Page MenuHomePhabricator

acooper (Andy Cooper)
Disabled

User Details

User Since
Apr 4 2023, 12:52 PM (150 w, 1 d)
Roles
Disabled
LDAP User
Andy Cooper
MediaWiki User
ACooper-WMF [ Global Accounts ]

Recent Activity

Apr 4 2025

acooper updated the task description for T391119: Notify privileged users that do not have an email configured.
Apr 4 2025, 3:41 PM · WMF-General-or-Unknown, MediaWiki-extensions-EmailAuth
acooper updated the task description for T391119: Notify privileged users that do not have an email configured.
Apr 4 2025, 3:41 PM · WMF-General-or-Unknown, MediaWiki-extensions-EmailAuth
acooper updated the task description for T391119: Notify privileged users that do not have an email configured.
Apr 4 2025, 3:40 PM · WMF-General-or-Unknown, MediaWiki-extensions-EmailAuth
acooper updated the task description for T391119: Notify privileged users that do not have an email configured.
Apr 4 2025, 3:39 PM · WMF-General-or-Unknown, MediaWiki-extensions-EmailAuth
acooper updated the task description for T391119: Notify privileged users that do not have an email configured.
Apr 4 2025, 3:39 PM · WMF-General-or-Unknown, MediaWiki-extensions-EmailAuth
acooper created T391119: Notify privileged users that do not have an email configured.
Apr 4 2025, 3:28 PM · WMF-General-or-Unknown, MediaWiki-extensions-EmailAuth

Mar 25 2025

acooper created T389924: Grant Access to logstash-access for acooper.
Mar 25 2025, 8:53 AM · LDAP-Access-Requests, SRE

Mar 24 2025

acooper added a comment to T389843: Grant Access to logstash-access for mstyles and mmartorana.

According to an email that went out logstash access now requires this new process to be followed. Appreciate if this can be handled as a priority as we need it for an ongoing incident.

Mar 24 2025, 6:02 PM · SRE, LDAP-Access-Requests
acooper added a comment to T388891: Decide hCaptcha enterprise trial configuration.

May need enterprise features enabling for secure enclave and proxy.

Mar 24 2025, 11:55 AM · Trust and Safety Product Sprint, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial)
acooper renamed T382148: Enable hCaptcha on test2wiki from Create hCaptcha test wiki to Enable hCaptcha on test wiki.
Mar 24 2025, 11:50 AM · Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), WE4.2 Bot detection (WE4.2 hCaptcha account creation trial)

Mar 21 2025

acooper removed a project from T379177: hCaptcha: Work out how to use returned score rather than just if the captcha was solved: WE4.2 Bot detection (WE4.2 hCaptcha account creation trial).
Mar 21 2025, 2:41 PM · ConfirmEdit (CAPTCHA extension)
acooper changed the status of T378188: Implement secure enclave mode for hCaptcha from Open to In Progress.
Mar 21 2025, 2:36 PM · Product Safety and Integrity (Sprint Apfel Strudel (Sep 29 - Oct 17)), MW-1.45-notes (1.45.0-wmf.18; 2025-09-09), WE4.2 Bot detection (WE4.2 hCaptcha account creation trial), ConfirmEdit (CAPTCHA extension)
acooper renamed T379179: Send hCaptcha API response data to event platform from Send captcha API response data to event logging to Send hCaptcha API response data to event platform.
Mar 21 2025, 2:35 PM · MW-1.45-notes (1.45.0-wmf.16; 2025-08-26), Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), MediaWiki-extensions-Campaigns, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial), Data-Engineering-Radar, MediaWiki-extensions-EventLogging, Data-Engineering, ConfirmEdit (CAPTCHA extension)
acooper changed the status of T388896: Enable Okta for hCaptcha from Open to In Progress.
Mar 21 2025, 2:33 PM · Trust and Safety Product Sprint, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial)

Mar 19 2025

acooper edited projects for T379179: Send hCaptcha API response data to event platform, added: WE4.2 Bot detection (WE4.2 hCaptcha account creation trial); removed WE4.2 Bot detection.
Mar 19 2025, 2:37 PM · MW-1.45-notes (1.45.0-wmf.16; 2025-08-26), Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), MediaWiki-extensions-Campaigns, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial), Data-Engineering-Radar, MediaWiki-extensions-EventLogging, Data-Engineering, ConfirmEdit (CAPTCHA extension)

Mar 14 2025

acooper created T388902: Make hCaptcha proxy URL compatible with MediaWiki CSP.
Mar 14 2025, 4:11 PM · MW-1.45-notes (1.45.0-wmf.7; 2025-06-24), WE4.2 Bot detection (WE4.2 hCaptcha account creation trial)
acooper created T388896: Enable Okta for hCaptcha.
Mar 14 2025, 3:51 PM · Trust and Safety Product Sprint, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial)
acooper added a project to T388891: Decide hCaptcha enterprise trial configuration: WE4.2 Bot detection (WE4.2 hCaptcha account creation trial).
Mar 14 2025, 3:01 PM · Trust and Safety Product Sprint, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial)
acooper updated the task description for T388891: Decide hCaptcha enterprise trial configuration.
Mar 14 2025, 3:01 PM · Trust and Safety Product Sprint, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial)
acooper created T388891: Decide hCaptcha enterprise trial configuration.
Mar 14 2025, 3:00 PM · Trust and Safety Product Sprint, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial)
acooper added a comment to T379177: hCaptcha: Work out how to use returned score rather than just if the captcha was solved.

For this patch, it's for trial implementation purposes and we will set the trust value threshold for zero so it will essentially not block any users.

Mar 14 2025, 2:45 PM · ConfirmEdit (CAPTCHA extension)
acooper edited projects for T382151: Make hcaptcha compatible with NoJS browsers, added: WE4.2 Bot detection (WE4.2 hCaptcha account creation trial); removed WE4.2 Bot detection.
Mar 14 2025, 2:42 PM · Trust and Safety Product Sprint, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial), ConfirmEdit (CAPTCHA extension)
acooper updated the task description for T382151: Make hcaptcha compatible with NoJS browsers.
Mar 14 2025, 2:42 PM · Trust and Safety Product Sprint, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial), ConfirmEdit (CAPTCHA extension)
acooper created T388882: Support selecting hCaptcha or FancyCaptcha based on URL.
Mar 14 2025, 2:38 PM · Trust and Safety Product Sprint, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial)

Mar 5 2025

acooper updated subscribers of T388029: Remove production data access for NDA expired user jdcc.
Mar 5 2025, 5:18 PM · SRE, SRE-Access-Requests
acooper updated subscribers of T388030: Remove production data access for NDA expired user mobrovac.
Mar 5 2025, 5:18 PM · SRE
acooper assigned T388030: Remove production data access for NDA expired user mobrovac to MoritzMuehlenhoff.
Mar 5 2025, 5:17 PM · SRE
acooper assigned T388029: Remove production data access for NDA expired user jdcc to MoritzMuehlenhoff.
Mar 5 2025, 5:17 PM · SRE, SRE-Access-Requests
acooper removed a project from T388034: Remove production data access for NDA expired user aude: WMF-NDA.
Mar 5 2025, 5:12 PM · Data-Platform-SRE (2025.03.01 - 2025.03.21), SRE, SRE-Access-Requests
acooper removed a project from T388029: Remove production data access for NDA expired user jdcc: WMF-NDA.
Mar 5 2025, 5:12 PM · SRE, SRE-Access-Requests
acooper removed a project from T388030: Remove production data access for NDA expired user mobrovac: WMF-NDA.
Mar 5 2025, 5:12 PM · SRE
acooper added a project to T388030: Remove production data access for NDA expired user mobrovac: WMF-NDA.
Mar 5 2025, 5:12 PM · SRE
acooper added a project to T388029: Remove production data access for NDA expired user jdcc: WMF-NDA.
Mar 5 2025, 5:12 PM · SRE, SRE-Access-Requests
acooper added a project to T388034: Remove production data access for NDA expired user aude: WMF-NDA.
Mar 5 2025, 5:11 PM · Data-Platform-SRE (2025.03.01 - 2025.03.21), SRE, SRE-Access-Requests
acooper assigned T388034: Remove production data access for NDA expired user aude to odimitrijevic.
Mar 5 2025, 4:54 PM · Data-Platform-SRE (2025.03.01 - 2025.03.21), SRE, SRE-Access-Requests
acooper added a comment to T388034: Remove production data access for NDA expired user aude.

Update - confirming with staff members whether this access is still required as they may still be actively doing volunteer work, will confirm back, so pause this request for now please

Mar 5 2025, 4:53 PM · Data-Platform-SRE (2025.03.01 - 2025.03.21), SRE, SRE-Access-Requests
acooper created T388034: Remove production data access for NDA expired user aude.
Mar 5 2025, 4:48 PM · Data-Platform-SRE (2025.03.01 - 2025.03.21), SRE, SRE-Access-Requests
acooper renamed T388029: Remove production data access for NDA expired user jdcc from Remove production data access for NDA expired user ori to Remove production data access for NDA expired user jdcc.
Mar 5 2025, 4:47 PM · SRE, SRE-Access-Requests
acooper created T388030: Remove production data access for NDA expired user mobrovac.
Mar 5 2025, 4:43 PM · SRE
acooper created T388029: Remove production data access for NDA expired user jdcc.
Mar 5 2025, 4:43 PM · SRE, SRE-Access-Requests

Feb 27 2025

acooper added a comment to T379010: Design task/job queue for task runs for initial phase of project.

Talking to @sbassett about how to break this down:
API tracks Repositories which are what we want to scan, Tools and ToolsConfig which is how things like semgrep are defined and called (likely will need to be containerized in some way), Tasks which are combination of a repo/branch/files and running the tool against those which produces a task which is a scan of the code and results

Feb 27 2025, 5:03 PM · Patch-For-Review, SecTeam-Processed, Universal Security Dashboard, Security, Security-Team
acooper added a comment to T342468: Craft more mediawiki-specific and php semgrep rule sets.

To split this up (discussion between me and @sbassett)

  1. Research the existing PHP rulesets that are in semgrep - default rules
  2. Research historical vulnerabilities and what would be a good candidate for a new rule - e.g. message API (but in general there's a lot of good coverage there, but would be good to find these issues earlier), permissions layer (however this might be tricky), csrf
  3. Review the rules we already contracted semgrep to write - semgrep functions that are potentially ones that can be used incorrect - can we refine which ones are most effective and less false positives, or use as inspiration for more? https://gitlab.wikimedia.org/repos/security/wikimedia-semgrep-rules especially https://gitlab.wikimedia.org/repos/security/wikimedia-semgrep-rules/-/blob/main/php/mw-php-sec-sniff.yaml
Feb 27 2025, 4:48 PM · Security-Team, GitLab-Application-Security-Pipeline

Feb 5 2025

acooper updated subscribers of T384545: Use of MediaWiki\Block\DatabaseBlock::isExemptedFromAutoblocks was deprecated in MediaWiki 1.44.

I was talking to @kostajh and it seems like StopForumSpam isn't superseded by IPoid because they aren't necessarily the same IPs (although someone would have to verify that), and IPoid isn't yet used for preventing actions although there is an epic for that: https://phabricator.wikimedia.org/T354599

Feb 5 2025, 1:27 PM · SecTeam-Processed, MW-1.44-notes (1.44.0-wmf.14; 2025-01-28), Beta-Cluster-reproducible, MediaWiki-extensions-StopForumSpam
acooper added a comment to T380232: Add app.goacoustic.com to wikipedia.org Content Security Policy (CSP).

Nothing left to do from my end

Feb 5 2025, 11:26 AM · Fundraising Tech - Chaos Crew, Fundraising Tech Chaos Holding Pen, User-greg, fr-acoustic, Wikimedia-Site-requests, Privacy Engineering, Privacy, Fundraising-Backlog, ContentSecurityPolicy

Jan 31 2025

acooper added a comment to T381033: Rate limiting on 'badoath' using $wgRateLimits doesn't work.

We're going to take some more time to understand the potential side effects of this issue and will resume next week.

Jan 31 2025, 5:30 PM · MW-1.44-notes (1.44.0-wmf.19; 2025-03-04), MW-1.43-notes, MW-1.42-notes, MW-1.39-notes, Patch-For-Review, MW-1.43-release, MW-1.42-release, MW-1.39-release, MediaWiki-Platform-Team (Radar), MediaWiki-Engineering, ConfirmEdit (CAPTCHA extension), MediaWiki-User-management, Security-Team, Security, MediaWiki-extensions-OATHAuth
acooper added a comment to T356599: hCaptcha: Implement compatibility with DiscussionTools.

@Esanders just talking about this with Reedy, we think the fix might be similar to how VisualEditor fixed it but we don't really have the javascript expertise to figure it out. Is there any chance we could get this fixed early Q4?

Jan 31 2025, 3:40 PM · Product Safety and Integrity (Sprint Mint Choc Chip Ice Cream (Oct 20 - Nov 7)), WE4.2 Bot detection (WE4.2 hCaptcha editing trial), ConfirmEdit (CAPTCHA extension), affects-Miraheze, DiscussionTools
acooper triaged T356599: hCaptcha: Implement compatibility with DiscussionTools as Medium priority.
Jan 31 2025, 3:37 PM · Product Safety and Integrity (Sprint Mint Choc Chip Ice Cream (Oct 20 - Nov 7)), WE4.2 Bot detection (WE4.2 hCaptcha editing trial), ConfirmEdit (CAPTCHA extension), affects-Miraheze, DiscussionTools
acooper added a comment to T356599: hCaptcha: Implement compatibility with DiscussionTools.

Now we're working on getting into hcaptcha into production for a trial, this bug is becoming more of a blocker because we'd really like to test it on edits. We aren't going to be ready for another quarter but if this was fixed we could do some more interesting experiments to show how well hcaptcha can protect against spam edits.

Jan 31 2025, 3:37 PM · Product Safety and Integrity (Sprint Mint Choc Chip Ice Cream (Oct 20 - Nov 7)), WE4.2 Bot detection (WE4.2 hCaptcha editing trial), ConfirmEdit (CAPTCHA extension), affects-Miraheze, DiscussionTools
acooper added a comment to T381033: Rate limiting on 'badoath' using $wgRateLimits doesn't work.

Just circling back on Scott's comment that the rate limit isn't configured in production, I chatted with @Reedy and its enabled by default without the config set.

Jan 31 2025, 2:54 PM · MW-1.44-notes (1.44.0-wmf.19; 2025-03-04), MW-1.43-notes, MW-1.42-notes, MW-1.39-notes, Patch-For-Review, MW-1.43-release, MW-1.42-release, MW-1.39-release, MediaWiki-Platform-Team (Radar), MediaWiki-Engineering, ConfirmEdit (CAPTCHA extension), MediaWiki-User-management, Security-Team, Security, MediaWiki-extensions-OATHAuth

Jan 22 2025

acooper assigned T342468: Craft more mediawiki-specific and php semgrep rule sets to mmartorana.
Jan 22 2025, 5:13 PM · Security-Team, GitLab-Application-Security-Pipeline
acooper closed T380306: Create basic specification (one-pager) and/or Decision Record Overview documents for USD, a subtask of T371814: [EPIC] Universal Security Dashboard, as Resolved.
Jan 22 2025, 5:12 PM · SecTeam-Processed, Universal Security Dashboard, user-sbassett, Epic, Security, Security-Team
acooper closed T380306: Create basic specification (one-pager) and/or Decision Record Overview documents for USD as Resolved.
Jan 22 2025, 5:12 PM · Universal Security Dashboard, Security, Security-Team

Jan 21 2025

acooper added a comment to T381944: Decide stewardship of the Country and Territory Protection List.

Meeting setup on 22 Jan to discuss this

Jan 21 2025, 4:29 PM · Analytics-Canonical-Data, SecTeam-Processed, WMF-Legal, Security-Team, Movement-Insights

Jan 9 2025

acooper updated subscribers of T380306: Create basic specification (one-pager) and/or Decision Record Overview documents for USD.

I responded to all open feedback, waiting to see if we get more comments over the next week (@Jly not sure if you saw this doc?)

Jan 9 2025, 4:36 PM · Universal Security Dashboard, Security, Security-Team

Dec 19 2024

acooper added a comment to T379190: Integrate HCaptcha into Account Creation flow on Android.

Just circling back on this, the plan is still to implement (all the dependencies for) a limited-rollout of hcaptcha on a trial basis in Q3, for a rollout of the trial in Q4 and an assessment of how effective it was.

Dec 19 2024, 6:49 PM · Wikipedia-iOS-App-Backlog, iOS Sprint 2025: Sprinty McSeddonface in São Paulo, Android Sprint 2025: RZA, Wikipedia-Android-App-Backlog (Android Release - FY2025-26), Patch-For-Review, WE4.2 Bot detection
acooper added a comment to T382501: Evaluate osv-scanner against LibUp.

I changed the langauge and context which is to have an opinion on whether LibUp is not sufficient for security purposes for CI/CD.

Dec 19 2024, 5:16 PM · SecTeam-Processed, Security, Security-Team, Universal Security Dashboard, Epic
acooper updated the task description for T382501: Evaluate osv-scanner against LibUp.
Dec 19 2024, 5:16 PM · SecTeam-Processed, Security, Security-Team, Universal Security Dashboard, Epic
acooper updated the task description for T382525: Investigate suitability of semgrep supply chain (commercial version) for USD.
Dec 19 2024, 5:13 PM · SecTeam-Processed, Security, Security-Team, Universal Security Dashboard, Epic
acooper created T382525: Investigate suitability of semgrep supply chain (commercial version) for USD.
Dec 19 2024, 5:07 PM · SecTeam-Processed, Security, Security-Team, Universal Security Dashboard, Epic
acooper created T382523: Investigate semgrep commercial security rules and recommend configuration for USD.
Dec 19 2024, 4:45 PM · SecTeam-Processed, Security, Security-Team, Universal Security Dashboard, Epic
acooper created T382521: Customize osv-scanner and assess suitable coverage for USD.
Dec 19 2024, 4:39 PM · SecTeam-Processed, Security, Security-Team, Universal Security Dashboard, Epic
acooper triaged T382501: Evaluate osv-scanner against LibUp as Low priority.
Dec 19 2024, 4:33 PM · SecTeam-Processed, Security, Security-Team, Universal Security Dashboard, Epic
acooper assigned T382501: Evaluate osv-scanner against LibUp to Mstyles.
Dec 19 2024, 3:24 PM · SecTeam-Processed, Security, Security-Team, Universal Security Dashboard, Epic
acooper updated the task description for T382501: Evaluate osv-scanner against LibUp.
Dec 19 2024, 3:22 PM · SecTeam-Processed, Security, Security-Team, Universal Security Dashboard, Epic
acooper updated the task description for T382501: Evaluate osv-scanner against LibUp.
Dec 19 2024, 3:21 PM · SecTeam-Processed, Security, Security-Team, Universal Security Dashboard, Epic
acooper created T382501: Evaluate osv-scanner against LibUp.
Dec 19 2024, 3:19 PM · SecTeam-Processed, Security, Security-Team, Universal Security Dashboard, Epic
acooper created T382500: [EPIC] Select and Tune Security Tools for Universal Security Dashboard.
Dec 19 2024, 3:15 PM · SecTeam-Processed, Security, Security-Team, Universal Security Dashboard, Epic

Dec 16 2024

acooper updated subscribers of T381033: Rate limiting on 'badoath' using $wgRateLimits doesn't work.
Dec 16 2024, 5:12 PM · MW-1.44-notes (1.44.0-wmf.19; 2025-03-04), MW-1.43-notes, MW-1.42-notes, MW-1.39-notes, Patch-For-Review, MW-1.43-release, MW-1.42-release, MW-1.39-release, MediaWiki-Platform-Team (Radar), MediaWiki-Engineering, ConfirmEdit (CAPTCHA extension), MediaWiki-User-management, Security-Team, Security, MediaWiki-extensions-OATHAuth
acooper added a comment to T379179: Send hCaptcha API response data to event platform.

We need to do something like this schema: https://schema.wikimedia.org/repositories/secondary/jsonschema/analytics/mediawiki/ip_reputation/score/current.yaml

Dec 16 2024, 11:52 AM · MW-1.45-notes (1.45.0-wmf.16; 2025-08-26), Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), MediaWiki-extensions-Campaigns, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial), Data-Engineering-Radar, MediaWiki-extensions-EventLogging, Data-Engineering, ConfirmEdit (CAPTCHA extension)
acooper added a comment to T381203: hCaptcha: Add a hook to modify score at runtime.

Is this where the request gets blocked if the score if >x? If so we don't need to do that next quarter.

Dec 16 2024, 11:48 AM · WE4.2 Bot detection, ConfirmEdit (CAPTCHA extension)

Dec 13 2024

acooper removed a project from T333770: Evaluate Cloudflare Turnstile as alternative to FancyCaptcha at Wikimedia: WE4.2 Bot detection.
Dec 13 2024, 3:57 PM · Accessibility, ConfirmEdit (CAPTCHA extension), Privacy
acooper removed a project from T378194: hCaptcha: Implement no captcha mode (API/no js usage): WE4.2 Bot detection.
Dec 13 2024, 2:48 PM · ConfirmEdit (CAPTCHA extension)
acooper renamed T382151: Make hcaptcha compatible with NoJS browsers from Add NoJS support for hcaptcha to Make hcaptcha compatible with NoJS browsers.
Dec 13 2024, 2:45 PM · Trust and Safety Product Sprint, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial), ConfirmEdit (CAPTCHA extension)
acooper assigned T382151: Make hcaptcha compatible with NoJS browsers to Reedy.
Dec 13 2024, 2:44 PM · Trust and Safety Product Sprint, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial), ConfirmEdit (CAPTCHA extension)
acooper created T382151: Make hcaptcha compatible with NoJS browsers.
Dec 13 2024, 2:44 PM · Trust and Safety Product Sprint, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial), ConfirmEdit (CAPTCHA extension)
acooper assigned T382150: Add hCaptcha support to API edits to Reedy.
Dec 13 2024, 2:43 PM · WE4.2 Bot detection, ConfirmEdit (CAPTCHA extension)
acooper created T382150: Add hCaptcha support to API edits.
Dec 13 2024, 2:43 PM · WE4.2 Bot detection, ConfirmEdit (CAPTCHA extension)
acooper updated the task description for T378194: hCaptcha: Implement no captcha mode (API/no js usage).
Dec 13 2024, 2:42 PM · ConfirmEdit (CAPTCHA extension)
acooper updated the task description for T382148: Enable hCaptcha on test2wiki.
Dec 13 2024, 2:39 PM · Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), WE4.2 Bot detection (WE4.2 hCaptcha account creation trial)
acooper updated the task description for T382148: Enable hCaptcha on test2wiki.
Dec 13 2024, 2:38 PM · Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), WE4.2 Bot detection (WE4.2 hCaptcha account creation trial)
acooper updated the task description for T382148: Enable hCaptcha on test2wiki.
Dec 13 2024, 2:38 PM · Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), WE4.2 Bot detection (WE4.2 hCaptcha account creation trial)
acooper added a comment to T380625: Augment captcha logging.

Can defer this until spoken to the decision science team for advice

Dec 13 2024, 2:32 PM · WE4.2 Bot detection, ConfirmEdit (CAPTCHA extension)
acooper added a project to T356599: hCaptcha: Implement compatibility with DiscussionTools: WE4.2 Bot detection.
Dec 13 2024, 2:31 PM · Product Safety and Integrity (Sprint Mint Choc Chip Ice Cream (Oct 20 - Nov 7)), WE4.2 Bot detection (WE4.2 hCaptcha editing trial), ConfirmEdit (CAPTCHA extension), affects-Miraheze, DiscussionTools
acooper created T382148: Enable hCaptcha on test2wiki.
Dec 13 2024, 2:30 PM · Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), WE4.2 Bot detection (WE4.2 hCaptcha account creation trial)
acooper updated the task description for T378194: hCaptcha: Implement no captcha mode (API/no js usage).
Dec 13 2024, 2:29 PM · ConfirmEdit (CAPTCHA extension)
acooper updated the task description for T378194: hCaptcha: Implement no captcha mode (API/no js usage).
Dec 13 2024, 2:28 PM · ConfirmEdit (CAPTCHA extension)
acooper added a project to T379179: Send hCaptcha API response data to event platform: WE4.2 Bot detection.
Dec 13 2024, 2:27 PM · MW-1.45-notes (1.45.0-wmf.16; 2025-08-26), Trust and Safety Product Sprint (Sprint Princess Tarta (August 18 - September 5)), MediaWiki-extensions-Campaigns, WE4.2 Bot detection (WE4.2 hCaptcha account creation trial), Data-Engineering-Radar, MediaWiki-extensions-EventLogging, ConfirmEdit (CAPTCHA extension), Data-Engineering
acooper added a project to T380625: Augment captcha logging: WE4.2 Bot detection.
Dec 13 2024, 2:27 PM · WE4.2 Bot detection, ConfirmEdit (CAPTCHA extension)
acooper updated the task description for T378194: hCaptcha: Implement no captcha mode (API/no js usage).
Dec 13 2024, 2:26 PM · ConfirmEdit (CAPTCHA extension)
acooper added a project to T378194: hCaptcha: Implement no captcha mode (API/no js usage): WE4.2 Bot detection.
Dec 13 2024, 2:24 PM · ConfirmEdit (CAPTCHA extension)
acooper added a project to T381203: hCaptcha: Add a hook to modify score at runtime: WE4.2 Bot detection.
Dec 13 2024, 2:23 PM · WE4.2 Bot detection, ConfirmEdit (CAPTCHA extension)
acooper added a project to T379177: hCaptcha: Work out how to use returned score rather than just if the captcha was solved: WE4.2 Bot detection.
Dec 13 2024, 2:23 PM · ConfirmEdit (CAPTCHA extension)
acooper added a comment to T362563: Application Security Review Request : async-profiler (Sampling CPU and HEAP profiler for Java featuring AsyncGetCallTrace + perf_events ).

We are planning to close this task by end of quarter unless we hear back from someone. We didn't get any information on priority or delivery schedule.

Dec 13 2024, 12:54 PM · Discovery-Search (Current work), Data-Platform-SRE (2024.11.30 - 2024.12.20), secscrum, Security, Application Security Reviews

Dec 11 2024

acooper added a comment to T381944: Decide stewardship of the Country and Territory Protection List.

I am following up and seeing whether we can schedule a discussion with the Human Rights team, just a small update.

Dec 11 2024, 11:43 AM · Analytics-Canonical-Data, SecTeam-Processed, WMF-Legal, Security-Team, Movement-Insights

Dec 10 2024

acooper updated the task description for T381430: Offboard Cleo Lemoisson from Security Team.
Dec 10 2024, 6:06 PM · SecTeam-Processed, Security, Security-Team
acooper added a comment to T381430: Offboard Cleo Lemoisson from Security Team.

Confirmed Cleo was removed from security-team@ (I think that must have happened automatically)

Dec 10 2024, 6:05 PM · SecTeam-Processed, Security, Security-Team

Dec 5 2024

acooper added a comment to T380232: Add app.goacoustic.com to wikipedia.org Content Security Policy (CSP).

Apologies I closed the ticket as I thought you forgot, then realized you were awaiting the sprint review meeting to close it, so put it back!

Dec 5 2024, 4:14 PM · Fundraising Tech - Chaos Crew, Fundraising Tech Chaos Holding Pen, User-greg, fr-acoustic, Wikimedia-Site-requests, Privacy Engineering, Privacy, Fundraising-Backlog, ContentSecurityPolicy
acooper added a comment to T380306: Create basic specification (one-pager) and/or Decision Record Overview documents for USD.

Document is ready for review: https://docs.google.com/document/d/1lnHCokqeFKL2Ie4LXensQi3Blla2DswO0HJ1p_qAg8c/edit?usp=sharing

Dec 5 2024, 3:57 PM · Universal Security Dashboard, Security, Security-Team
acooper reopened T380232: Add app.goacoustic.com to wikipedia.org Content Security Policy (CSP) as "Open".
Dec 5 2024, 1:30 PM · Fundraising Tech - Chaos Crew, Fundraising Tech Chaos Holding Pen, User-greg, fr-acoustic, Wikimedia-Site-requests, Privacy Engineering, Privacy, Fundraising-Backlog, ContentSecurityPolicy
acooper closed T380232: Add app.goacoustic.com to wikipedia.org Content Security Policy (CSP) as Resolved.
Dec 5 2024, 1:30 PM · Fundraising Tech - Chaos Crew, Fundraising Tech Chaos Holding Pen, User-greg, fr-acoustic, Wikimedia-Site-requests, Privacy Engineering, Privacy, Fundraising-Backlog, ContentSecurityPolicy