Last modified: 2014-06-18 16:32:16 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T68793, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 66793 - Targeted forced password update
Targeted forced password update
Status: NEW
Product: MediaWiki
Classification: Unclassified
Maintenance scripts (Other open bugs)
unspecified
All All
: Normal enhancement (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-06-18 16:32 UTC by Greg Grossmeier
Modified: 2014-06-18 16:32 UTC (History)
2 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Greg Grossmeier 2014-06-18 16:32:08 UTC
Use case: Some security breach at some other company that results in usernames/emails and passwords and/or hashes exposed. Users tend to reuse passwords across sites, thus, the security of their mediawiki password could also be compromised.

Thus, we could get access to that list of emails and force a password reset on their account on their next login. We'd also probably want the maint script to send the user an email when we do this.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links