I'd say too, please distribute this information as appropriate to your local
---------- Forwarded message ----------
From: Brion Vibber <brion(a)wikimedia.org>
Date: May 8, 2007 7:17 AM
Subject: [Foundation-l] Password security notes
To: Wikimedia developers <wikitech-l(a)lists.wikimedia.org>
Cc: wikipedia-l(a)lists.wikimedia.org, Wikimedia Foundation Mailing List
-----BEGIN PGP SIGNED MESSAGE-----
As noted in other threads on several mailing lists, a few admin accounts
on en.wikipedia have been compromised recently, used to vandalize
high-traffic protected pages.
We're starting to roll out some additional protections against
password-guessing attacks, including but not limited to:
* Additional logging to better detect dictionary-style attacks
* Speed-bump measures against multiple failed logins
[But not that should DoS legitimate users. The traditional "lock out the
account after three tries" would make it trivial to lock out all the
site's sysops -- not wise. :)]
* Weak-password checks on existing sysops on our largest sites. Several
accounts have had their weak passwords invalidated and will need to
reset by mail before logging in again.
* Several targeted blocks against known cracking attempts.
Over the coming days we will additionally be rolling out more automated
password-strength checkers at login / set-password / change-password
time to reduce the danger of guessable passwords.
Please distribute this information as appropriate to your local
- -- brion vibber (brion @ wikimedia.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v126.96.36.199 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
-----END PGP SIGNATURE-----
foundation-l mailing list
* habent enim emolumentum in labore suo *