This task serves as a placeholder for Security-Team specific items to track Randall Scout's onboarding process.
Onboarding buddy: @Catrope
- Verify you can log in to okta.wikimedia.org
- Verify all relevant ITS accounts have been created (G Suite, metawiki, etc. - metawiki is critical to doing other things)
- Set up Slack and have @Rsilvola add you to @product-security group and to relevant channels (#product-safety-and-integrity, #talk-to-safety-and-security, et al)
- Create your account in Wikimedia Phabricator
- Create a Wikimedia developer account if you have not yet done so.
- Enable 2FA for Okta, MetaWiki, OfficeWiki, Phabricator, GitLab and all other accounts, where possible
- Review WMF-specific / Product-Tech onboarding documentation (see your OfficeWiki onboarding page)
- Create a Phabricator ticket to get added to necessary groups Phabricator groups: WMF-NDA, acl*security_secteam and acl*security_team ("Requesting access to <list> as member of the PSI Security Team.") and tag your manager. -- Created T429600-T429601
- Create IRC account and ask on team chat to get invited to relevant channels (_security, et al) (Request IRCCloud access from techsupport@)
- Set IRC highlight word "secteam" as this is our standard team messaging indicator
- Set enforce for IRC nick
- Have @Rsilvola add you to psi-all@, security-team@ and security@ mailing lists
- Subscribe to the wikitech-l mailing list
- Request to be subscribed to the private ops-l mailing list via a new Phab task (Requested via this link... but seems stuck... possibly requires NDA - Randall... Update Jun 30, emailed list owner per instructions on mailman page -Randall)
- Have @Rsilvola add you to the Security Team Google drive
- Have @Rsilvola add you to Secteam Google calendars (ST, PSI)
- Have @Rsilvola add you to the Asana Security team. (If you don't have Asana access, contact ITS)
- Request to be added to wmf ldap group (Use idm)
- Request deployment & stats private data access (documentation) - https://phabricator.wikimedia.org/T430594
- Set up Kerberos creds per T380525#10377682 (new subtask), (example: T381986) - https://phabricator.wikimedia.org/T430598
- Request access to Gitlab /repos/security on team chat - Appear to have access already
- Request 1Password access from ITS, and on team chat to get added to the team vault.
- Create user page on meta (once ITS creates your meta user account) - example: https://meta.wikimedia.org/wiki/User:SBassett_(WMF) (optional)
- Update wiki team pages on officewiki and mediawiki
- Update contact and team info on officewiki
- Create an officewiki user page
- Review https://www.mediawiki.org/wiki/Security/SOP/Application_Security_Reviews and linked documentation in References section and provide any relevant feedback you may have.
- The tone of the article makes it sounds like we don't want (or just can't/won't) review code. It uses too many words and sounds like a lawyer wrote it. (Also, a lot of passive voice.)
- It's unclear what kind of code the security team *is* looking for.
- It looks like we handled quite a few in the past, but fewer recently. (20 requests in the last year, only 1 for upcoming review). How did this workload feel to the team?
- The last comments on the discussion page were 5 years ago. 10 months since last edit.
- A lot of deep links from here are old, but not badly outdated. (updated a few things along the way.)
- Continue through team resources including on
- Security Team pages on officewiki
- Privacy Engineering pages on officewiki
- Security pages mediawiki
- ...and see if there's any relevant documentation creation or cleanup you can take on. (Making numerous edits where I see things I can improve... particularly in the MediaWiki docs. A lot of our team materials have warnings at the top that they are out-of-date but seem to be current with explanations I've been given. I think some can be consolidated. Some day before a holiday we might want to work up a plan. I'll keep editing as I come across things.)