I bricked my phone a while ago, losing my two-factor authentication tokens. I can still access Phabricator through the active session on my computer, but nowhere else. I made a request that the authentication be removed on IRC a month earlier, which Quiddity helpfully responded to and emailed two ops, qgil and andre. Unfortunately, I haven't heard from them since. Could anyone kindly help?
Description
Related Objects
Event Timeline
I am sorry for not following up on this earlier.
There are currently no guidelines on this (T85706) and how we could verify the request.
Was the one-time token displayed to you, and did you archive that token?
No, I didn't see any one-time token when activating the feature. I can provide my committed identity on my enwiki user page (at the bottom) to prove my identity.
If using the committed identity is acceptable, how can I send you the source text in a secure way?
I'm not really sure what to do here. If @zhaofengli can demonstrate to @Aklapper's satisfaction then I'm ok with wiping the two-factor requirement (since @Aklapper is wiser in the ways of this than I).
Pardon my missing technical knowledge, being someone who does not use modern mobile phones to do stuff on the internet.
If using the committed identity is acceptable, how can I send you the source text in a secure way?
What is "the source text" in this context? The token? I simply wonder if it's anything that is also stored somewhere(TM) in Phabricator and that we could compare with. But right now I do not even have an idea how to use two-factor auth in Phab with my mobile phone at all.
Ah, so apparently there is a "user committed identity" template at the bottom of user pages.
Valhalla was kind enough to explain to me on IRC how things are supposed to work in this century.
<valhallasw`cloud> basically, zhaofeng would tell you what the secret string is, you'd SHA-512 that and compare, and that would tell you you're talking to the right person
@zhaofengli, could you please
- go to https://phabricator.wikimedia.org/paste/create/
- click on "Visible To: Public (No Login Required)"
- click "Custom Policy" in the dropdown
- under "Allow users", enter the usernames: Aklapper, chasemp
- click "Save Policy"
- click on "Editable By: All Users"
- click "Custom Policy" in the dropdown
- under "Allow users", enter the usernames: Aklapper, chasemp
- click "Save Policy"
- paste the text
- click "Create Paste"
- Paste the P number (something like P987654) here
@zhaofengli: Thanks! The sha256sum result of that string fits so the identity is correct
@chasemp: Still I'm clueless what needs to be done now server-side to wipe it