* How Wikipedia is sparking a revolution
endif; ?>One of the online lookup resources I am fond of for network-related information is the Wikipedia. This free online encyclopedia has extensive listings of network and security entries that have been helpful to my students and me and that many readers may already be using.
I recently ran across an interesting challenge to the integrity of Wikipedia; perhaps some of you will also be interested in the issue and others will be prompted to examine the resource for yourselves. The case also raises very general questions about the trustworthiness of collaborative documentation efforts on the Web – methods that may soon be applied to commercial software development.
The issue arose when one of the instructors in the Master of Science in Information Assurance program at Norwich University recently came across this article:
Librarian: Don’t use Wikipedia as source
https://www.syracuse.com/news/poststandard/index.ssf?/base/news-0/1093338972139211.xml
The article referenced is by Al Fasoldt of _The Post-Standard_ newspaper. He explained that a school librarian pointed out that Wikipedia https://en.wikipedia.org/wiki/Main_Page > is “not the online version of an established, well-researched traditional encyclopedia. Instead, Wikipedia is a do-it-yourself encyclopedia, without any credentials.” The librarian, Susan Stagnitta, wrote, “Anyone can change the content of an article in the Wikipedia, and there is no editorial review of the content.” Fasoldt then goes on to dismiss the entire Wikipedia as untrustworthy.
Not so fast.
I looked at a range of entries concerning information assurance in the Wikipedia and, although I didn’t agree with everything I read, I certainly found no cause for wholesale rejection of this resource. All the articles had cross-references and many had links to authoritative source materials. The overview article on “computer security” has a brief summary of key issues and includes many internal and external links:
https://en.wikipedia.org/wiki/Computer_security
In addition, although it is true that anyone can modify text, the FAQ has sections that discuss how changes are discussed and accepted or rejected:
https://en.wikipedia.org/wiki/Wikipedia:FAQ
The process is by no means random. Changes are flagged as major or minor; those who are interested in a particular page can find out when it has been changed and exactly what the changes are. Errors and vandalism can be corrected immediately by reversion to a previous state. Vandals can be blocked from further access to editing functions.
I cannot discount Wikipedia simply because it lacks centralized control; neither does the Web as a whole. The Wikipedia project reports that as of early November, the contributors are working on 385,078 articles. It includes facilities for collaboration by people from around the world, including groups for serious discussion of articles, lists of open tasks and specific requests for help in active projects.
From a security standpoint, I have no particular complaints; the resource is at least as good a contribution as many a commercial site I have looked through. As always, _caveat emptor_: translating loosely here, “user beware.”
Far from dismissing this resource, I think it is a useful and exciting venture. My hope is that some among you will be sufficiently pleased to contribute to the work and thus improve a resource that can benefit network and security managers in the long run.
Interestingly, the approach is also being used for software development. A start-up called JotSpot is using the wiki (Hawaiian for “quick”) technology to create applications that users can change, just like Wikipedia pages can be changed: https://www.nwfusion.com/news/2004/1028wikistart.html




