Community Wishlist Survey 2019/Anti-harassment/Add an option to require email address and username to reset password
Appearance
From Meta, a Wikimedia project coordination wiki
This is an archived version of this page, as edited by Teseo (talk | contribs) at 14:46, 18 November 2018 (Support proposal). It may differ significantly from the current version .
Add an option to require email address and username to reset password
- Problem: Trolls and LTAs have been knocking Special:PasswordReset with the intention of trolling and (currently) this cannot be prevented. Then I get password reset I did not request. While I know I have secure password (and 2FA) on both my SUL accounts and my email, it's annoying so it'd better if I can just prevent them. It sometimes gives the impression to ordinary users that their account is being compromised, which is not a good UX.
- Who would benefit: Those who gets spammed with false password reset
- Proposed solution: Have a OPT-IN checkbox on Preferences, turned off by default. The checkbox will require you to enter your registered email address AND your username to get a password reset. When you set this up, you know your email address, but trolls don't.
- More comments:
- Phabricator tickets: phab:T145952
- Proposer: — regards, Revi 10:38, 4 November 2018 (UTC) [reply ]
Discussion
- When I can use different mailadresses and I have forgotten which one is necessary for passwort reset? There should be a separate option to send a confirmation mail to the adress used.--Brainswiffer (talk) 07:24, 17 November 2018 (UTC) [reply ]
- That is not part of this vote. — regards, Revi 07:29, 17 November 2018 (UTC) [reply ]
- Currently, you just need to know one of the following: "Email address used for the account" OR "user name", so technically you do not need to know email address to send password reset. But this is being actively abused and one steward I know gets 20 passwords per week (or day, I don't recall). With my proposal, people who voluntarily choose to enforce strict requirement will need to know both "email address used for the account" AND "user name". It's a big difference. Since the change is supposed to be opt-in (you have to click a check box on Preferences, and save it - it is not enabled by default when you register or suddenly forced when you sign in) most ordinary users do not need to take any actions. — regards, Revi 08:08, 17 November 2018 (UTC) [reply ]
- Without going into all reasons why this does not work, this doesn't really work even if it is quite common. A real solution is based upon something an attacker can't know, not something that is just a little bit hard to know. So instead of using a mailaddress as the additional information you use one-time scratch codes, and store them as hash codes on the server. That means only the user knows the real scratch codes, but also that the user requesting the scratch codes must keep them safely. — Jeblad 08:05, 18 November 2018 (UTC) [reply ]
- Given our position on 2FA expansion and number of people losing 2FA & scratch code, that is not a solution as well. — regards, Revi 08:31, 18 November 2018 (UTC) [reply ]
- Sorry, but scratch codes are the only solution that works and can be proven to be secure. Email and SMS is not secure, and using those for reacquiring credentials can be circumvented. The ting you use to identify yourself can not be anything an attacker can know or easily regenerate. That include all kinds of smart questioning, means of communication, etc.
- Note that the present implementation of 2FA at WMFs servers are defacto a single factor login. I leave it to the reader to figure out why.
- Anyhow, there are a lot of information available about this, so it should be unnecessary to argue about it. — Jeblad 09:38, 18 November 2018 (UTC) [reply ]
- Given our position on 2FA expansion and number of people losing 2FA & scratch code, that is not a solution as well. — regards, Revi 08:31, 18 November 2018 (UTC) [reply ]
Voting
- Support Support MER-C (talk) 18:59, 16 November 2018 (UTC) [reply ]
- Support Support James Martindale (talk) 19:22, 16 November 2018 (UTC) [reply ]
- Support Support XXBlackburnXx (talk) 20:15, 16 November 2018 (UTC) [reply ]
- Support Support George Ho (talk) 20:30, 16 November 2018 (UTC) [reply ]
- Support Support This should definitely be added and would be extremely useful to those of us who receive a good amount of password reset emails. Vermont (talk) 21:33, 16 November 2018 (UTC) [reply ]
- Support Support See above. Super Wang on zhwiki (Share your opinions) 23:55, 16 November 2018 (UTC) [reply ]
- Support Support Braveheidi (talk) 01:05, 17 November 2018 (UTC) [reply ]
- Support Support Dolotta (talk) 01:07, 17 November 2018 (UTC) [reply ]
- Support Support New visitor (talk) 02:02, 17 November 2018 (UTC) [reply ]
- Support Support Ellery (talk) 02:38, 17 November 2018 (UTC) [reply ]
- Support Support Liuxinyu970226 (talk) 03:38, 17 November 2018 (UTC) [reply ]
- Support Support Hiàn (talk) 04:44, 17 November 2018 (UTC) [reply ]
- Support Support Andrew J.Kurbiko (talk) 05:15, 17 November 2018 (UTC) [reply ]
- Support Support 4nn1l2 (talk) 05:27, 17 November 2018 (UTC) [reply ]
- Support Support Jimmyshjj (talk) 06:06, 17 November 2018 (UTC) [reply ]
- Support Support Kpgjhpjm (talk) 07:37, 17 November 2018 (UTC) [reply ]
- Support Support Acamicamacaraca (talk) 08:09, 17 November 2018 (UTC) [reply ]
- Support Support –Ammarpad (talk) 08:41, 17 November 2018 (UTC) [reply ]
- Support Support Because there is a possibility that it can be misused with only one element. 水瀬悠志 (talk) 09:32, 17 November 2018 (UTC) [reply ]
- Support Support --Alaa :)..! 10:39, 17 November 2018 (UTC) [reply ]
- Support Support ‐‐1997kB (talk) 11:07, 17 November 2018 (UTC) [reply ]
- Support Support Martin Urbanec (talk) 13:45, 17 November 2018 (UTC) [reply ]
- Support Support Zoranzoki21 (talk) 13:51, 17 November 2018 (UTC) [reply ]
- Support Support Winged Blades of Godric (talk) 16:01, 17 November 2018 (UTC) [reply ]
- Support Support Yilku1 (talk) 16:38, 17 November 2018 (UTC) [reply ]
- Support Support As Im patrolling recent changes on dewiki, I frequently get such mails from IPs who want to say ironically thanks for reverting their vandalism Victor Schmidt (talk) 16:58, 17 November 2018 (UTC) [reply ]
- Support Support Alangi Derick (talk) 17:11, 17 November 2018 (UTC) [reply ]
- Support Support Cabayi (talk) 17:22, 17 November 2018 (UTC) [reply ]
- Support Support Aristeas (talk) 17:31, 17 November 2018 (UTC) [reply ]
- Support Support Amir (talk) 18:49, 17 November 2018 (UTC) [reply ]
- Strong support Strongest possible support Definitely a good idea — pythoncoder (talk | contribs) 19:21, 17 November 2018 (UTC) [reply ]
- Support Support Helland (talk) 19:51, 17 November 2018 (UTC) [reply ]
- Support Support —Thanks for the fish! talk•contribs 19:55, 17 November 2018 (UTC) [reply ]
- Support Support JAn Dudík (talk) 20:00, 17 November 2018 (UTC) [reply ]
- Support Support Yamaha5 (talk) 20:34, 17 November 2018 (UTC) [reply ]
- Support Support Mehdi Talk 20:37, 17 November 2018 (UTC) [reply ]
- Support Support Seems to be a great solution to a seemingly long-standing problem on Wikipedia. SshibumXZ (talk) 21:04, 17 November 2018 (UTC) [reply ]
- Support Support obviously yes Cohaf (talk) 21:09, 17 November 2018 (UTC) [reply ]
- Strong support Strongest possible support Seems like a great idea. Redactyll (talk) 17:31, 17 November 2018 (UTC) [reply ]
- Support Support Bellezzasolo (talk) 21:50, 17 November 2018 (UTC) [reply ]
- Support Support --Hadibe (talk) 22:10, 17 November 2018 (UTC) [reply ]
- Support Support Yoav Rafalin (talk) 00:47, 18 November 2018 (UTC) [reply ]
- Support Support Wunkt2 (talk) 02:47, 18 November 2018 (UTC) [reply ]
- Support Support TonyBallioni (talk) 03:53, 18 November 2018 (UTC) [reply ]
- Support Support The fact that it is opt-in makes it very easy to support this. Mz7 (talk) 03:53, 18 November 2018 (UTC) [reply ]
- Support Support Temp3600 (talk) 05:49, 18 November 2018 (UTC) [reply ]
- Support Support 책읽는달팽 (User talk) 07:47, 18 November 2018 (UTC) [reply ]
- Oppose Oppose Wrong solution. — Jeblad 08:05, 18 November 2018 (UTC) [reply ]
- Support Support Jules78120 (talk) 09:50, 18 November 2018 (UTC) [reply ]
- Support Support فرهنگ2016 (talk) 10:41, 18 November 2018 (UTC) [reply ]
- Support Support Hydriz (talk) 14:25, 18 November 2018 (UTC) [reply ]
- Support Support Massimo Telò (talk) 14:46, 18 November 2018 (UTC) [reply ]