Page MenuHomePhabricator

Logging usernames which are created by common IP & system
Open, Needs TriagePublic

Description

I suggest adding the possibility to automatically identify potential socks when a user creates multiple accounts, all using the same IP and system details.

MediaWiki should log such accounts as "possible sock puppetry" without showing their IP. Users who have proper rights (i.e. sysop or higher) should be able to see these logs

Related Objects

StatusSubtypeAssignedTask
OpenNone

Event Timeline

Yamaha5 created this task.Aug 14 2017, 8:42 AM
Restricted Application added a subscriber: Aklapper. · View Herald TranscriptAug 14 2017, 8:42 AM
Yamaha5 renamed this task from Logging name of users which are created by common IP & system to Logging usernames which are created by common IP & system.Aug 14 2017, 9:38 AM
Yamaha5 updated the task description. (Show Details)
Huji updated the task description. (Show Details)Aug 14 2017, 1:21 PM
Huji added a subscriber: Huji.Aug 14 2017, 1:24 PM

I cleaned up the Task based on offline discussion with @Yamaha5

We already have a feature in AbuseFilter that would allow doing something similar to this (i.e. you can throttle account creation by the same IP). I think what he is asking is to be able to throttle account creation by IP + user-agent. As of now, UA is not used as a variable in AbuseFilter.

And by "logging" what he means is to tag those actions for future review. So do not stop the user when the throttle is kicked, but do tag the action instead.

Huji created subtask Restricted Task.Aug 14 2017, 1:27 PM