User:魔琴/斜坡计划/en

维基百科,自由的百科全书
This is a translation of the parent page: User:魔琴/斜坡计划
Languages: English 中文

The Slope Project (Chinese: 斜坡计划) aims to improve the registration process for Wikipedia users in mainland China. It plans to automatically grant IPBE by verifying the user's region, bringing convenience to mainland China users who edit Wikimedia projects through proxies or other means.

This page traces the progress of relevant discussions and the ideas came up by the community members. You're welcomed to edit this page, participate in the discussions and open new discussions.

Related discussions[编辑]

Basic Idea[编辑]

  1. Page: Provide a special registration page for users in mainland China and guide them to it.
  2. Verification: Verify whether the user is from mainland China.
  3. Authorization: If true, create an account and give it IPBE.

Page[编辑]

Proposal Explanation Problem
Variable IP address HTTPS can be used smoothly? WMF has sufficient IP ranges or manpower?
Toolforge toolforge.org is not blocked toolforge.org may be blocked
Separate domain Cost of purchasing and maintaining domain name (e.g. blockade detection);
Concern for leaking user identity

How to provide the address?

  • The original proposal required users to click "apply" and get the address in their email.
  • Directly add a link on the registration page (MediaWiki:Signupstart).
  • 2604:86C0:A001:6:D833:FBFF:FE98:C900: Provide the link at the your-IP-blocked message.

Verification[编辑]

Proposal Explanation Problem
IP verify The user disconnects the VPN, and the page verifies the location of the IP address.

Hotaru Natsumi: How should we define the permitted IPs? Only the civilian ones like as4134 or all the IPs that feed to mainland China?

Authorization[编辑]

(To be supplemented) Create the account on-site using a bot? Create directly at the WMF level?

Concerns[编辑]

  • Shizhao: China has more than just (4, mentioned in the original proposal) ISPs. Verifacation should base on IP location. (Modified above.)
  • Diskdance: The simpler the process, the better. Payments methods obviously unsuitable.
  • Will it be blocked?
    • Will it result in stricter bans, such as a complete IP ban?
  • The discussion at enwiki suggests a trial run (e.g. 1 year, 10,000 accounts).

Anti-Abuse[编辑]

  • YFdyh000: How to prevent account registration through proxies or zombie networks in mainland China and being abused?
  • LuciferianThomas: The current proposal lacks sufficient consideration for anti-abuse measures. Adequate support should be provided to CUers (and stweards) to obtain raw technical information to confirm that the creators are not known abusers, and then give promission (to the user).
  • 魔琴: On the site, there should be administrators to prevent mass creation and long-term abuse, and to block open proxies.
  • Hotaru Natsumi: Should this portal sync local and global IP blocking lists? How should we handle vandalism that requires chained blocking?

Anti-Blocking[编辑]

  • Original proposal: Send the address via email; use variable IP addresses.
  • 魔琴: Protect the site with CAPTCHA (learned from wikimirror - a mirror site).
  • 魔琴: If using a separate domain name, the domain should not contain the keyword "wikipedia" to prevent interference.
  • Diskdance: Use domain fronting to protect the site and its visitors.
  • 落花有意12138:Non-public obfuscation of service characteristics at irregular intervals.
  • 落花有意12138:Host a service offering portal URL on another site (e.g. toolforge) and encrypt it with a randomly generated token.

WMF?[编辑]

  • Cwek: Opinion of WMF should be sought.
  • YFdyh000: Is WMF needed?
  • Diskdance: Does the Privacy Policy apply?
  • 166.161.149.117: [The project] conflicts with the ideology of WMF.
  • Shizhao: WMF always wants to maintain neutral.

Use third-party websites[编辑]

  • Diskdance: It's not promising to rely on censorable but not yet censored platform (like Toolforge). We should use censorship-resistant platforms, typically to rely on large entities which government cannot easily block. (quoted from phab:T336882#8933517)
  • 虹易: Collaborate with public libraries and universities, hosting the portal on their websites.

Protect user identity[编辑]

The government has access to the data about who visits which website, so by comparing these data and the Wikimedia account registeration logs, they could easily match an account with an individual in real life.

Installing on existing projects[编辑]

If we install the function on existing Wikimedia projects (including Toolforge), it's hard for the government to determine whether visitors are registering or not, making it less easier to link user accounts with individuals.

Domain fronting[编辑]

Domain fronting is a technique for Internet censorship circumvention that uses different domain names in different communication layers of an HTTPS connection to discreetly connect to a different target domain than is discernable to third parties monitoring the requests and connections.

SRE's reply:

  1. Support in principle.
  2. SRE does not have sufficient energy to sustainably confront with the censorship of mainland China. Need heavy dedication to achieve a significant return.
  3. Would require coordinated cooperation of multiple teams.

Problems:

  • Need custom application.
    • Consider integrate the function in the Wikipedia app?

Delaying registration time[编辑]

After a user submits a registration request, the server does not handle it at the time. Instead, It delays the registration for a period of time. That makes it difficult to directly match the visit time with the registration logs.

Forced or optional? Delay period being randomly determined or user-selectable? Can users be allowed to choose to accept the risk and register immediately?

Question: How to handle username collisions?

Temporary Account[编辑]

The portal only registers temporary accounts. Requests for permanent accounts would be sent to IPBE-granting system.

When a user fill the registeration request, the choice of registering a permanent account could be chosen. When the request is submitted, the portal provides a temporary account for the user to edit instantly. (The validity period could be restricted for, e.g. a month, or any other time depending on the backlog of the IPBE-granting system.) At the same time, the portal sent user name and other information to IPBE granters.

Problem: User name of temporary accounts. IPBE-granting system may be needed.

Use third-party websites[编辑]

See above.

See also[编辑]