Re: Preventing account takeovers through expired domains (was: Do we have any policy for disabling inactive users)

2022-02-19 Thread Zbigniew Jędrzejewski-Szmek
On Sat, Feb 19, 2022 at 02:18:38PM +0100, Björn Persson wrote: > Possible step 3: A program on a Fedora Project server notes that > example.net has been deactivated. The program removes the address > j@example.net from J. Doe's account, or disables sending to the > nonexistent address. ... >

Preventing account takeovers through expired domains (was: Do we have any policy for disabling inactive users)

2022-02-19 Thread Björn Persson
Vitaly Zaitsev via devel wrote: > We're talking about potentially hacked accounts, right? In this subthread I'm talking about *preventing* account takeovers so that they don't happen in the first place. One specific method of takeover that the Fedora Project would be able to prevent. I thought