Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Wikipedia: Wikitech
Inactive sysops + improving security
 

Index | Next | Previous | View Flat


benapetr at gmail

Apr 4, 2012, 12:43 AM


Views: 367
Permalink
Inactive sysops + improving security

I have seen there is a lot of wikis where people are concerned about
inactive sysops. They managed to set up a strange rule where sysop
rights are removed from inactive users to improve the security.
However the sysops are allowed to request the flag to be restored
anytime. This doesn't improve security even a bit as long as hacker
who would get to some of inactive accounts could just post a request
and get the sysop rights just as if they hacked to active user.

For this reason I think we should create a new extension auto sysop
removal, which would remove the flag from all users who didn't login
to system for some time, and if they logged back, the confirmation
code would be sent to email, so that they could reactivate the sysop
account. This would be much simpler and it would actually make hacking
to sysop accounts much harder. I also believe it would be nice if
system sent an email to holder of account when someone do more than 5
bad login attemps, in order to be warned that someone is likely trying
to compromise their account.

_______________________________________________
Wikitech-l mailing list
Wikitech-l [at] lists
https://lists.wikimedia.org/mailman/listinfo/wikitech-l

Subject User Time
Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 12:43 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 12:54 AM
    Re: Inactive sysops + improving security jayvdb at gmail Apr 4, 2012, 1:15 AM
    Re: Inactive sysops + improving security amir.aharoni at mail Apr 4, 2012, 1:16 AM
    Re: Inactive sysops + improving security p858snake at gmail Apr 4, 2012, 1:19 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 1:25 AM
    Re: Inactive sysops + improving security mwgrunny at gmail Apr 4, 2012, 1:26 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 1:33 AM
    Re: Inactive sysops + improving security morton.thomas at googlemail Apr 4, 2012, 1:39 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 1:47 AM
    Re: Inactive sysops + improving security jayvdb at gmail Apr 4, 2012, 2:03 AM
    Re: Inactive sysops + improving security wikiposta at gmail Apr 4, 2012, 2:09 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 2:12 AM
    Re: Inactive sysops + improving security jayvdb at gmail Apr 4, 2012, 2:16 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 2:21 AM
    Re: Inactive sysops + improving security morton.thomas at googlemail Apr 4, 2012, 2:23 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 2:28 AM
    Re: Inactive sysops + improving security morton.thomas at googlemail Apr 4, 2012, 2:31 AM
    Re: Inactive sysops + improving security jayvdb at gmail Apr 4, 2012, 2:32 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 2:39 AM
    Re: Inactive sysops + improving security morton.thomas at googlemail Apr 4, 2012, 2:48 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 4:31 AM
    Re: Inactive sysops + improving security morton.thomas at googlemail Apr 4, 2012, 4:37 AM
    Re: Inactive sysops + improving security dgerard at gmail Apr 4, 2012, 4:39 AM
    Re: Inactive sysops + improving security lists at nadir-seen-fire Apr 4, 2012, 4:53 AM
        Re: Inactive sysops + improving security emufarmers at gmail Apr 4, 2012, 9:40 AM
    Re: Inactive sysops + improving security lists at nadir-seen-fire Apr 4, 2012, 4:56 AM
    Re: Inactive sysops + improving security innocentkiller at gmail Apr 4, 2012, 5:35 AM
    Re: Inactive sysops + improving security Platonides at gmail Apr 4, 2012, 5:36 AM
        Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 5:33 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 5:38 AM
    Re: Inactive sysops + improving security overlordq at gmail Apr 4, 2012, 7:24 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 7:35 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 7:40 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 7:42 AM
    Re: Inactive sysops + improving security morton.thomas at googlemail Apr 4, 2012, 7:54 AM
    Re: Inactive sysops + improving security morton.thomas at googlemail Apr 4, 2012, 7:56 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 8:33 AM
    Re: Inactive sysops + improving security innocentkiller at gmail Apr 4, 2012, 8:45 AM
    Re: Inactive sysops + improving security benapetr at gmail Apr 4, 2012, 8:48 AM
    Re: Inactive sysops + improving security innocentkiller at gmail Apr 4, 2012, 8:59 AM
    Re: Inactive sysops + improving security agarrett at wikimedia Apr 12, 2012, 7:49 PM
    Re: Inactive sysops + improving security wikiposta at gmail Apr 12, 2012, 10:00 PM
    Re: Inactive sysops + improving security jayvdb at gmail Apr 12, 2012, 10:17 PM
    Re: Inactive sysops + improving security benapetr at gmail Apr 12, 2012, 10:56 PM
    Re: Inactive sysops + improving security jayvdb at gmail Apr 12, 2012, 11:33 PM
    Re: Inactive sysops + improving security benapetr at gmail Apr 12, 2012, 11:52 PM
    Re: Inactive sysops + improving security ariel at wikimedia Apr 13, 2012, 12:06 AM
        Re: Inactive sysops + improving security benapetr at gmail Apr 13, 2012, 12:30 AM
    Re: Inactive sysops + improving security Platonides at gmail Apr 13, 2012, 11:21 AM
    Re: Inactive sysops + improving security dgerard at gmail Apr 13, 2012, 12:17 PM

  Index | Next | Previous | View Flat
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.