3 ms·
Oh, I also got one: https://wiki.archlinux.org/index.php?title=Special:CreateAccount&returnto=Main+page https://wiki.archlinux.org/index.php?title=Special:Creat
by J-Kuhn 4mo ago
Oh, I also got one: https://wiki.archlinux.org/index.php?title=Special:CreateAccount&returnto=Main+page https://wiki.archlinux.org/index.php?title=Special:CreateAcc...
> To protect the wiki against automated account creation, we kindly ask you to answer the question that appears below (more info):
What is the output of: LC_ALL=C pacman -V|sed -r "s#[0-9]+#$(date -u +%m)#g"|base32|head -1
Wait, they really do that...
- alright2565 4mo agoIf you can't understand that command before pasting it in your terminal, then you probably shouldn't be editing the Arch Linux wiki.
- PlasmaPower 4mo agoThey have a similar command for the Arch Linux forum, where beginners are encouraged to ask questions
- spockz 4mo agoMy issue with this style of verification is more that it normalises running commands right in the terminal. Commands that come from place you kind of trust. And poof at some point it will contain some nefarious code. Instead of using a package manager (the curl to bash variant) or running these commands in a container/vm.
- stavros 4mo agoAgreed, this is the first thing I thought of too. Don't teach people to paste unknown commands into their terminal!
- jampekka 4mo agoArch Wiki's core content is instructions of what commands to run right in the terminal.
- __david__ 4mo agoI understand what you’re saying but in this case notice they don’t even mention terminal or command lines. You have to already understand enough context to know what they mean and at that point you should be able to interpret the command itself.
- chrismorgan 4mo agoAlso you need, to some extent, to understand that it’s something to execute in a terminal, because it doesn’t tell you that bit.
- class4behavior 4mo agoThen write and highlight exactly that! ( e.g. "Never copy or execute code you do not understand! This is only for people who already know what will happen! Confirm:") Forget about teaching people bad patterns. It's annoying when others assume everyone experiencing something under the same context and considers the same things as them.
- scratchyone 4mo agoTo be fair, just because you understand the code you see doesn't mean its safe to copy-paste. Many of these compromised sites will show something that appears to be a benign command but will be something entirely different when you copy them. Not good to get people into the habit of copying and running code in their terminal.