Jump to content

Talk:Product Safety and Integrity/Account Security

Add topic
From mediawiki.org
Latest comment: 6 months ago by Novem Linguae in topic Necessity
Recent changes on our talk pages 
List of abbreviations:
D
Wikidata edit
N
This edit created a new page (also see list of new pages)
m
This is a minor edit
b
This edit was performed by a bot
(±123)
The page size changed by this number of bytes

6 August 2026

      15:08 Deletion log Clump talk contribs changed visibility of a revision on page Talk:Trust and Safety Product/Temporary Accounts: content hidden (Revision spam)
      15:08  Talk:Trust and Safety Product/Temporary Accounts 2 changes hist 0 [~2026-43461-59; Clump]
  m   
15:08 (cur | prev) −169 Clump talk contribs (Reverted edits by ~2026-43461-59 (talk) to last version by Dexbot) Tag: Rollback
      
14:54 (cur | prev) +169 ~2026-43461-59 talk (Google: new section) Tags: Reverted Mobile edit Mobile web edit New topic

Some thoughts

[edit]
  • I oppose the idea of Help:Extension:EmailAuth pressuring wikimedians even deeper into the ass of Gugl, the totalopolist controlling the internet and the real world as well.
  • I also oppose arguments like It is a necessary baseline for the security of Wikipedia and The integrity and reputation of Wikipedia as an encyclopedia written by and for human beings denying the existence of other projects like wiktionary, commons, wikidata and some more.
Taylor 49 (talk) 18:17, 28 November 2025 (UTC)Reply

Necessity

[edit]

I get enabling this as an option, but is there a reason why this is going to be made necessary for an increasing number of users? Does this add extra security relative to, say, rules around the strength of passwords? I don't expect Wikimedia to go for the stupid "at least one special character" nonsense, but there are decent measures of password strength out there. Why not use them?

Yaris678 (talk) 13:21, 28 January 2026 (UTC)Reply

2FA (TOTP type that uses an authenticator app on a smartphone) is more secure than a strong password. You can get trojanned or keylogged or phished by an attacker, and they can steal your password that way, and with TOTP the attacker still probably can't finish logging in since they don't have your smartphone.
I think the benefit vs hassle calculation for 2FA makes sense for certain security-sensitive user groups. Also most wiki-related accounts stay logged in for a long time, which greatly reduces the hassle factor. Looking at an app a couple times a year is pretty low friction.
Requiring special characters is helpful at preventing password crackers and dictionary attacks, but isn't as strong as 2FA. (If we don't require special characters in passwords yet, we probably should for everyone. That has a great benefit vs hassle calculation.)
What both of these security rules have in common is that they completely eliminate entire categories of attacks, which is super good for security. –Novem Linguae (talk) 05:46, 29 January 2026 (UTC)Reply