[Bug 28747] AntiSpoof and CentralAuth should be friends

2011-04-29 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28747

Platonides platoni...@gmail.com changed:

   What|Removed |Added

 CC||agarr...@wikimedia.org,
   ||platoni...@gmail.com
  Component|User login  |CentralAuth
Version|unspecified |any
 AssignedTo|wikibugs-l@lists.wikimedia. |vasi...@gmail.com
   |org |
Product|MediaWiki   |MediaWiki extensions
Summary|SUL allows circumvention of |AntiSpoof and CentralAuth
   |impersonation measures  |should be friends

--- Comment #1 from Platonides platoni...@gmail.com 2011-04-29 19:18:16 UTC 
---
AntiSpoof does not work with CentralAuth currently.

This could work on two ways: by blocking the account autocreation if there's a
local account with similar name, or by blocking registration if there is a
similarly named global account.

I think the later is preferable.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are the assignee for the bug.
You are on the CC list for the bug.

___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l


[Bug 28747] AntiSpoof and CentralAuth should be friends

2011-04-29 Thread bugzilla-daemon
https://bugzilla.wikimedia.org/show_bug.cgi?id=28747

--- Comment #2 from SoWhy a...@sowhy.de 2011-04-29 19:33:39 UTC ---
Blocking autocreation would probably not work without heavy modifications, also
that would still allow impersonation of prominent users on little known side
projects, for example by claiming to be an en-wiki admin on en-wikiversity. 

On a side note, AntiSpoof probably needs to be improved as well, as seen in the
recent attack of impersonation accounts on en-wiki. For example, AntiSpoof does
not block the creation of usernames with a single character changed unless that
character is similar to the changed one (SöWhy is blocked but SüWhy is
not). On a short username like mine, a change of a character is easily noticed
but if the username has 15+ characters or if the username is complicated, many
people will not notice the change, so it would probably be good if AntiSpoof
checked how much the new username has in common with existing ones.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
--- You are receiving this mail because: ---
You are on the CC list for the bug.
___
Wikibugs-l mailing list
Wikibugs-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l