Page MenuHomePhabricator

Compile, organize and schedule various Wikimedia security-related user audits
Closed, DeclinedPublic

Description

There are a handful of user audits that the Security-Team should be regularly performing:

  1. T237696: Wikimedia deployers audit
  2. {https://phabricator.wikimedia.org/T252465}
  3. T245526: Audit @wikimedia GitHub org access (2020)
  4. {https://phabricator.wikimedia.org/T225069}
  5. {https://phabricator.wikimedia.org/T263784}
  6. {https://phabricator.wikimedia.org/T273829}
  7. {https://phabricator.wikimedia.org/T263237}
  8. T299400: Audit members of acl*security for more than x duration of no activity (Jan 2022)
  9. T274475: Audit WM maintained libraries for lack of phan
  10. T391150: Audit Phabricator security policies and groups membership

Likely some others too, which we should catalog here and automate/schedule in the simplest way possible.

Event Timeline

sbassett triaged this task as Medium priority.Jun 1 2020, 9:27 PM
sbassett added a project: Security-Team.
sbassett moved this task from Incoming to Back Orders on the Security-Team board.
sbassett updated the task description. (Show Details)

Interesting blog post on further securing Github orgs, which is somewhat related to the Github user audits we've done previously. Not all of these apply to us, of course, and some might translate nicely for Gitlab, as well. https://alsmola.medium.com/securing-github-organizations-9c33c850638

A possibly-helpful tool for github (and gitlab?) audits: https://github.com/scribe-public/gitgat

sbassett claimed this task.
sbassett lowered the priority of this task from Medium to Low.
sbassett moved this task from Back Orders to Our Part Is Done on the Security-Team board.

Declining this for now as most of these should now be tracked via Security-Audits (https://phabricator.wikimedia.org/project/profile/8069/).