This task serves as a placeholder for #Security-Team specific items to track Randall Scout's onboarding process.
Onboarding buddy: @Catrope
[x] Verify you can log in to okta.wikimedia.org
[x] Verify all relevant ITS accounts have been created (G Suite, metawiki, etc. - metawiki is critical to doing other things)
[x] Set up Slack and have @Rsilvola add you to `@product-security` group and to relevant channels (`#product-safety-and-integrity`, `#talk-to-safety-and-security`, et al)
[x] [[https://www.mediawiki.org/wiki/Phabricator/Help#Creating your account|Create your account in Wikimedia Phabricator]]
[x] ...and [[ https://phabricator.wikimedia.org/settings/panel/external/ | link your ITS created work MediaWiki SUL account to your Phabricator account ]]
[x] [[ https://wikitech.wikimedia.org/wiki/Help:Getting_Started | Create a Wikimedia developer account ]] if you have not yet done so.
[x] ...and [[ https://phabricator.wikimedia.org/settings/panel/external/ | link it to your Phabricator account ]]
[x] Enable 2FA for Okta, MetaWiki, OfficeWiki, Phabricator, GitLab and all other accounts, where possible
[ ] Review WMF-specific / Product-Tech onboarding documentation (see your OfficeWiki onboarding page)
[x] Create a Phabricator ticket to get added to necessary groups Phabricator groups: #WMF-NDA, #acl_security_secteam and #acl_security_team ("Requesting access to <list> as member of the PSI Security Team.") and tag your manager. -- Created T429600-T429601
[x] Create IRC account and ask on team chat to get invited to relevant channels (_security, et al) (Request IRCCloud access from techsupport@)
[x] Set IRC highlight word "secteam" as this is our standard team messaging indicator
[x] [[ https://meta.wikimedia.org/wiki/IRC/Instructions#Register_your_nickname,_identify,_and_enforce | Set enforce for IRC nick ]]
[x] Have @Rsilvola add you to psi-all@, security-team@ and security@ mailing lists
[x] [[ https://lists.wikimedia.org/mailman/listinfo/wikitech-l | Subscribe to the wikitech-l mailing list ]]
[ ] [[ https://lists.wikimedia.org/mailman/listinfo/ops | Request to be subscribed to the private ops-l mailing list via a new Phab task ]] (Requested via this link... but seems stuck... possibly requires NDA - Randall)
[x] Have @Rsilvola add you to the Security Team Google drive
[x] Have @Rsilvola add you to Secteam Google calendars (ST, PSI)
[x] Have @Rsilvola add you to the [[ https://app.asana.com/0/788081631501639/1208942394446003 | Asana Security team ]]. (If you don't have Asana access, contact ITS)
[x] Request to be added to `wmf` ldap group (Use [[ https://idm.wikimedia.org | idm ]])
[x] Request deployment & stats private data access ([[https://wikitech.wikimedia.org/wiki/SRE/Production_access | documentation]]) - https://phabricator.wikimedia.org/T430594
[x] Set up Kerberos creds per T380525#10377682 (new subtask), ] Set up Kerberos creds per T380525#10377682 (new subtask), (example: T381986)(example: T381986) - https://phabricator.wikimedia.org/T430598
[ ] Request access to Gitlab `/repos/security` on team chat
[x] [[ https://phabricator.wikimedia.org/T164290#4046628 | Add wikitech static /etc/hosts entry ]] (**optional**)
[x] Create user page on meta (once ITS creates your meta user account) - example: https://meta.wikimedia.org/wiki/User:SBassett_(WMF) (**optional**)
[x] Update wiki team pages on [[https://office.wikimedia.org/wiki/Wikimedia_Security_Team| officewiki]] and [[https://www.mediawiki.org/wiki/Product_Safety_and_Integrity/Team| mediawiki ]]
[x] Update contact and team info on [[ https://office.wikimedia.org/wiki/Contact_list#Product_Safety_and_Integrity| officewiki ]]
[x] Create an officewiki user page
[x] Review https://www.mediawiki.org/wiki/Security/SOP/Application_Security_Reviews and linked documentation in References section and provide any relevant feedback you may have.
* The tone of the article makes it sounds like we don't want (or just can't/won't) review code. It uses too many words and sounds like a lawyer wrote it. (Also, a lot of passive voice.)
* It's unclear what kind of code the security team *is* looking for.
* It looks like we handled quite a few in the past, but fewer recently. (20 requests in the last year, only 1 for upcoming review). How did this workload feel to the team?
* The last comments on the discussion page were 5 years ago. 10 months since last edit.
* A lot of deep links from here are old, but not badly outdated. (updated a few things along the way.)
[ ] Continue through team resources including on
[ ] [[ https://office.wikimedia.org/wiki/Wikimedia_Security_Team | Security Team pages on officewiki ]]
[ ] [[ https://office.wikimedia.org/wiki/Security/Training/Privacy_Engineering | Privacy Engineering pages on officewiki ]]
[ ] [[ https://www.mediawiki.org/wiki/Security | Security pages mediawiki ]]
[ ] ...and see if there's any relevant documentation creation or cleanup you can take on.