Page MenuHomePhabricator

Add preference to disable auto-creation of accounts with CentralAuth
Open, LowPublic

Description

In order to help alleviate many of the privacy concerns raised in T21161, there should be a preference to disable auto-creation of accounts with CentralAuth.

To maintain the expectation of privacy, it should probably be set to disable auto-creation as the default.

Details

Reference
bz28369

Event Timeline

bzimport raised the priority of this task from to Medium.Nov 21 2014, 11:29 PM
bzimport set Reference to bz28369.
bzimport added a subscriber: Unknown Object (MLST).

bugs wrote:

I would actually suggest enabling auto-creation by default. The defaults should keep the majority of users in mind, and the majority of users would want their accounts created automatically (that's the purpose of the feature in the first place). New users would not care or know that their accounts were automatically created, so they probably wouldn't look for such an option nor would they want to disable it. People who have privacy concerns, likely the minority, are usually very "preference-savvy" and would tend to look for any settings to enable that would increase their privacy.

I agree with Casey.
Moreover, this is currently useless because of bug 20852: if you don't want to autocreate accounts, you'll just avoid to login globally. This silly checkbox on login will be hopefully removed soon; if it's moved to Special:Preferences, though, it would be better to avoid to have multiple preferences about how SUL works (we already have too many preferences).

This depends on having global preferences (although unlike the normal case this would be a prefernce internal to centralauth).

Delaying account creation seems easier to me.

If what we want is a temporary fix, patch the policy.

Nemo_bis lowered the priority of this task from Medium to Low.May 2 2015, 10:00 AM
Nemo_bis set Security to None.
MarcoAurelio changed the task status from Open to Stalled.Sep 19 2015, 4:57 PM
MarcoAurelio subscribed.

Since the bug was reported, several things have changed in Wikimedia. We have now a new privacy policy and terms of use. Also, accounts have been SUL finalised. Is this still required?

I don't know about Mark but I'd be tempted to suggest there may still be an argument for this - I believe what happens is right now accounts can be auto-created (leaving a publicly visible log) by a simple page view (I could be mistaken and it could require logging into the wiki, but I still doubt that's something people would expect to have publicly logged).

Aklapper changed the task status from Stalled to Open.Mar 22 2020, 10:59 PM

In that case, setting task status to open

Since there is already a log entry on loginwiki when an account is created, perhaps run a job similar to @Krinkle's https://meta.wikimedia.org/wiki/User:Krinkle/Tools/Global_SUL to create local accounts on all wmf wikis at the same time? This would remove the aspect of logging when users first visit a wiki, but would expand logging of when their global account was first created

jrbs renamed this task from Add preference to disable auto-creation to Add preference to disable auto-creation of accounts with GlobalAuth.Dec 29 2021, 10:52 AM
JJMC89 renamed this task from Add preference to disable auto-creation of accounts with GlobalAuth to Add preference to disable auto-creation of accounts with CentralAuth.Dec 29 2021, 10:59 AM
JJMC89 updated the task description. (Show Details)