Hello everyone,
For a long time now, we have had the default behaviour of admins can
unblock themselves if blocked.
In my opinion, this is a poor default. In the event of a compromised
admin account, the compromised account can just unblock themselves and
continue being malicious.
To that end, and in light of some recent admin accounts being
compromised, we now disallow admins to unblock themselves. This
doesn't apply to self blocks - Admins who block themselves can still
unblock themselves. However admins who are blocked by other admins can
no longer unblock themselves.
I'm still open to communities who want to continue to have the old
behaviour to opt out of the new behaviour - The primary thing here is
that the default has now changed, so that anywhere that was using the
old behaviour for no other reason then it was the default is now using
the new behaviour.
--
Brian Wolff ([[User:BWolff_(WMF)]])
Wikimedia Security Team