Page MenuHomePhabricator

2fa reset for MarkAHershberger
Closed, ResolvedPublic

Description

My phone got wet and doesn't work any more. I don't have any 2fa reset tokens.

I've created /home/mah/help.txt.asc in my home directory on bastion.wmflabs.org with the following content:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Help me, Obi-Wan Kenobi. You're my only hope.
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEPO+CYoBtPwtrodvdeVbuR3+QGjAFAlsVQ/UACgkQeVbuR3+Q
GjCofAf/c8RmkD7m7iN7m3RQ4AKlYwmtEQqJvTuJCoJK+yFRZ+MLfVRdXGfAFP17
Xzm0KP+N1mbLllFP0V57itBF/NFQhW7x700wg+8l5mTFMu1qcStg4iT7uNhmhljM
6L8zrfIC7j6hMuBTuGrQhn6cPgaf0rnzI8eUOqTFPDOInvjIIW6V1e73UE6AGK7D
JQ5GMKs6kXu0HPXrrGYxOIUK3GTPUSx1fbL8ToY2HNy3cvtPboMwwxomSiDdKeqD
T9Xekp1omb2xY+zgjdaW7uvl7T2wFAdxh0ZvFFKCUydGH306BGJP83yKmn/fR9ov
AXFA3nQRgFzbSk5/8STFG3lLpjQfjA==
=r29R
-----END PGP SIGNATURE-----

Event Timeline

which 2FA account is this (wiki, phab, something else?)

For the signed message, can you sign something referencing the date and the url of this ticket.

A google hangouts video chat with someone who knows you is also the standard way to identify someone in a situation like this.

wiki and phab.

Now at /home/mah/phab-ticket.txt.asc on bastion:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

https://phabricator.wikimedia.org/T196370 2018-06-04
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEEPO+CYoBtPwtrodvdeVbuR3+QGjAFAlsVZjAACgkQeVbuR3+Q
GjBFVwgAgMDfwfDxwrOefwS71N4DhOYzE3QFSht+kX3mThKhJzhH2uqCmPgXsjFB
pKLSy6CM8WKfX1t0rcaB7Mte7yoJuBRLd2cZ1cViRTpPY2ORnkaUqqjG7q/Js6ff
ThPq+hYkbfa6gS++cpgLrFFk065Gu2V2yfsqRUuBR4dxLk+l8KjlyGMPB7nc+mKC
9N241Bj6AFAlZpwvpXfBVhPhFMoPApR6bpCkiHrssyDlbb3VX84dcSvAdg6+gvYn
ck96GabJJFl+qkk/5m/mGdtaykH3x8i+rq/ValsgrTq59oxRZX/Ef4ILs8fy2Si9
a+cEbsOWTIhefxDd7WPSlyiqwRbGbg==
=nJ3H
-----END PGP SIGNATURE-----

I'll try to get a google hangout going with @Tgr or @cicalese (I would try with you, but I don't have your id on hangouts -- mine is hexmode, if you or anyone else wants to confirm.)

Google's 2fa backup was an sms message.

Confirmed via video chat that @Hexmode is @Hexmode.

Does wiki mean Wikimedia SUL (Wikipedia etc.) or wikitech(/Horizon) or both?

Mentioned in SAL (#wikimedia-operations) [2018-06-04T17:44:46Z] <tgr> disabled SUL+wikitech 2FA for MarkAHershberger (T196370)

I have reset MarkAHershberger and MarkAHershberger. I don't have Phabricator access, someone else will have to do that.

aklapper@phab1001:~$ sudo /srv/phab/phabricator/bin/auth strip --all-types --user Hexmode
Usage Exception: There are no matching factors to strip.

There is no 2FA on that Phab account: https://phabricator.wikimedia.org/people/query/YzCImuDTp7Nc/#R

Ok, SUL is fixed. Wikitech is fixed. All that is left is phabricator.

Ah, sorry!

aklapper@phab1001:~$ sudo /srv/phab/phabricator/bin/auth strip --all-types --user MarkAHershberger
These auth factors will be stripped:
    MarkAHershberger	totp	Mobile Phone App (TOTP)
    Strip these authentication factors? [y/N] y
Stripping authentication factors...
Done.
Vvjjkkii renamed this task from 2fa reset for MarkAHershberger to lobaaaaaaa.Jul 1 2018, 1:06 AM
Vvjjkkii reopened this task as Open.
Vvjjkkii triaged this task as High priority.
Vvjjkkii updated the task description. (Show Details)
Vvjjkkii removed a subscriber: Aklapper.
CommunityTechBot renamed this task from lobaaaaaaa to 2fa reset for MarkAHershberger.Jul 1 2018, 10:22 PM
CommunityTechBot closed this task as Resolved.
CommunityTechBot claimed this task.
CommunityTechBot raised the priority of this task from High to Needs Triage.
CommunityTechBot updated the task description. (Show Details)
CommunityTechBot added a subscriber: Aklapper.