Page MenuHomePhabricator

Make it clear what password is being reset
Closed, ResolvedPublic

Description

As reported by @RoySmith, it's unclear on https://idm.wikimedia.org/wikimedia/password/ as to what password is actually being changed.

A user shouldn't need to know the intricacies of our systems, to know that changing a password for MyUsername here isn't going to change the password on other WMF wikis with the same username

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald Transcript

Just to add some additional flavor here, this all started when I set up my account on the ombuds wiki. Lastpass saw a new password being set and updated its entry, but since wikitech and ombuds are both in the wikimedia domain, it got confused and updated the wrong entry. This was further confused by idp also being in the wikimedia.domain. I realize some of the blame can be placed on lastpass, but not all of it, so the WMF side should do as much as it can to make it clear what is happening.

SLyngshede-WMF changed the task status from Open to In Progress.Feb 5 2024, 3:41 PM
SLyngshede-WMF claimed this task.
SLyngshede-WMF triaged this task as Medium priority.

Change 997484 had a related patch set uploaded (by Slyngshede; author: Slyngshede):

[operations/software/bitu@master] Make it clear what password is being reset

https://gerrit.wikimedia.org/r/997484

I'm not aware of any way to giving password managers hints as to which entries they should update, and which they shouldn't. I'm happy to implement something that will help Lastpass do the right thing, but I can find any suggestions in their documentation.

It is possible to add rules to Lastpass to ensure that wrong sub-domains aren't updated and to let Lastpass know that some domains/sub-domains are equivalent. Sadly it doesn't seem to be possible to push that information... which makes sense for security.

Change 997484 merged by Slyngshede:

[operations/software/bitu@master] Make it clear what password is being reset

https://gerrit.wikimedia.org/r/997484

SLyngshede-WMF moved this task from Pending Release to Resolved on the Bitu board.