping will happen, because blocking that means blocking an IP, which is easy to get around. So yeah, that'd be declined.

There is discussion (in #wikimedia-operations) about blocking specific referrers (since this just might be a MITM/proxy, I haven't looked closely, tbh).

You can block the domain see https://httpd.apache.org/docs/2.4/rewrite/access.html secition Denying Hosts in a Blacklist

Which would make it a lot harder since they would need to change there domain which would be costly unless they use the free domains such as .tk

I don't see how to technically "stop allowing other websites to cache content". You can also screenscrape any data or use the feed.

Legally speaking, we state that in Wikimedia Phabricator, content is "licensed under Creative Commons Attribution-ShareAlike 3.0 (CC-BY-SA) unless otherwise noted". If the logo on top or other items are considered a Trademark Abuse, https://wikimediafoundation.org/wiki/Trademark_policy#6_Trademark_Misuse should apply?

I don't see how to technically "stop allowing other websites to cache content". You can also screenscrape any data or use the feed.

Legally speaking, we state that in Wikimedia Phabricator, content is "licensed under Creative Commons Attribution-ShareAlike 3.0 (CC-BY-SA) unless otherwise noted". If the logo on top or other items are considered a Trademark Abuse, https://wikimediafoundation.org/wiki/Trademark_policy#6_Trademark_Misuse should apply?

But woulden copying the login page and allow a user to put there username and password constitute a security risk since that is stealing someones data. Even if a user should know the website is fake. Some people can be scammed into entering the details. Plus it has everyones users information.

You can also block access to those websites meaning anyone from that website wont be able to access phabricator unless they change there domain.

We could ask http://www.noip.com/ to ask for the website to be taken down.

I don't see how to technically "stop allowing other websites to cache content". You can also screenscrape any data or use the feed.

Legally speaking, we state that in Wikimedia Phabricator, content is "licensed under Creative Commons Attribution-ShareAlike 3.0 (CC-BY-SA) unless otherwise noted". If the logo on top or other items are considered a Trademark Abuse, https://wikimediafoundation.org/wiki/Trademark_policy#6_Trademark_Misuse should apply?

But woulden copying the login page and allow a user to put there username and password constitute a security risk since that is stealing someones data. Even if a user should know the website is fake. Some people can be scammed into entering the details. Plus it has everyones users information.

We can't police the internet, sadly. There are phishing attempts all the time.

We could ask http://www.noip.com/ to ask for the website to be taken down.

There's hundreds more, and enough who don't care about laws/requests to take down.

It's not being copied, it's a proxy, MITM (Man In The Middle).

@Paladox, you can report trademark abuse here, and we'll investigate: https://meta.wikimedia.org/wiki/Special:Contact/licenseabuse

It appears that this is an anti-censorship web proxy (see here) that will work for any site.

Oh thanks for finding that out I didn't know that.

But seems strange to be coming from china in the English lanaguge.

And it uses http not https.

Nothing we can do here technically that's worth the time.

I came across this strange URL while searching for something on Google.

https://lookup-api.apple.com/phabricator.wikimedia.org/T99174

All the links in the task are prefixed as well. The first link to Meta also partially works.

It looks innocuous, but I thought worth mentioning.