Last modified: 2014-10-20 05:48:35 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T72910, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 70910 - Logout users with MD5 password hash
Logout users with MD5 password hash
Status: NEW
Product: Wikimedia
Classification: Unclassified
Site requests (Other open bugs)
wmf-deployment
All All
: Low minor (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-09-16 23:23 UTC by Tyler Romeo
Modified: 2014-10-20 05:48 UTC (History)
8 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Tyler Romeo 2014-09-16 23:23:36 UTC
With PBKDF2 being deployed, if and only if it seems to be working OK for a short while, we should reset the user tokens of users with MD5 hashes, thus forcing them to re-login and update their hashes. (We can also do this in batches to avoid a massive number of simultaneous hashing being done.)
Comment 1 Chris Steipp 2014-09-17 00:56:56 UTC
It would be nice if we could wrap them in another hash instead of trying to force a login. I'd rather not have the hash in our DB at all.

From what I remember, there's a reason the script had issues doing that, but I don't remember why..
Comment 2 Kunal Mehta (Legoktm) 2014-10-20 05:48:35 UTC
Is the wrapOldPasswords.php script useful for this purpose?

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links