Cannabis Ruderalis

Content deleted Content added
2a01:261:5f0:ae00:d024:f653:3684:eae1 (talk)
fixed problem
Tags: Reverted Mobile edit Mobile web edit
m Reverted edit by 5.116.126.28 (talk) to last version by ThaddeusSholto
 
(31 intermediate revisions by 26 users not shown)
Line 1: Line 1:
<noinclude>{{pp-move-indef}}</noinclude>
{{redirect|WP:PASSWORD|the policy on password strength|:meta:Password policy}}
{{infopage|WP:SECURITY|WP:SECURE|WP:PASSWORD|WP:UAS}}
{{nutshell|Failing to use a sensible password can lead to temporary loss of editing access and may lead to permanent loss of privileged access.}}

All registered users have to log in using a [[password]] before they can edit using their usernames. Passwords help ensure that someone does not masquerade as another editor. Editors should use a [[Password_strength#Guidelines_for_strong_passwords|strong password]] to avoid being blocked for bad edits by someone who guesses or "[[Password cracking|cracks]]" other editors' passwords. Users may access their account's [[Help:Preferences|preferences]] to change their password.

== In general ==
== In general ==
Password strength requirements are explained in the [[meta:Password policy|password policy]]. For normal users, those requirements are enforced when an account is created and when a password is changed.
Password strength requirements are explained in the [[meta:Password policy|password policy]]. For normal users, those requirements are enforced when an account is created and when a password is changed.
Line 16: Line 23:
Accounts that appear to have been compromised may be blocked without warning; administrators will generally not unblock such accounts without evidence that their rightful owners solely control them.
Accounts that appear to have been compromised may be blocked without warning; administrators will generally not unblock such accounts without evidence that their rightful owners solely control them.


'''Never, ever, share your password'''. Accounts with advanced permissions risk their permissions being revoked or account blocked due to violation of community trust and standards on account sharing.
'''Never, ever, share your password'''. Accounts with advanced permissions risk their permissions being revoked or account blocked due to violation of community trust and [[Wikipedia:Username policy#Sharing accounts|standards on account sharing]].


=== Changing your password ===
=== Changing your password ===
Line 25: Line 32:
[[File:2018-05-04 Failed Attempt.jpg|thumb|upright=1.5|A [[Help:Notifications|notification]] alerting a user of a failed login attempt from a new device]]
[[File:2018-05-04 Failed Attempt.jpg|thumb|upright=1.5|A [[Help:Notifications|notification]] alerting a user of a failed login attempt from a new device]]


Through the [[Wikipedia:Notifications]] system, you will be alerted when someone attempts and fails to log in to your account. Multiple alerts are bundled into one for an attempt from a new device/IP, but for a known device/IP, you get one alert for every 5 attempts.
Through the [[Wikipedia:Notifications|notification]] system, you will be alerted when someone attempts and fails to log in to your account. Multiple alerts are bundled into one for an attempt from a new device/IP, but for a known device/IP, you get one alert for every 5 attempts.


If you receive this notification, don't worry! Your account is still secure. But even if you do have a strong password, you may want to change your password anyway, if you suspect that someone else has tried to access your account.
If you receive this notification, don't worry! Your account is still secure. But even if you do have a strong password, you may want to change your password anyway, if you suspect that someone else has tried to access your account.
Line 40: Line 47:
== Privileged editors ==
== Privileged editors ==


On Wikipedia, only certain users (including [[Wikipedia:Administrators|administrators]]) can perform some actions. It is especially important that these privileged editors have strong passwords. Administrators, [[Wikipedia:Bureaucrat|bureaucrats]], [[Wikipedia:Checkuser|checkusers]], [[Wikipedia:Steward|stewards]] and [[Wikipedia:Oversight|oversighters]] discovered to have [[Password strength|weak passwords]], or to have had their accounts compromised by a malicious person, may have their accounts blocked and their privileges removed on grounds of site security. In certain circumstances, the revocation of privileges may be permanent. Discretion on resysopping temporarily [[wikt:desysop|desysopped]] administrators is left to the bureaucrats, provided they can determine that the administrator is back in control of the previously compromised account.
On Wikipedia, only certain users (including [[Wikipedia:Administrators|administrators]]) can perform some actions. It is especially important that these privileged editors have strong passwords. Administrators, [[Wikipedia:Bureaucrat|bureaucrats]], [[Wikipedia:Checkuser|checkusers]], [[Wikipedia:Steward|stewards]] and [[Wikipedia:Oversight|oversighters]] discovered to have [[Password strength|weak passwords]], or to have had their accounts compromised by a malicious person, may have their accounts blocked and their privileges removed on grounds of site security. In certain circumstances, the revocation of privileges may be permanent. Discretion on resysopping temporarily [[wikt:desysop|desysopped]] administrators is left to the [[Wikipedia:Arbitration Committee|Arbitration Committee]], provided they can determine that the administrator is back in control of the previously compromised account.


== Two-factor authentication (2FA) ==
== Two-factor authentication (2FA) ==
Line 50: Line 57:
To set up two-factor authentication:
To set up two-factor authentication:
* This action is currently limited to administrators, bureaucrats, oversighters, checkusers, edit filter managers, template editors and interface administrators. Other users may request 2FA at [[:m:Steward_requests/Global_permissions#Requests_for_2_Factor_Auth_tester_permissions|Steward requests/Global permissions]] on Meta.
* This action is currently limited to administrators, bureaucrats, oversighters, checkusers, edit filter managers, template editors and interface administrators. Other users may request 2FA at [[:m:Steward_requests/Global_permissions#Requests_for_2_Factor_Auth_tester_permissions|Steward requests/Global permissions]] on Meta.
* See [[Help:Two-factor authentication]] for step-by-step directions, cautions, and information about this feature.
* First you must have or install a [[:en:Time-based One-time Password Algorithm|Time-based One-time Password Algorithm]] (TOTP) client. For most users, this will be a phone or tablet application. [[Google Authenticator|Google Authenticator]] is a popular example <sup>[https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&hl=en_GB Android] [https://itunes.apple.com/gb/app/google-authenticator/id388497605?mt=8 iOS]</sup>, along with [[Google Authenticator#Implementations|other implementations of it]].
* Next go to [[Special:OATH]] (this link is also available from your [[Special:Preferences#mw-prefsection-personal|preferences]]).
* [[Special:OATH]] presents you with a [[:en:QR code|QR code]] containing the '''two-factor account name''' and '''two-factor secret key.''' This is needed to pair your client with the server.
* Scan the QR code with, or enter the two-factor account name and key into, your TOTP client.
* Enter a verification code from your TOTP client into the OATH screen to complete the enrollment.


== Notes ==
== Notes ==
Line 67: Line 70:
* [[Password strength]]
* [[Password strength]]
* [[Wikipedia:Committed identity]]
* [[Wikipedia:Committed identity]]
* [[Wikipedia:FAQ/Technical]] (how to recover password)
* [[Wikipedia:FAQ/Technical#How_do_I_recover_a_password_I_have_forgotten?|Wikipedia:FAQ/Technical]] (how to recover password)
* [[Wikipedia:Wikipedia Signpost/2006-02-06/Password security]]
* [[Wikipedia:Wikipedia Signpost/2006-02-06/Password security]]
* [[Wikipedia:Wikipedia Signpost/2006-12-18/Technology report]]
* [[Wikipedia:Wikipedia Signpost/2006-12-18/Technology report]]

Latest revision as of 10:16, 28 February 2024

All registered users have to log in using a password before they can edit using their usernames. Passwords help ensure that someone does not masquerade as another editor. Editors should use a strong password to avoid being blocked for bad edits by someone who guesses or "cracks" other editors' passwords. Users may access their account's preferences to change their password.

In general[edit]

Password strength requirements are explained in the password policy. For normal users, those requirements are enforced when an account is created and when a password is changed.

You should have a password that:

  • is at least eight characters (ten for privileged accounts)
  • has a mixture of upper and lowercase letters and numbers
  • avoids dictionary words, given or last names, or personal information (date of birth, cat's name, etc.)
  • is not used on any other website – websites periodically get hacked, with user information leaked onto the internet

Do this, and your password is likely to be reasonably strong. The burden of using sufficiently strong passwords lies on you, the user. What this means is that if your account is compromised (for any reason), this will be treated as you not having used a sufficiently strong password.

Avoid linking to external sites from your user page and user talk pages, since this reveals a connection that can be used in an attempt to take over your Wikipedia user account.

If you need to use a public computer or connect your own computer to a public Wi-Fi network, consider establishing an alternative account (see WP:VALIDALT for important instructions and limitations) since malicious software or hardware could capture your password.

Accounts that appear to have been compromised may be blocked without warning; administrators will generally not unblock such accounts without evidence that their rightful owners solely control them.

Never, ever, share your password. Accounts with advanced permissions risk their permissions being revoked or account blocked due to violation of community trust and standards on account sharing.

Changing your password[edit]

Click on "Preferences" at the top right-hand corner of the page and then click the "Change Password" button on the "User Profile" tab to access the Special:ChangePassword page.

Failed login attempts[edit]

A notification alerting a user of a failed login attempt from a new device

Through the notification system, you will be alerted when someone attempts and fails to log in to your account. Multiple alerts are bundled into one for an attempt from a new device/IP, but for a known device/IP, you get one alert for every 5 attempts.

If you receive this notification, don't worry! Your account is still secure. But even if you do have a strong password, you may want to change your password anyway, if you suspect that someone else has tried to access your account.

What to do when your account has been compromised[edit]

Information on what to do when your account has been compromised can be found at Wikipedia:Compromised accounts § After being compromised.

In a nutshell, you can help Wikipedia block access to the account and prevent malicious behavior. Do not expect to be able to regain control of the account.

What to do when your device has been compromised[edit]

Wikipedia's "Log out" link logs out all the user's current sessions. If a logged-in device is lost or stolen, changing the password and logging out on another device may help to prevent future abuse of the account on the lost device.

Privileged editors[edit]

On Wikipedia, only certain users (including administrators) can perform some actions. It is especially important that these privileged editors have strong passwords. Administrators, bureaucrats, checkusers, stewards and oversighters discovered to have weak passwords, or to have had their accounts compromised by a malicious person, may have their accounts blocked and their privileges removed on grounds of site security. In certain circumstances, the revocation of privileges may be permanent. Discretion on resysopping temporarily desysopped administrators is left to the Arbitration Committee, provided they can determine that the administrator is back in control of the previously compromised account.

Two-factor authentication (2FA)[edit]

Wikimedia's implementation of two-factor authentication (2FA) is a way of strengthening the security of your account. If you enable two-factor authentication, every time you log in you will be asked for a one-time six-digit number in addition to your password. This number can be provided by an app on your smartphone or other authentication device (called a TOTP client). In order to login you must know your password and have your authentication device available to generate the code.

Enrolling[edit]

To set up two-factor authentication:

  • This action is currently limited to administrators, bureaucrats, oversighters, checkusers, edit filter managers, template editors and interface administrators. Other users may request 2FA at Steward requests/Global permissions on Meta.
  • See Help:Two-factor authentication for step-by-step directions, cautions, and information about this feature.

Notes[edit]

For informal advice on personal security, including passwords, see Wikipedia:Personal security practices.

Users are encouraged to provide an email address in their preferences, as this enables them to reset their password via email if necessary. (Providing an email address also makes possible communications with other users via email; this can be disabled in preferences by unchecking the option "allow other users to email me".) Email alerts generated by the Wikipedia:Notifications system can also be sent to your email address, such as "failed login attempts" and "login from an unfamiliar device" notifications (these two messages are on by default, but are configurable in the notifications preferences).

See also[edit]

Leave a Reply