Last modified: 2009-05-24 16:29:44 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T20898, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 18898 - Filter out privacy policy bypassinging javascripts
Filter out privacy policy bypassinging javascripts
Status: RESOLVED INVALID
Product: Wikimedia
Classification: Unclassified
General/Unknown (Other open bugs)
unspecified
All All
: Normal enhancement (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2009-05-24 10:53 UTC by folengo
Modified: 2009-05-24 16:29 UTC (History)
1 user (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description folengo 2009-05-24 10:53:10 UTC
This is a Wikimedia projects only suggestion/request. This could remain optional for Mediawiki software used outside the Wikimedia Foundation. 

The Wikimedia Foundation' s privacy policy (1) states that : "Except as described above, Wikimedia policy does not permit distribution of personally identifiable information under any circumstances", meaning that notwithstanding a few exception (like a request from a judge), the Foundation does not transmit the users' IP addresses to third parties. 

At present, when a user reads an image description page on the French language Wikipedia, his or her IP address is being sent to an external website called "pacli.appspot.com". This is connected to the "order a poster print of this picture/Obtenir un poster de cette image" link on the top of the page.

For example, if you access [[:fr:Fichier:Tigeress with cubs in Kanha Tiger reserve.jpg]] with Firefox,  then select  "Page Info / Media" in the tools menu of Firefox, you can see that a file has been downloaded to your computer from the following address : http://pacli.appspot.com/posterstats/tick?page=Fichier:Tigeress_with_cubs_in_Kanha_Tiger_reserve.jpg&position=showLink 

That means that at present, the owner of the pacli.appspot.com website is able to compute a database of all the IP adresses of Wikipedia users reading image description pages on the French Wikipedia. It is very easy  for this owner to know the IP address of the picture's uploader, because the uploader's IP is the first IP address ever accessing that particular picture. As far as I know, nothing prevents that website's owner to further disseminate the collected IP addresses.

Perhaps this problem will be solved by editing the javascipt used on the French Wikipedia. But in order to prevent this sort of situation from occurring on a variety of Wikimedia projects, some sort of filter might be implemented, forbidding this kind of javascript codes from being inserted into Wikimedia projects without users' knowledge.

(1) [[:foundation:Privacy policy]] http://wikimediafoundation.org/wiki/Privacy_policy
Comment 2 Happy-melon 2009-05-24 16:29:32 UTC
This is JavaScript found at [[fr:MediaWiki:Common.js/lienposter]]; it is not a MediaWiki issue.  It is, however, a legitimate concern, I suggest you take it up either on [[fr:MediaWiki talk:Common.js/lienposter]], a more prominent forum on frwiki, or on [[meta:Wikimedia forum]] for a wider audience.  If you feel the situation is serious, you can contact the Foundation Ombudsmen Committee, who can take binding action if the need arises.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links