Talk:Mandatory two-factor authentication for users with some extended rights
Add topicThis page is for discussions related to the Mandatory two-factor authentication for users with some extended rights page. Please remember to:
|
Missing notifications
[edit]I've heard that some are unable to use CU/OS now, which indicates that this has gone into effect. However, I don't think that the page's promise of contact[ing] impacted users directly ahead of the change occurred. Why is that, and will the change be delayed to after the notifications have occurred instead of before? Sdrqaz (talk) 01:44, 21 May 2025 (UTC)
- NOTE: The config change has now been reverted in Wikimedia production (i.e. the users without 2FA can use their tools again), whilst we check what went wrong in the planned communication. Some of the communication went out, but apparently not all.
- We will leave the config reverted for at least a week after confirmed-communications have been delivered.
- Thank you Sdrqaz for your note here and phab. Quiddity (WMF) (talk) 23:16, 21 May 2025 (UTC)
- Thank you, Quiddity (WMF). I've not seen the message so maybe it is already clear, but based on Ponyo's reverted message, it may need to be made clearer that Special:OATH needs to be accessed from a wiki where the user has CU/OS. (I know that Help:Two-factor authentication does say that, but it wouldn't hurt to repeat). Sdrqaz (talk) 23:30, 21 May 2025 (UTC)
- Per Special:GlobalGroupPermissions most global groups have oathauth-enable permissions, we should just add that to the global temporary account IP viewer group allowing all CU & OS to enable 2FA via any wiki (e.g. meta when they are reading this page). Johannnes89 (talk) 06:07, 22 May 2025 (UTC)
- Sounds sensible, good idea. Sdrqaz (talk) 17:11, 22 May 2025 (UTC)
- I've added that detail to the page. Thanks again, Sdrqaz. -- Quiddity (WMF) (talk) 17:24, 22 May 2025 (UTC)
- Per Special:GlobalGroupPermissions most global groups have oathauth-enable permissions, we should just add that to the global temporary account IP viewer group allowing all CU & OS to enable 2FA via any wiki (e.g. meta when they are reading this page). Johannnes89 (talk) 06:07, 22 May 2025 (UTC)
- Thank you, Quiddity (WMF). I've not seen the message so maybe it is already clear, but based on Ponyo's reverted message, it may need to be made clearer that Special:OATH needs to be accessed from a wiki where the user has CU/OS. (I know that Help:Two-factor authentication does say that, but it wouldn't hurt to repeat). Sdrqaz (talk) 23:30, 21 May 2025 (UTC)
- As @Quiddity (WMF) mentioned above, we're delaying it - I've just updated the meta page to reflect a new deadline of June 3rd (another 2 weeks after May 20th), in acknowledgement of the communication error. EMill-WMF (talk) 14:08, 22 May 2025 (UTC)
- Thank you! Sdrqaz (talk) 17:11, 22 May 2025 (UTC)
Temporarily disabling 2FA
[edit]When I last changed by 2FA device, I remember temporarily disabling 2FA on my old device, migrating everything to my new device, then enabling 2FA as a new setup on my new device. Would I still be able to do that next time I upgrade, or will I be prevented from disabling 2FA? Thryduulf (talk: meta · en.wp · wikidata) 02:07, 21 May 2025 (UTC)
- You are prevented from taking actions requiring the rights when you have 2FA disabled. You are not prevented from disabling 2FA. Izno (talk) 19:00, 21 May 2025 (UTC)
Comments for security
[edit]- What issues have you had, or seen others have, with two-factor authentication on Wikimedia projects?
- To write down recovery codes, it may be hard for someone to distinguish similar characters like "V" and "U".
- Are there technical security requirements other than 2FA that we should be considering as potential requirements for maintaining privileged access on the wikis?
- Maybe we need to arrange password policies. For example, how about changing Stewards'
(MinimalPasswordLength)to 12 or more?
- Maybe we need to arrange password policies. For example, how about changing Stewards'
- What other user groups or privileges should we be focused on as we look at strengthening our security policies?
- Anyone who has extended privilege should be enforced to set 2FA, in my view.
- What do we most need to be careful about as we go about this work?
- To make improvement on WebAuthn support, please.
- Any other comments or questions you have.
- Thank you for your any effort to secure the Wikimedia project!
--T4NeGMp7P4en (talk) 06:59, 13 September 2025 (UTC)
Extended security testing, dogfooding
[edit]Can we start outlining extended security requirements and spin up a testing group? Compare to EG Google Advanced Protection or Apple Advanced Data Protection, where a user cannot disable MFA and has no 'backup codes'. PERSISTENT.CIRCUMSTANCE (talk) 17:20, 28 October 2025 (UTC)
Adding 'EmailAuth' to 2FA
[edit]Can we have OFF / SUSPICIOUS / ON options for EmailAuth added to the 2FA options? Currently 2FA only offers some TOTP scheme and then some version of WebAuthn, and turning either of these on disables EmailAuth entirely. PERSISTENT.CIRCUMSTANCE (talk) 03:23, 29 October 2025 (UTC)
- See T394105 for past discussion. Tgr (WMF) (talk) 13:50, 31 October 2025 (UTC)
- I'll leave this here for anyone else who would ask for the same thing without finding it on the Phabricator.
- As of today the discussion covers almost everything I would want to bring up. The only thing missing is the lack of discussion surrounding disabling password reset by email. PERSISTENT.CIRCUMSTANCE (talk) 15:42, 31 October 2025 (UTC)
cannot
[edit]From laptop (i do not use phones). I installed KeeWeb-1.18.7.win.x64.exe but made mistake with username (sarrikaterina verifying my email sarrikaterina@yahoo.com), and now, it will not let me + add a password from New1= Sarri.greek. Every time I open, I cannot get my previous entry, it stops me. I cannot find that screen from https://phabricator.wikimedia.org/F83529879 I am informed that I will be expelled as a bureaucrat from el.wikt https://el.wiktionary.org/wiki/Χρήστης:Sarri.greek in... I cannot remember the message. Will I be able to enter at all, with my old password? or will I be expelled from wiktionary altogether? Sorry, I am too old, and lack modern dexterities. Sarri.greek (talk) 15:54, 1 June 2026 (UTC)
- @Sarri.greek not sure I understand the situation but I'm sure there will be a way to recover the account. Did you try to use Special:AccountRecovery?
- If nothing else works, you can just email Trust and Safety at their general email address and explain the situation. Tgr (WMF) (talk) 17:52, 1 June 2026 (UTC)
- No, M Tgr (WMF)|Tgr (WMF) This link will accept neither my old password, nor a new one (which was supposed to be in Kee..)
- https://auth.wikimedia.org/elwiktionary/w/index.php?title=Ειδικό:ΣύνδεσηΧρήστη&returnto=Ειδικό%3AAccountSecurity&returntoquery=&force=OATHManage
- It would be great if someone gave me a password -any password, I do not mind- for User:Sarri.greek so that i get a free 'pass'. I do not have any fear for security: I am not that important (interface someone, or global someone). If I cannot come back, well, goodbye wiktionary. Thank you, sorry because I am elderly, and do not know simple things.Sarri.greek (talk) 18:04, 1 June 2026 (UTC)
I go either to
- https://auth.wikimedia.org/elwiktionary/w/index.php?title=Ειδικό%3AAccountSecurity&action=enable&module=webauthn
- What do I do with these 4-letter codes? I inserted a USB and nothing happened.
- https://auth.wikimedia.org/elwiktionary/w/index.php?title=Ειδικό%3AAccountSecurity&action=enable&module=webauthn
....(2026-06-01T18:32:21Z)
(redacted)
I insert a USB, but nothing is clickable at the second little grey screen that comes up, except 'Cancel' (or the choice from another white screen with dropdowns)
I try at en.wiktionary
Recovery codes created: 18:44, 1 June 2026 (2026-06-01T18:44:13Z)
(redacted) Never mind. If a button 'Ask for exception' is ever created, I will clcik on it, add my Username and a password. Sarri.greek (talk) 18:56, 1 June 2026 (UTC)
- @Sarri.greek, the codes that you posted here, are recovery codes for you account. When you log in, and you don't have any other second factor at hand, you can use one of those codes to log in (each is single-use only). Please don't post these publicly, and treat them similarly to passwords (the only exception is, you don't have to remember them).
- Please also note that bureaucrat are definitely not "rights that aren't relevant for security". 'Crats can promote new interface admins, which makes this group (indirectly) powerful and potentially risky if the account is taken over. Msz2001 (talk) 19:10, 1 June 2026 (UTC)
- A! I see. Thank you, M Msz2001. So, these are 'one-use passwords' instead of my own. OK. Thanks. If fail, I hope I can come back as a common user. Sarri.greek (talk) 19:13, 1 June 2026 (UTC)
PS Cannot do passkeys either. Not that it matters, seniors are not so many among you. Everything in this 'Help' page is Greek to me. If you are interested, in what form my idiocy is unfolding.. Here is what i did (I have Windows 10, Chrome browser -I bought a new laptop with Windows11, but I did not like it)
I log out.
When I log in with my old password, he asks me for a stronger one
I made one. I also get a CAPTCHA every time i log in
I get passkeys (previously I clicked 'Add keys'. Today, they came automatically.)
I downlad it = Wikimedia - recovery codes.txt (it has many 4-digit uppercase letters)
I see that i must set up the 2-way thing
https://meta.wikimedia.org/wiki/Help:Two-factor_authentication#Log_in_with_two-factor_authentication
If you're using a passkey: Follow the prompts on your device to complete verification using your fingerprint, face scan, or PIN code.
I do not have fingerprints etc.
I cannot find these 'prompts' and a PIN code (???does he mean the passkey?)
Here are the two square grey cards that I get:
1) Enable Security key. Choose the nickname for your key
Security key setup. Set up your secuirty key to sing in to auth.wikimedia.org as Sarri.greek
>>What does this nickname mean???. Anyway: I copypasted the first XXXX key. It may serve as a 'nickname' too.
I click OK
2) Enable Security key. Continue setup. Insert your security key into the USB port. Cancel.
>> There is nothing to click except Cancel.
I must write something at a USB and insert it? In what form?
I inserted a USB but still, the only clickable thing i see is 'Cancel'
I also go to Preferences>Account security and clik 'manage'. Same problems. I also downloaded an 'Authenticator' at a smartphone I have (but I use it twice a year or so: I use an old mobile for banks with no problem: They send one 6digit at SMS and another 6digit at my email). It keeps writing 6digit codes and I do not know how to uninstall it... Sarri.greek (talk) 07:37, 8 June 2026 (UTC)
- @Sarri.greek, I'll try to describe the 2FA options in simpler terms (maybe the help page is too technical). If you want or have to configure 2FA, you have three options:

Configure authenticator app 
A YubiKey - Authenticator app (such as Google Authenticator, Authy etc.) – this is typically an app you install on your smartphone, although there are also versions to install on your computer (for example, Open Authenticator has a version for Windows). To configure such method, you typically use the app to scan a QR code displayed on Special:AccountSecurity (like on the screenshot on the right; sorry, I only had a Polish version of this screenshot at hand). Then, once the app starts generating 6-digit codes for your Wikimedia account, you type the code on Special:AccountSecurity (and also, when logging in, you type the 6-digit code as well).
- If you can't scan the QR code, you can also set up the app by copying the long key displayed under the code (42 letters on the screenshot).
- Security key – these are typically physical keys that look similarly to flash drives. A common example of these are YubiKeys. Please note, that you can't use any USB stick as a security key (i.e., security keys and flash drives are different type of devices, even though they look similarly). Only after inserting a security key, the prompt that you've been talking about should show something more than just "Cancel" button.
- If you're using a device capable of biometrics (a fingerprint scanner or special type of webcam), your device ships with an internal module that can work as a security key. In such case, you'll unlock the key (and thus, log in) by scanning your finger or face or by entering a PIN code that you normally log into your device with.
- Passkeys – these are available only if you configure any of the above first. A passkey works very similar to the what's described in the bullet point above.
- Authenticator app (such as Google Authenticator, Authy etc.) – this is typically an app you install on your smartphone, although there are also versions to install on your computer (for example, Open Authenticator has a version for Windows). To configure such method, you typically use the app to scan a QR code displayed on Special:AccountSecurity (like on the screenshot on the right; sorry, I only had a Polish version of this screenshot at hand). Then, once the app starts generating 6-digit codes for your Wikimedia account, you type the code on Special:AccountSecurity (and also, when logging in, you type the 6-digit code as well).
- A few other notes – if you're asked for a nickname for a given authentication method, it's for your convenience, so that you can recognize which key is the one you added (so, you can type e.g., "blue YubiKey" there – or whatever else, it's only for you). Also, the recovery codes – these are 10 codes with length of 16 letters each (they are broken up in groups of four only for easier typing, but one line = one code). MSzwarc-WMF (talk) 11:49, 8 June 2026 (UTC)
- M @MSzwarc-WMF: I am so sorry that I caused you to describe in such lengths. At a smartphone that i have, i loggedin at wiktionary. 1st time ok. 2nd time I got (or I went to Preferences>..) a screen with 2 options. Apps and Keys. I have tried both of them. Keys. I have downloaded. nothing more. Apps. I got the screen like your photograph (podzięka for this Sir!). I copied the 42 letters (with spaces) like at 'Krok 5' = Failed. I copied the first of the the codes given in step 4=failed. Started again. now, new card like your photo. I copied at Krok5 the 42 leters without spaces. Clicked the blue button under it. A huge page of Wikimedia Foundation Privacy Policy came to my screen.
- The Fixers.shop said, they know what 2FA is, but they have never done it and refused. I will show it at a young person at my bridge club -maybe they will know what to do-
- You are probably amazed that there are people in this world that lack such dexterities. I (age 62) have learnt how to do emails. Normally, I can follow instructions with steps. I can type codes at a white space indicated to me. That is all. With 6digit codes first at SMS (at+30 6973 869019), then at email sarrikaterina @ yahoo.com, or another email too if you wish, I have moved lots of money (in batches) with ebanking; a simple method, alas, not sufficient here. Thank you so much for your time: please, do not bother with my unique, peculiar case. ~2026-33689-10 (talk) 14:08, 8 June 2026 (UTC) o!!what is this? https://meta.wikimedia.org/wiki/Special:CentralAuth?target=Sarri.greek



