Re: Wiki 2FA - Mailing list pgsql-www

From Tom Lane
Subject Re: Wiki 2FA
Date
Msg-id 12012.1453592953@sss.pgh.pa.us
Whole thread Raw
In response to Re: Wiki 2FA  ("Joshua D. Drake" <jd@commandprompt.com>)
Responses Re: Wiki 2FA  ("Joshua D. Drake" <jd@commandprompt.com>)
Re: Wiki 2FA  ("Greg Sabino Mullane" <greg@turnstep.com>)
List pgsql-www
"Joshua D. Drake" <jd@commandprompt.com> writes:
> On 01/23/2016 03:35 PM, Tom Lane wrote:
>> I doubt it would help much unless we required a 2FA auth cycle for
>> every single edit, which I for one wouldn't stand for.  Reasonably
>> user-friendly policies like one auth a day would still be plenty
>> easy for spammers too.  (They've got phones too ya know.)

> Bummer, o.k. Although it seems that spammers only go after easy targets. 

I dunno.  I was astonished that they came back a second time after we'd
once thrown them off and cleaned up the mess; you'd think they'd realize
that that would just happen again.  I think it may have been an
intentional attack on the PG project as such, not just drive-by spamming.
(If so, and if the goal was to complicate our lives, they succeeded.)

Or maybe I'm just too paranoid.
        regards, tom lane



pgsql-www by date:

Previous
From: "Joshua D. Drake"
Date:
Subject: Re: Wiki 2FA
Next
From: "Joshua D. Drake"
Date:
Subject: Re: Wiki 2FA