Per discussions on Wikimedia Slack, this would potentially entail:
- Determining a list of eligible Wikimedia users. Everyone? Privileged users?
- How to best support this in addition to other mechanisms such as OATH and WebAuthn.
- Who manages support for this feature, especially if it's rolled out to millions of Wikimedia accounts?
As @Tgr pointed out, it's certainly up for debate as to whether this is a good idea from a security standpoint. (EmailAuth isn't the most secure form of 2fa, but is likely better than nothing).
