[Wikimedia Announcements] Securing access to Wikimedia sites with HTTPS

2015-06-12 Thread Juliet Barbara
The Wikimedia Foundation is pleased to announce that we have begun the
transition of the Wikimedia projects and sites to the secure HTTPS
protocol. You may have seen our blog post from this morning; it has also
been posted to relevant Village Pumps (Technical).

This post is available online here:
https://blog.wikimedia.org/2015/06/12/securing-wikimedia-sites-with-https/

Securing access to Wikimedia sites with HTTPS

BY YANA WELINDER https://blog.wikimedia.org/author/ywelinder/, VICTORIA
BARANETSKY https://blog.wikimedia.org/author/victoria-baranetsky/ AND BRANDON
BLACK https://blog.wikimedia.org/author/brandon-black/ ON JUNE 12TH


To be truly free, access to knowledge must be secure and uncensored. At the
Wikimedia Foundation, we believe that you should be able to use Wikipedia
and the Wikimedia sites without sacrificing privacy or safety.

Today, we’re happy to announce that we are in the process of implementing
HTTPS https://en.wikipedia.org/wiki/HTTPS to encrypt all Wikimedia
traffic. We will also use HTTP Strict Transport Security
https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security (HSTS) to
protect against efforts to ‘break’ HTTPS and intercept traffic. With this
change, the nearly half a billion people who rely on Wikipedia and its
sister projects every month will be able to share in the world’s knowledge
more securely.

The HTTPS protocol creates an encrypted connection between your computer
and Wikimedia sites to ensure the security and integrity of data you
transmit. Encryption makes it more difficult for governments and other
third parties to monitor your traffic. It also makes it harder for Internet
Service Providers (ISPs) to censor access to specific Wikipedia articles
and other information.

HTTPS is not new to Wikimedia sites. Since 2011, we have been working on
establishing the infrastructure and technical requirements, and
understanding the policy and community implications of HTTPS for all
Wikimedia traffic, with the ultimate goal of making it available to all
users. In fact, for the past four years
https://blog.wikimedia.org/2011/10/03/native-https-support-enabled-for-all-wikimedia-foundation-wikis/,
Wikimedia users could access our sites with HTTPS manually, through HTTPS
Everywhere https://www.eff.org/https-everywhere, and when directed to our
sites from major search engines. Additionally, all logged in users
https://blog.wikimedia.org/2013/08/28/https-default-logged-in-users-wikimedia-sites/
have been accessing via HTTPS since 2013.

Over the last few years, increasing concerns about government surveillance
prompted members of the Wikimedia community to push
https://blog.wikimedia.org/2013/08/01/future-https-wikimedia-projects/
for more broad protection through HTTPS. We agreed, and made this
transition a priority for our policy and engineering teams.


We believe encryption makes the web stronger for everyone. In a world where
mass surveillance has become a serious threat to intellectual freedom,
secure connections are essential for protecting users around the world.
Without encryption, governments can more easily surveil sensitive
information, creating a chilling effect, and deterring participation, or in
extreme cases they can isolate or discipline citizens. Accounts may also be
hijacked, pages may be censored, other security flaws could expose
sensitive user information and communications. Because of these
circumstances, we believe that the time for HTTPS for all Wikimedia traffic
is now. We encourage others to join us as we move forward with this
commitment.

The technical challenges of migrating to HTTPS

HTTPS migration for one of the world’s most popular websites can be
complicated. For us, this process began years ago and involved teams from
across the Wikimedia Foundation. Our engineering team has been driving this
transition, working hard to improve our sites’ HTTPS performance, prepare
our infrastructure to handle the transition, and ultimately manage the
implementation.

Our first steps involved improving our infrastructure and code base so we
could support HTTPS. We also significantly expanded and updated our server
hardware. Since we don’t employ third party content delivery systems, we
had to manage this process for our entire infrastructure stack in-house.

HTTPS may also have performance implications for users, particularly our
many users accessing Wikimedia sites from countries or networks with poor
technical infrastructure. We’ve been carefully calibrating our HTTPS
configuration to minimize negative impacts related to latency, page load
times, and user experience. This was an iterative process that relied on
industry standards, a large amount of testing, and our own experience
running the Wikimedia sites.

Throughout this process, we have carefully considered how HTTPS affects all
of our users. People around the world access Wikimedia sites from a
diversity of devices, with varying levels of connectivity and freedom of
information. Although we have 

[Wikimedia Announcements] This week on the Wikimedia Blog

2015-06-12 Thread Fabrice Florin
Hi folks,

Here are some of the stories featured this week on the Wikimedia Blog:

• Securing access to Wikimedia sites with HTTPS
https://blog.wikimedia.org/2015/06/12/securing-wikimedia-sites-with-https/

* Wikimedia Foundation Board election results are in
https://blog.wikimedia.org/2015/06/05/board-election-results/

• How the Wikimedia Foundation Board elections are organized
https://blog.wikimedia.org/2015/06/10/how-board-elections-are-organized/

* How to join a Wikipedia meetup near you (VIDEO)
https://blog.wikimedia.org/2015/06/05/wikipedia-meetups/

Note: You can also view the meetup video on YouTube:
https://www.youtube.com/watch?v=a5uZvTHQuhE

• Over 5,000 new articles created with the Content Translation tool
https://blog.wikimedia.org/2015/06/09/content-translation-tool/

• Open Badges for editor retention
https://blog.wikimedia.org/2015/06/11/open-badges/

• Evaluation helps Wikimedia leaders learn together
https://blog.wikimedia.org/2015/06/09/evaluation-helps-leaders-learn-together/

More stories on the Wikimedia Blog:
https://blog.wikimedia.org/


Enjoy,


Fabrice


___

Fabrice Florin
Movement Communications Manager
Wikimedia Foundation

https://en.wikipedia.org/wiki/User:Fabrice_Florin_(WMF)
___
Please note: all replies sent to this mailing list will be immediately directed 
to Wikimedia-l, the public mailing list of the Wikimedia community. For more 
information about Wikimedia-l:
https://lists.wikimedia.org/mailman/listinfo/wikimedia-l
___
WikimediaAnnounce-l mailing list
WikimediaAnnounce-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikimediaannounce-l