File:Mockup-proposal-2emails--change-email-2.png

From Meta, a Wikimedia project coordination wiki

Original file(1,179 × 739 pixels, file size: 82 KB, MIME type: image/png)

This is a file from the Wikimedia Commons. The description on its description page there is copied below.

Summary

Description
English: Part of a number of graphics, created to accompany a proposel on phabricator to allow users to use more than one email address in wikimedia.
Français : Partie d'un certain nombre de graphiques, créés pour accompagner une proposition sur phabricator pour permettre aux utilisateurs d'utiliser plus d'une adresse e-mail dans wikimedia.
Date
Source Created by me with free graphics software, based on screenshots of the layout of the english wikipedia, asoftware which is licenced under the GPL.
Author this version by Gradzeichen (°), based on the work of numerous contributers to the mediawiki software and translators of the user interface.

See phab:T129747:

The same email address is used for wikimail and password recovery.

For password recovery an address with a secure mail provider is a good choice. For wikimail on the other hand a throw-away-mail-address, that can be easily replaced, if it becomes known to a stalker or the public, makes more sense. This is especially true for accounts with additional rights and prolific authors. These groups cannot work without wikimail and are unlikely to abstain from the possibilty to recover a lost password.

I propose the following: Add the option to specify a second email address in the preferences for all users.

Add the following global preferences (email and password are already global):

  • checkboxes to select what email address to use with wikimail or none at all
  • checkboxes to select what email address to use for password recovery or none at all
    • if both boxes are checked, different temporary passwords are sent to both addresses and both are needed to login
  • checkboxes to select what email address to use for echo and other notifications
  • in a more ambitious additional approach the local echo preferences could allow the configuration of every notification type to be sent onwiki, to first address, to second address
  • checkboxes to send a TAN to either of the adresses on login (achieving a cheap way of 2FA, at least until true 2FA is implemented)

In a given time frame only one email address can be changed. A confirm message is sent to the new address and additionally a "cancel the change" message is sent to the other unchanged address.

The option of two addresses would allow the use of a throw-away-email-address for wikimail. So if this address becomes known to a stalker, you can simply change this address, while keeping your secret secure email address for all other uses.

Nothing changes for any user who does not specify an email address or stays with one address.

Licensing

GNU head

This work is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or any later version. This work is distributed in the hope that it will be useful, but without any warranty; without even the implied warranty of merchantability or fitness for a particular purpose. See version 2 and version 3 of the GNU General Public License for more details.

Captions

Add a one-line explanation of what this file represents

Items portrayed in this file

depicts

12 March 2016

File history

Click on a date/time to view the file as it appeared at that time.

Date/TimeThumbnailDimensionsUserComment
current16:14, 2 April 2016Thumbnail for version as of 16:14, 2 April 20161,179 × 739 (82 KB)°User created page with UploadWizard