Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-23 Thread RhinosF1 -
The spelling of ‘August’ is wrong in the second image on https://phabricator.wikimedia.org/T243247. Looks fine in the code though so not sure if fixed. RhinosF1 On Thu, 23 Jan 2020 at 16:55, Mukunda Modell wrote: > The update was deployed last night just a bit after midnight UTC. Upon >

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-23 Thread Mukunda Modell
The update was deployed last night just a bit after midnight UTC. Upon logging in, anyone with an affected auth factor should see a notification with instructions for how to proceed. For the curious, you can see screenshots of the notification which I attached to the task for this change, T243247

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-20 Thread David Sharpe
That conversation helped provide more clarity. Thank you for taking the time to respond! > On Jan 20, 2020, at 11:30 PM, Pine W wrote: > > Thanks for the updates, transparency, and timely notifications. > > I hope that I didn't sound like I was trying to be a pest earlier in this >

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-20 Thread Pine W
Thanks for the updates, transparency, and timely notifications. I hope that I didn't sound like I was trying to be a pest earlier in this thread. What may have been clear to people who are familiar with Phabricator 2FA was not clear to me at the time. Pine (

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-20 Thread Mukunda Modell
The plan is as follows: Sometime in the near future, we will be invalidating the sessions of anyone who has an auth factor which was potentially affected. If you were one of the potentially affected users then the next time you log in to Phabricator, you should see a notification directing you to

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-17 Thread Andre Klapper
On Fri, 2020-01-17 at 17:21 +, RhinosF1 - wrote: > What about those that do? See the last email. It said: "More to come soon…". andre -- Andre Klapper (he/him) | Bugwrangler / Developer Advocate https://blogs.gnome.org/aklapper/ ___ Wikitech-l

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-17 Thread RhinosF1 -
What about those that do? RhinosF1 On Fri, 17 Jan 2020 at 15:51, David Sharpe wrote: > There is a team working on the Phabricator 2FA action item right now. > More to come soon… > > No action is required for people without 2FA configured within Phabricator. > > > > > On Jan 17, 2020, at 10:25

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-17 Thread David Sharpe
There is a team working on the Phabricator 2FA action item right now. More to come soon… No action is required for people without 2FA configured within Phabricator. > On Jan 17, 2020, at 10:25 AM, RhinosF1 - wrote: > > Can you also confirm we need to take NO action? > > RhinosF1 > >

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-17 Thread RhinosF1 -
Can you also confirm we need to take NO action? RhinosF1 On Fri, 17 Jan 2020 at 11:02, revi wrote: > Hi, > > If it is possible to do so, can you notify to the people whose 2FA were > reset? I know at least few people who uses 2FA on Phab, and does not read > emails from wikitech-l and/or

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-17 Thread revi
Hi, If it is possible to do so, can you notify to the people whose 2FA were reset? I know at least few people who uses 2FA on Phab, and does not read emails from wikitech-l and/or wikimedia-l. Thanks! 나의 iPhone에서 보냄 > 2020. 1. 17. 06:26, David Sharpe 작성: > > However, out of an abundance of

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-16 Thread Michael Holloway
Do those of us using Phabricator 2FA need to take any action? On Fri, Jan 17, 2020 at 7:38 AM Greg Grossmeier wrote: > Keeping this thread on-list to help others who might be unsure. > > Hello Pine, > > On Thu, Jan 16, 2020 at 4:23 PM Pine W wrote: > > > The way that I log into Phab is by

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-16 Thread Greg Grossmeier
Keeping this thread on-list to help others who might be unsure. Hello Pine, On Thu, Jan 16, 2020 at 4:23 PM Pine W wrote: > The way that I log into Phab is by using > https://phabricator.wikimedia.org/auth/start/?next=%2F, and then logging > into MediaWiki and authorizing Phab to access my

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-16 Thread Pine W
Hi Greg, The way that I log into Phab is by using https://phabricator.wikimedia.org/auth/start/?next=%2F, and then logging into MediaWiki and authorizing Phab to access my credentials. The MediaWiki login including the 2FA is the same that I use for many other Wikimedia sites. So, although this

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-16 Thread Greg Grossmeier
On Thu, Jan 16, 2020 at 2:50 PM Pine W wrote: > Some of us use the same 2FA for Phabricator as for on wiki accounts. Should > the 2FA reset apply to all Wikimedia 2FAs that could be used for > Phabricator, or only those that actually have been used for Phabricator? > Hi Pine, Phabricator has

Re: [Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-16 Thread Pine W
Hi David, Thanks for the information. Some of us use the same 2FA for Phabricator as for on wiki accounts. Should the 2FA reset apply to all Wikimedia 2FAs that could be used for Phabricator, or only those that actually have been used for Phabricator? Is there a public ticket that people can

[Wikitech-l] 14 January 2020 security incident on Phabricator

2020-01-16 Thread David Sharpe
Hello, On 14 January 2020, staff at the Wikimedia Foundation discovered that a data file exported from the Wikimedia Phabricator installation, our engineering task and ticket tracking system, had been made publicly available. The file was leaked accidentally; there was no intrusion. We have