Last modified: 2012-09-20 12:46:02 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T42328, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 40328 - Upgrade visitors' computers running Windows/MSIE 6,7,8 or 9 to a secure browser
Upgrade visitors' computers running Windows/MSIE 6,7,8 or 9 to a secure browser
Status: RESOLVED WONTFIX
Product: Wikimedia
Classification: Unclassified
Site requests (Other open bugs)
unspecified
All All
: Unprioritized enhancement (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2012-09-18 11:35 UTC by Mathias Schindler
Modified: 2012-09-20 12:46 UTC (History)
6 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Mathias Schindler 2012-09-18 11:35:52 UTC
According to a Microsoft Advisory, the browser software "Internet Explorer" allowes remote code execution in almost all currently deployed versions and operating systems. http://technet.microsoft.com/en-us/security/advisory/2757760

This should account for roughly 25% of our traffic at Wikimedia web sites. http://stats.wikimedia.org/wikimedia/squids/SquidReportClients.htm

Couldn't we just upgrade those visitors' machines with a decent reliable browser, such as Firefox or Chrome or Opera, maybe with the help of framework software such as https://community.rapid7.com/community/metasploit/blog/2012/09/17/lets-start-the-week-with-a-new-internet-explorer-0-day-in-metasploit?

If applicable criminal law or established moral or ethical standards do not permit remote software upgrades via this path, we could at least consider displaying a warning for visitors to use one of the suggested strategies to deal with such a major browser security issue.
Comment 1 Andre Klapper 2012-09-20 12:40:23 UTC
This has been discussed several times (last time that I am aware of is http://lists.wikimedia.org/pipermail/wikitech-l/2012-June/061070.html ) and outcome of discussion is that nothing like this is currently planned.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links