Re: Wiki 2FA - Mailing list pgsql-www

From Tom Lane
Subject Re: Wiki 2FA
Date
Msg-id 11574.1453592141@sss.pgh.pa.us
Whole thread Raw
In response to Re: Wiki 2FA  ("Joshua D. Drake" <jd@commandprompt.com>)
Responses Re: Wiki 2FA
List pgsql-www
"Joshua D. Drake" <jd@commandprompt.com> writes:
> On 01/23/2016 12:41 PM, Magnus Hagander wrote:
>> It does not protect against people signing up for multiple accounts.
>> Unless  you were actually planning to send out hardware 2FA tokens to
>> each actual contributor, but I'm pretty sure you didn't mean that?

> No. I meant the idea of having Google Authenticator required (which is 
> open source). It works on any Android device as well as others 
> (windows). I believe it would help with the autoscripting edits?

I doubt it would help much unless we required a 2FA auth cycle for
every single edit, which I for one wouldn't stand for.  Reasonably
user-friendly policies like one auth a day would still be plenty
easy for spammers too.  (They've got phones too ya know.)  In fact,
considering it is trivial to have as many GA instances as you want
all sharing the same key, I'm pretty sure that even a 2FA-check-per-edit
policy could be scripted against.  The bots would just need to have
a local token generator running the same key that the mechanical
turks had signed up with.
        regards, tom lane



pgsql-www by date:

Previous
From: Peter Geoghegan
Date:
Subject: Re: Wiki 2FA
Next
From: "Joshua D. Drake"
Date:
Subject: Re: Wiki 2FA