https://bugzilla.wikimedia.org/show_bug.cgi?id=11354





--- Comment #2 from Mark Ryan <[email protected]>  2009-01-13 01:48:39 UTC ---
I think you (Happy-melon) might misunderstand how Special:MergeAccount works.
When I go to it on en.wp, it presents me with 27 accounts which have already
been merged, and a list of more than 40 wikis where there is a 'Mark' account
which could not be merged. If I type a password into the box at the bottom, it
checks all of those outstanding accounts to see if the password matches what I
typed in. If none have a matching password, it returns me to the page and says
"No accounts could be confirmed using this password." -- I can then try another
password immediately. The password you supply does not have to match the
password for the account on the wiki you're merging from; that way you can
merge accounts which are your own but which have different passwords. So brute
force seems possible. But by the same token you can't register a new account
with the same username as someone else, so the chances for misuse of this are
minimal.


-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to