Page MenuHomePhabricator

Review list of groups for which 2FA is a requirement
Closed, ResolvedPublic

Description

Currently 2FA is required for the following groups:

  • ombudsman [1]
  • sysadmin [1]
  • staff [1]
  • founder [1]
  • global-interface-editor [1]
  • global-sysop [2]
  • interface-admin [3]
  • steward [4]
  • centralnoticeadmin [5]
  • wmf-supportsafety [6]

On the other hand there are at least the following groups that currently do not require 2FA:

  • bureaucrat (can grant anyone including themselves interface-admin, on meta also centralnoticeadmin)
  • checkuser (can perform checks which expose potentially user identifying information)
  • oversighter (can view oversighted revisions which can contain user identifying information)
  • import (can use XML import thus make whatever mess of the wiki like importing edits made in the future and what not)

I do not pretend to have the suggestion list complete. A review of all existing groups should be made, this should include some custom groups, and possibly some of them should have 2FA requirement added.

[1] https://meta.wikimedia.org/wiki/Special_global_permissions
[2] https://meta.wikimedia.org/wiki/Global_sysops
[3] https://meta.wikimedia.org/wiki/Interface_administrators
[4] https://meta.wikimedia.org/wiki/Stewards
[5] https://meta.wikimedia.org/wiki/Meta:Central_notice_administrators
[6] https://meta.wikimedia.org/wiki/Meta:WMF_Support_and_Safety

Event Timeline

sbassett triaged this task as Medium priority.Apr 30 2019, 5:44 PM
sbassett added subscribers: sbassett, Bawolff, Reedy, chasemp.

What has to be done to speed things up? Is there something one can help with? From T242555 I suspect that the bottleneck is the communication burden. Is that the case?

I would assume Trust-and-Safety would need to first prioritize such a project, as it's still sitting within their backlog.

Aklapper added a parent task: Restricted Task.May 17 2025, 9:04 AM
mszwarc claimed this task.
mszwarc subscribed.

Closing this as resolved – as part of the current work on 2FA enforcement from local and global groups, a broader list of 26 groups to require 2FA from was published on: https://meta.wikimedia.org/wiki/Mandatory_two-factor_authentication_for_users_with_some_extended_rights

sbassett changed the visibility from "Custom Policy" to "Public (No Login Required)".
sbassett removed a subscriber: chasemp.