Jump to content
 







Main menu
   


Navigation  



Main page
Contents
Current events
Random article
About Wikipedia
Contact us
Donate
 




Contribute  



Help
Learn to edit
Community portal
Recent changes
Upload file
 








Search  

































Create account

Log in
 









Create account
 Log in
 




Pages for logged out editors learn more  



Contributions
Talk
 



















Contents

   



(Top)
 


1 In general  



1.1  Changing your password  





1.2  Failed login attempts  





1.3  What to do when your account has been compromised  





1.4  What to do when your device has been compromised  







2 Privileged editors  





3 Two-factor authentication (2FA)  



3.1  Enrolling  







4 Notes  





5 See also  














Wikipedia:User account security






العربية
فارسی
Français

Bahasa Indonesia
ି
Tiếng Vit

 

Edit links
 









Project page
Talk
 

















Read
Edit
View history
 








Tools
   


Actions  



Read
Edit
View history
 




General  



What links here
Related changes
Upload file
Special pages
Permanent link
Page information
Get shortened URL
Download QR code
Wikidata item
 




Print/export  



Download as PDF
Printable version
 




In other projects  



MediaWiki
 
















Appearance
   

 






From Wikipedia, the free encyclopedia
 


All registered users have to log in using a password before they can edit using their usernames. Passwords help ensure that someone does not masquerade as another editor. Editors should use a strong password to avoid being blocked for bad edits by someone who guesses or "cracks" other editors' passwords. Users may access their account's preferences to change their password.

In general[edit]

Password strength requirements are explained in the password policy. For normal users, those requirements are enforced when an account is created and when a password is changed.

You should have a password that:

Do this, and your password is likely to be reasonably strong. The burden of using sufficiently strong passwords lies on you, the user. What this means is that if your account is compromised (for any reason), this will be treated as you not having used a sufficiently strong password.

Avoid linking to external sites from your user page and user talk pages, since this reveals a connection that can be used in an attempt to take over your Wikipedia user account.

If you need to use a public computer or connect your own computer to a public Wi-Fi network, consider establishing an alternative account (see WP:VALIDALT for important instructions and limitations) since malicious software or hardware could capture your password.

Accounts that appear to have been compromised may be blocked without warning; administrators will generally not unblock such accounts without evidence that their rightful owners solely control them.

Never, ever, share your password. Accounts with advanced permissions risk their permissions being revoked or account blocked due to violation of community trust and standards on account sharing.

Changing your password[edit]

Click on "Preferences" at the top right-hand corner of the page and then click the "Change Password" button on the "User Profile" tab to access the Special:ChangePassword page.

Failed login attempts[edit]

Anotification alerting a user of a failed login attempt from a new device

Through the notification system, you will be alerted when someone attempts and fails to log in to your account. Multiple alerts are bundled into one for an attempt from a new device/IP, but for a known device/IP, you get one alert for every 5 attempts.

If you receive this notification, don't worry! Your account is still secure. But even if you do have a strong password, you may want to change your password anyway, if you suspect that someone else has tried to access your account.

What to do when your account has been compromised[edit]

Information on what to do when your account has been compromised can be found at Wikipedia:Compromised accounts § After being compromised.

In a nutshell, you can help Wikipedia block access to the account and prevent malicious behavior. Do not expect to be able to regain control of the account.

What to do when your device has been compromised[edit]

Wikipedia's "Log out" link logs out all the user's current sessions. If a logged-in device is lost or stolen, changing the password and logging out on another device may help to prevent future abuse of the account on the lost device.

Privileged editors[edit]

On Wikipedia, only certain users (including administrators) can perform some actions. It is especially important that these privileged editors have strong passwords. Administrators, bureaucrats, checkusers, stewards and oversighters discovered to have weak passwords, or to have had their accounts compromised by a malicious person, may have their accounts blocked and their privileges removed on grounds of site security. In certain circumstances, the revocation of privileges may be permanent. Discretion on resysopping temporarily desysopped administrators is left to the Arbitration Committee, provided they can determine that the administrator is back in control of the previously compromised account.

Two-factor authentication (2FA)[edit]

Wikimedia's implementation of two-factor authentication (2FA) is a way of strengthening the security of your account. If you enable two-factor authentication, every time you log in you will be asked for a one-time six-digit number in addition to your password. This number can be provided by an app on your smartphone or other authentication device (called a TOTP client). In order to login you must know your password and have your authentication device available to generate the code.

Enrolling[edit]

To set up two-factor authentication:

Notes[edit]

For informal advice on personal security, including passwords, see Wikipedia:Personal security practices.

Users are encouraged to provide an email addressintheir preferences, as this enables them to reset their password via email if necessary. (Providing an email address also makes possible communications with other users via email; this can be disabled in preferences by unchecking the option "allow other users to email me".) Email alerts generated by the Wikipedia:Notifications system can also be sent to your email address, such as "failed login attempts" and "login from an unfamiliar device" notifications (these two messages are on by default, but are configurable in the notifications preferences).

See also[edit]


Retrieved from "https://en.wikipedia.org/w/index.php?title=Wikipedia:User_account_security&oldid=1230922031"

Categories: 
Wikipedia information pages
Wikipedia user account security
Hidden category: 
Wikipedia move-protected project pages
 



This page was last edited on 25 June 2024, at 12:46 (UTC).

Text is available under the Creative Commons Attribution-ShareAlike License 4.0; additional terms may apply. By using this site, you agree to the Terms of Use and Privacy Policy. Wikipedia® is a registered trademark of the Wikimedia Foundation, Inc., a non-profit organization.



Privacy policy

About Wikipedia

Disclaimers

Contact Wikipedia

Code of Conduct

Developers

Statistics

Cookie statement

Mobile view



Wikimedia Foundation
Powered by MediaWiki