Page MenuHomePhabricator

Please remove an MFA factor from my Phabricator account
Closed, ResolvedPublic

Description

For security reasons, I set up MFA on this account on Sunday. Unfortunately, I was not aware that all MFA factors had to be provided to log in, and thought only one was sufficient, like it is the case with other services like Github. I now realized that the second factor I registered using Dashlane was not saved in the Dashlane app (I likely forgot to save it after setting it up). I still have access to the first factor I registered.
Would it be possible to remove this entry from my account?

image.png (1,656×51 px, 8 KB)

If that helps something, the ID of it shown in the edit URL is 1449.

Event Timeline

Hi, uh I once also ran into setting up two MFA factors... I am going to file an upstream ticket to improve the UI to make this clearer.

These reset requests are always a bit tricky to verify. In an ideal world this would be a video call with three people if anyone knows how you look like? :-/
(Or sharing your phrase for your Committed Identity on https://meta.wikimedia.org/wiki/User:SomeRandomDeveloper in a private Paste only viewable for you and me but that one only got added yesterday so it's too fresh per guidelines).

Does the Security-Team have any further recommendations how to handle this (as I expect an increased number of 2FA reset requests coming in due to improved security instructions)?

Hi, thank you for the quick response. Unfortunately, nobody in the MW community knows how I look like, because I am very careful about sharing my real-life identity for privacy reasons.
I still have access to everything else: My email, my MW account, my Github, Discord, Gerrit, all of which I've used along with this account in the past. I am also pretty certain that nobody except for me has ever accessed Phabricator with my static IP.
My other MFA factor also still works. Is removing only one even possible or does it still require the same verification as removing all?

Garrr, Phabricator doesn't allow removing only one of two 2FA using the very same "provider" (TOTP)

Since @SomeRandomDeveloper seems fairly privacy conscious (that's great!) and doesn't know anyone at the WMF personally, I don't think video, etc. verification is really an option here. We also aren't set up to verify identity via government IDs or anything like that. So the best we can probably do here is a live call with whomever is claiming to be @SomeRandomDeveloper and requesting they complete certain actions related to a group of their accounts, e.g. respond to an email sent to their account with a certain message, make a specific edit on a project, push a test change set to gerrit for a specific project and then abandon it, etc. This would be far from perfect security but would likely be better than nothing, assuming it's ok with WMF-Legal and Trust-and-Safety. The only option after that, IMO, is disabling @SomeRandomDeveloper and just setting up a new account.

Aklapper triaged this task as Medium priority.
Aklapper removed a project: Security-Team.

Thanks a lot for the guidance (also noted for next time)! I'll follow up with SomeRandomDeveloper out-of-band.

Aklapper moved this task from To Triage to Administration (UI) on the Phabricator board.

Verified the request, TOTP stripped and asked the user to set it up again.