Wikipedia talk:WikiProject Computer security
Add topic| This is the talk page for discussing WikiProject Computer security and anything related to its purposes and tasks. |
|
| Archives (index): 1, 2, 3, 4, 5Auto-archiving period: 3 months |
| This project page does not require a rating on Wikipedia's content assessment scale. It is of interest to the following WikiProjects: | ||||||||||||||||
| ||||||||||||||||
June 2026 GAN Backlog Drive
[edit]| Good article nominations | June 2026 Backlog Drive | |
| June 2026 Backlog Drive:
Do you want to become more experienced in the GA process?
Interested in taking part? You can sign up here. | |
| Other ways to participate: | |
| You're receiving this message because you have participated in a good article review this year or participated in the previous backlog drive. | |
Requested move at Talk:Trojan horse (computing)#Requested move 30 May 2026
[edit]
There is a requested move discussion at Talk:Trojan horse (computing)#Requested move 30 May 2026 that may be of interest to members of this WikiProject. 🦅White-tailed eagleTalk to the eagleStalking eagle 01:18, 30 May 2026 (UTC)
Rework of project page
[edit]I restructured the project page at Wikipedia:WikiProject Computer security to feature specific todo items, clarify scope, and hide some outdated material. To @DanielPharos or any other members who might still have an eye on things, I'm interested in thoughts, suggestions, and objections. Dreamyshade (talk) 21:55, 14 June 2026 (UTC)
Some articles that need specific work
[edit]A few suggestions:
- The article at hacker has an awkward relationship with security hacker and needs a rewrite - see discussion at Talk:Hacker#Structure
- Computer security gets a lot of views but is not in good shape as a whole; the United States section is outdated
- Social engineering (security) - "Countermeasures" section needs expansion
- Login needs citations and is very short, which provides a good opportunity to integrate material about authentication and authorization, MFA, passkeys, cookies, and related topics in a plain language way
- Password manager needs material about benefits to balance out the emphasis on vulnerabilities; tagged as needing citations since 2013
- Onion routing - tagged as outdated since 2017
- Cryptographic nonce - tagged as needing citations since 2013
- Keychain (software) - also tagged as needing citations since 2013
- Bytecode - tagged as needing citations since 2009
- Pop-up ad - tagged as needing citations since 2008
Dreamyshade (talk) 22:09, 14 June 2026 (UTC)
- I would add that the "hacker has an awkward relationship with security hacker" should probably also include Black hat (computer security), and possibly even Threat actor. I'd also be inclinded to remove bytecode from the security project (and indeed, pop-up ad) Joe (talk) 12:28, 15 June 2026 (UTC)
- Agree that those hacker-related articles need sorting out as a whole, following the guidelines at Wikipedia:Summary style.
- Bytecode and pop-up ad aren't tagged to this WikiProject, but I ran into them while assessing security-related articles. Pop-up ad would be helpful to improve because it's related to adware, scareware, and malvertising (another article that needs work), including technical support scams and ransomware.
- Another open task: cybersecurity engineering should be merged into security engineering (see Wikipedia:Articles for deletion/Cybersecurity engineering). Dreamyshade (talk) 16:20, 17 June 2026 (UTC)
- I took a quick swing at moving some of the content for that merge. It should be a bit easier now. Worth noting that we should also merge in Secure by design (which I've just PROD'd) and maybe Secure coding while we are here? Joe (talk) 08:48, 18 June 2026 (UTC)
- Thanks for starting that merge! I believe secure by design could be a pretty interesting and robust article because of its specific intersection with US and UK government initiatives, especially CISA. I'll write a brief note on the talk page there. Secure coding could also be a good and helpful article if cleaned up, although the scope of that article vs. defensive programming should be clarified. Dreamyshade (talk) 16:24, 18 June 2026 (UTC)
- Curious if you have opinions on how to handle psychology in cybersecurity. The article, as it stands, is WP:OR/WP:SYNTH and fails verification (see Talk:Psychology in cybersecurity). Currently the only article that links there is cyberpsychology. The topic is a plausible article subject (I provided a list of sources on the talk page), but it needs WP:TNT. Options include WP:STUBBIFY or nominate to merge with another article. It's related to usable security, engineering psychology, and social engineering, but none of them seem like a clear merge target. (Courtesy ping to @Kaolay who wrote this article.) Dreamyshade (talk) 19:47, 18 June 2026 (UTC)
- I am cautious about having on-wiki opinions on that one to be honest. Like, yeah, the whole area is *woefully* underserved on Wikipedia, but I'd be citing people I have to sit next to at meetings... Joe (talk) 20:40, 18 June 2026 (UTC)
- BTW, I note from https://projo.toolforge.org/jobs/ea29f?min_pageviews=4000&names_only=1&max_quality=.5&cleanup_only=1&sort=pageviews&dir=desc, that Hacker really is our biggest problem. Do we think we have enough energy to a) open up a merge conversation with Security hacker and b) agree a set of, like, five really serious sources that are high-quality, Post-2020 and that involved editors all have access to, so that those sources can be the backbone of the resulting article? Joe (talk) 20:44, 18 June 2026 (UTC)
- That's funny about psychology in cybersecurity. This field is certainly a small world sometimes.
- Hacker is a really challenging article. I'm up for helping but don't yet have a vision of what it could be, and I'd want to have a clear goal before proposing a merge. Could be helpful to start a rewrite in draftspace, at least an outline? Have you looked at the old versions for inspiration? This version from 2023 is interesting to me. Dreamyshade (talk) 21:00, 18 June 2026 (UTC)
- I think we are in the same place. I think I need a solid set of sources to come to a vision. Maybe we come back to it after clearing up some of the other bits. We've certainly got a lot to do! Joe (talk) 21:10, 18 June 2026 (UTC)
- BTW, I note from https://projo.toolforge.org/jobs/ea29f?min_pageviews=4000&names_only=1&max_quality=.5&cleanup_only=1&sort=pageviews&dir=desc, that Hacker really is our biggest problem. Do we think we have enough energy to a) open up a merge conversation with Security hacker and b) agree a set of, like, five really serious sources that are high-quality, Post-2020 and that involved editors all have access to, so that those sources can be the backbone of the resulting article? Joe (talk) 20:44, 18 June 2026 (UTC)
- I am cautious about having on-wiki opinions on that one to be honest. Like, yeah, the whole area is *woefully* underserved on Wikipedia, but I'd be citing people I have to sit next to at meetings... Joe (talk) 20:40, 18 June 2026 (UTC)
- I took a quick swing at moving some of the content for that merge. It should be a bit easier now. Worth noting that we should also merge in Secure by design (which I've just PROD'd) and maybe Secure coding while we are here? Joe (talk) 08:48, 18 June 2026 (UTC)
Do we have anyone with a particular interest in the ISO27000 standards?
[edit]The ISO/IEC 27000 family and related articles need a lot of work (in the first place, I think most of the articles aren't even tagged for this project). I'm putting it on my list but I'd welcome anyone with an interest in the topic to get in touch Joe (talk) 21:04, 18 June 2026 (UTC)
- I just learned that there's a substantial amount of academic research about implementation and efficacy of the ISO 27000 family: Google Scholar search. I added material from this review article to ISO/IEC 27001. I'm now convinced that Wikipedia editors could do a good thing for the whole industry by incorporating academic research into these articles, so that they aren't just recaps of what ISO says about its own standards.
- Also going to merge ISO/IEC 27001 Lead Implementer and ISO/IEC 27001 Lead Auditor into ISO/IEC 27001. Dreamyshade (talk) 00:18, 29 June 2026 (UTC)
Handling duplicative articles
[edit]@Joereddington I support figuring out how to deal with the many poorly-sourced, vague, and duplicative articles in this topic area, but I support avoiding WP:BATHWATER through applying Wikipedia:Deletion policy#Alternatives to deletion. This includes: "If editing can address all relevant reasons for deletion, this should be done rather than deleting the page." and "If two pages are duplicates or otherwise redundant, one should be merged and redirected to the other, using the most common, or more general page name." I'll write notes on the talk pages for Information security awareness, Software security assurance, and Security kernel. Dreamyshade (talk) 16:11, 19 June 2026 (UTC)
- I think I'm reading this as "Stop PRODing things" and that's fair enough - my thing is just that there are _so_ many articles that are content forks, bording on POV content forks and _so_ few editors... Certainly I'm happy to take more relaxed approach while we work on all the other things to do... Joe (talk) 05:07, 25 June 2026 (UTC)
- Sorry! I find PROD really helpful for articles about obscure companies and products, but I do hesitate on it for terms and topics because the old content just disappears, and it creates broken incoming links unless somebody fixes them. I like to use WP:BLAR (blank-and-redirect) for articles that are too obscure or duplicative to be worth fixing, and that have minimal content worth merging. It's faster than PROD - doesn't require a waiting period or discussion - and it's easy for somebody to reverse in the future if they want to go back and rescue some content or build out the article. I also consider it fine to do a minimal-effort copy-and-paste merge of any potentially-worthwhile parts, without trying to integrate them very well into the target article, with an edit summary that provides credit. Somebody else can fix that up. Dreamyshade (talk) 05:25, 25 June 2026 (UTC)
- Ran into the annoying security awareness cluster again and nominated for merge: Wikipedia:Articles for deletion/Information security awareness.
- Also nominated this redundant article: Wikipedia:Articles for deletion/Automated penetration testing.
- On the other hand, I found a draft for Sectigo that allowed me to split it out from Xcitium (both formerly known as divisions of Comodo), which was overdue! Dreamyshade (talk) 22:50, 1 August 2026 (UTC)
Some potential tasks that intersect with computer science
[edit]- Off-by-one error - 15k views over the past 30 days - tagged as confusing, needs citations
- Race condition - 7.8k views - needs citations
- Time-of-check to time-of-use - 6k views - needs citations
- Segmentation fault - 4.3k views - tagged as needing citations since 2011
- Object-capability model - 2.6k views - tagged as needing citations since 2013
- Reference counting - 2.4k views - tagged as needing citations since 2015
- Pseudonymization - 1.5k views - needs some rewriting and citations
- Type conversion - 1k views - tagged as needing citations since 2011
- Data validation - 1k views - tagged as needing citations since 2016
- Memory protection - tagged as needing citations since 2012
Vital articles
[edit]I noticed there's a list of vital computer security articles (40 articles), and I linked to it from our scope statement. Interestingly, when I use PetScan to make a list of articles at the intersection of Category:All Computer security articles and Category:All Wikipedia vital articles, there are 71 results, since there are security-related articles within other lists of vital articles. I ran that list through Projo and found a couple nice opportunities to improve vital articles: Patch (computing) and Electronic lock both have minimal citations. Dreamyshade (talk) 07:31, 21 June 2026 (UTC)
COI edit request at Prompt injection
[edit]There is a narrow COI edit request at Talk:Prompt injection about attribution wording in the History section; uninvolved review would be appreciated. VarnishDelta742 (talk) 15:05, 26 June 2026 (UTC)
Cybersecurity of Wikipedia
[edit]Requesting feedback on this draft essay (User:Superb Owl/Security) on the state of cybersecurity across Wikimedia projects Superb Owl (talk) 16:41, 26 June 2026 (UTC)
- Interesting! I'd suggest asking the Product Safety and Integrity team for input (on their talk page or similar); I wonder if they already have an internal outline that they could share some version of. Dreamyshade (talk) 17:27, 26 June 2026 (UTC)
- Done! Superb Owl (talk) 18:47, 26 June 2026 (UTC)
Regulatory requirements sections
[edit]This table catalogs 66 articles where @JGellatly added a "Regulatory requirements" section or similar, mostly focused on the HIPAA Security Rule and related US health industry security compliance requirements (which are relevant to his declared COI, although the content does not directly mention or link to his company). The table has 66 articles, including 59 with the content present and 7 where it was reverted.
Like I said at Wikipedia:AI noticeboard#User:Jgellatly (which has some context), I think that some coverage of regulations is reasonable in several of these articles, but the specific additions have issues with original research (cited to primary sources that don't necessarily back up the specific claims of relevance to the subject) and balance (US-centric, and overly specific to HIPAA in most cases). Like, zero trust architecture is tangential to HIPAA. Wikipedia:Summary style means that we don't need to cover the same level of detail about the HIPAA Security Rule in every article that is possibly related. We especially don't need to cover a HIPAA Security Rule notice of proposed rulemaking in so many articles - it's not even a final rule.
For example, even if just talking about healthcare data security regulations, GDPR is equally as important as HIPAA. If trying to briefly cover relevant cyber-security regulations and information security standards in general on computer security articles, I'd say top-tier is GDPR, HIPAA/HITECH, NIST Cybersecurity Framework, and ISO 27001. Second tier might be NIS2 (EU digital infrastructure), Digital Operational Resilience Act (EU financial), Cyber Resilience Act (EU), PCI DSS, and Protection of Personal Information Act, 2013 (South Africa).
Anyway, I'd encourage reviewing the following articles, updating them, and updating the table. Dreamyshade (talk) 05:59, 29 June 2026 (UTC)
- User is @User:Jgellatly (lower case G)--correcting so the courtesy ping will work.
- I support a cleanup here, and suspect that most of these sections should be removed or heavily revised. I don't have the topic expertise to be much help but would be happy to provide an opinion on LLM use in a given article.
- M kuhner (talk) 06:28, 29 June 2026 (UTC)
- I understand that user is now blocked for socking thanks to excellent work by @Dreamyshade and others. Tbh - I don't think anyone needs to be a HIPAA expert - checking references for halluciations goes a long way... Joe (talk) 11:24, 29 June 2026 (UTC)
- The term "topic expertise" is the catch in this project. It is a pretty complicated and very dynamic area. I have not seen a Wiki user who really understands the topic today. About 7 to 10 years ago I understood the general issues quite well. Now I would need to read for a year to catch up. Look at the computer faculty at Berkeley, Stanfotd and UCLA. They are "loaded" with security people, because it is easy to get tenure that way, unlike databases which are stable. So let us set modest goals as we proceed. Yesterday, all my dreams... (talk) 11:03, 6 July 2026 (UTC)
- I would agree with that tier list. I've reviewed a few and added notes to the table. Easy to get distracted fixing other bits of the articles as well :D Joe (talk) 11:12, 29 June 2026 (UTC)
- As best I can discover, the HIPAA tightening proposed 2024 is not finalized as of June 2026. Its inclusion I think therefore violates WP:DUE in just about every article where it appears except HIPAA itself. A single-country regulation that has not even been implemented is a very weak illustration of most of these concepts. (Looking at the one in Attack surface as an example. M kuhner (talk) 13:15, 29 June 2026 (UTC)
- Support a WP:LLMPRV at this point. If anyone would like to salvage their contributions, they can do so, but it's probably best to clear out the slop first, and maybe look for the gold later. guninvalid (talk) 08:06, 30 June 2026 (UTC)
- The more of these I see, the more artificial and inappropriate each one looks. I'm not sure that's entirely fair, but there it is.... Once in a while the first sentence is worth salvaging. Mostly I'm taking them out. M kuhner (talk) 03:16, 2 July 2026 (UTC)
- Hi @User:Dreamyshade, I see you edited the problem section in Supply chain attack--are you satisfied with it? I am 99% out of patience and am generally just taking them out, but if you've checked the citations here, I'll leave it alone. M kuhner (talk) 18:59, 4 July 2026 (UTC)
- @M kuhner Oh thanks for asking! I have not reviewed that one. I went through and fixed syntax problems (missing ref tags) in a lot of these, just so that the content would be readable for further review. Please go ahead as you see fit! Dreamyshade (talk) 21:19, 4 July 2026 (UTC)
- My suggestion: zap them all, 99.9% nonsense. Yesterday, all my dreams... (talk) 10:50, 6 July 2026 (UTC)
- @M kuhner Oh thanks for asking! I have not reviewed that one. I went through and fixed syntax problems (missing ref tags) in a lot of these, just so that the content would be readable for further review. Please go ahead as you see fit! Dreamyshade (talk) 21:19, 4 July 2026 (UTC)
Calling this done and collapsing the table! Big thanks to everyone who helped with this effort despite the dry subject matter. Dreamyshade (talk) 04:14, 11 July 2026 (UTC)
- Woohoo! Great community effort. Also found a couple of articles that could really use some tender loving care (or possibly deletion). M kuhner (talk) 04:19, 11 July 2026 (UTC)
- We sure do have a lot of those in this WikiProject. Please feel free to make a new thread about what you found, on the off chance that this might inspire somebody to deal with them. Dreamyshade (talk) 04:24, 11 July 2026 (UTC)
Table of regulatory sections | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
References
|
What to do and not to do
[edit]If you people want to improve this project there are 4 things to do:
1. Delete the junk, and there is plenty of it. You have made a good start above.
2. Find the key terms and concepts missing from the articles. Multiple ways to do so.
3. Find reasonable RS definitions.
4. Be modest. Know that this is a complicated project.
I leave item 1 alone. For key terms various web searches may be performed and what they have in common may be a key term. Item 3 may appear as a challenge, but not impossible at all. The very best site for this topic is IBM which has pretty good tutorial type articles. So search for computer security at the IBM site and you will get key terms and definitions.
What NOT to do is obvious, avoid AI suggestions. I typed computer security into Grokipedia and it has text such as "The scope of computer security primarily focuses on endpoint devices such as desktops, laptops, servers, and virtual machines, distinguishing it from broader cybersecurity, which extends to networked environments and internet-scale threats" which is, of course, pure nonsense. The source listed for it was a hopeless site. And for Unix Security it has many pages which are copies of old, outdated Unix manuals. Nonsense would be too kind a word for Grokipedia.
Anyway, I do not have much time, so will remain silent for a while. Yesterday, all my dreams... (talk) 12:07, 6 July 2026 (UTC)
Miscellaneous positive updates
[edit]- An article in scope just achieved Good Article status: Appin, an Indian cyber espionage company. Nice work @Brandon.
- Several editors recently improved Jesse Tuttle, an article about a former hacker, which was previously in bad shape (especially for a BLP).
- A few days ago Cybersecurity in popular culture was proposed for deletion because it was likely LLM-generated, but @~2026-38843-54 rescued the article by cutting it down to verifiable material. It's a nice starting point now.
- Melissa (computer virus) and Anna Kournikova (computer virus) recently got overhauled by @AdaCiccone. Very helpful!
Dreamyshade (talk) 04:48, 11 July 2026 (UTC)
- Also the work you guys have been doing cleaning up all the regularity requirements stuff is really impressive. Well done! Joe (talk) 09:56, 11 July 2026 (UTC)
Articles in scope that are tagged for AI cleanup
[edit]Based on this query, processed with Projo to rank in approximate order of pageviews over the past 60 days:
- uBlock Origin – Web browser content blocking extension
- Pegasus (spyware) – Israeli mobile phone spyware
- Privacy law – Area of law
- Kaspersky Lab – Russian multinational cybersecurity and anti-virus provider
- Randomization – Process of making something random
- Entrust – American digital security company
- Microsoft SmartScreen – Microsoft Windows anti-malware system
- Internet security awareness – End-user knowledge of cybersecurity
Tips: Wikipedia:WikiProject AI Cleanup/Guide. Dreamyshade (talk) 07:07, 14 July 2026 (UTC)
- I took a swing at Internet security awareness. Joe (talk) 15:27, 15 July 2026 (UTC)
Unreferenced articles
[edit]For anyone interested in the August 2026 Unreferenced article backlog drive, a few articles in scope with zero references:
- Certified Payment-Card Industry Security Implementer
- Fail-stop
- International Computer Security Association
- Offline private key protocol
- Quarantine (antivirus program) – Act of isolating computer files with viruses
- Security Attribute Modulation Protocol
- Service central de la sécurité des systèmes d'informations
- Web hosting control panel – Web application to manage servers

