Page MenuHomePhabricator

Increase $wgMinimalPasswordLength to 6 bytes
Closed, ResolvedPublic

Description

https://www.mediawiki.org/wiki/Requests_for_comment/Passwords was accepted by the Architecture Committee, as discussed in https://www.mediawiki.org/wiki/Architecture_meetings/RFC_review_2014-03-05.

It was decided that $wgMinimalPasswordLength would be set to 6 bytes by default, pending a few tasks:

Related Objects

Event Timeline

csteipp created this task.Apr 10 2015, 11:43 PM
csteipp raised the priority of this task from to Needs Triage.
csteipp updated the task description. (Show Details)
csteipp added a project: TechCom-RFC.
csteipp added a subscriber: csteipp.
Restricted Application added a subscriber: Aklapper. · View Herald TranscriptApr 10 2015, 11:43 PM

Patch to allow login with old, short passwords: https://gerrit.wikimedia.org/r/#/c/117635/

Pine added a subscriber: Pine.Apr 16 2015, 7:43 AM

I'm guessing that this should also be in the Security project so I'll boldly add it.

Pine set Security to None.
daniel moved this task from Inbox to Under discussion on the TechCom-RFC board.Apr 22 2015, 8:32 PM
Spage assigned this task to csteipp.Jun 17 2015, 8:31 PM
Spage added a subscriber: Spage.

@csteipp Has this been implemented? TechCom Isn't sure. If so, you can just close this task.

@Spage, No, not yet. Since we now (as of this week) have group specific passwords, I wasn't sure if that should change what we set for all users. Since 6 was chosen as a balance between being long for regular users and short for admins.

Restricted Application added subscribers: StudiesWorld, Matanya. · View Herald TranscriptNov 26 2015, 3:12 PM
Restricted Application added a subscriber: JEumerus. · View Herald TranscriptMay 18 2016, 1:07 AM
Mdann52 closed this task as Resolved.Oct 18 2016, 6:08 PM
Mdann52 added a subscriber: Mdann52.

Seemingly resolved with T94774