Page MenuHomePhabricator

Password recovery blocked from the WMF office
Closed, DuplicatePublic

Description

That's just silly.

https://www.mediawiki.org/wiki/Special:PasswordReset

Your IP address is blocked from editing. To prevent abuse, it is not allowed to use password recovery from this IP address.

Event Timeline

Can you let us know what IP you were editing from, So we can look at unblocking it?

If IPs are blocked then blocking password resets from that IP makes sense given the history of abuse there. That said:

The Office IP is blocked to anonymous editing on MW.org, personally I don't think it needs to be and so we could easily just unblock it but even if I think it's unnecessary I can understand why it was done originally. Essentially a staff member a couple years ago got frustrated that there were lots of staff members who were editing logged out making notes or changing project plans without any sign of 'who' they were (and difficult to track down because so may staff members edited from the same IP. I didn't think it was necessary then but certainly not something I cared enough about to stop.

[In the meantime know that it's only a local block, you can reset your IP on any other SUL wiki if you'd like]

Well, it all makes sense historically, and I'm not sure any new feature work is justified. In an ideal world however, it would be possible to prevent anonymous editing from an IP range but treat other types of abuse such as password cracking independently.

I've worked around the problem for now, by resetting my password via phone, but maybe we should keep an eye on how annoying this is when WMF staff change their passwords en masse.

The user account policy requires staff accounts to have various things, it's somewhat pointless if staff can just make paid edits while logged out (as a few people appeared to be doing)