Wikidot Password Policy Enforcement
This is the list of users who have moderator or administrator permissions on any of the following sites:
If they have multiple ranks, then the highest one is listed.
A person may be checked off the list if one of the following is true:
They are in compliance with the Wikidot Password Policy, and have affirmed as such to a different staff member.
The password must be at least 32 characters in length.
The password must be inherently random. Example generators: Random.org or Diceware
The password must not be reused. The password for the Wikidot account may not be the same as the password for any other account the individual has, past or present.
They give up any advanced permissions on the above sites. Do not pressure people into relinquishing permissions, this bullet is here for completeness.
Private Message Templates
The following can be used to explain to users on the list about the policy and what is required of them for it.
Discord
Hello, as part of a new security policy, we've been going around and ensuring that privileged Wikidot accounts have secure passwords as a safeguard against attacks. Anybody who has moderator or administrator permissions on the main site, O5, or one of the three official sandboxes will need to be in compliance with the policy.
The password requirements are as follows:
* The password must be **at least 32 characters** in length.
* The password must be **randomly generated**.
* The password must **not be reused**. This password should not be the same as for any other account you have, past or present.
Remember to keep the password somewhere secure so you don't forget it. Don't just keep it in your browser's "saved passwords" store. We recommend you use a secure password manager. Two such services are Bitwarden and 1Password.
**Do not share the password with me.** Once you have changed your password to a value that meets the requirements, affirm that you have done so and we can check your name off the list.
If you have any questions, feel free to ask.
Relevant resources:
* https://www.wikidot.com/account/settings (changing password)
* <https://random.org/passwords/> (random string password generation)
* <https://diceware.dmuth.org/> (word-based password generation)
Wikidot
Hello, as part of a new security policy, we've been going around and ensuring that privileged Wikidot accounts have secure passwords as a safeguard against attacks. Anybody who has moderator or administrator permissions on the main site, O5, or one of the three official sandboxes will need to be in compliance with the policy.
The password requirements are as follows:
* The password must be **at least 32 characters** in length.
* The password must be **randomly generated**.
* The password must **not be reused**. This password should not be the same as for any other account you have, past or present.
Remember to keep the password somewhere secure so you don't forget it. Don't just keep it in your browser's "saved passwords" store. We recommend you use a secure password manager. Two such services are Bitwarden and 1Password.
**Do not share the password with me.** Once you have changed your password to a value that meets the requirements, affirm that you have done so and we can check your name off the list.
If you have any questions, feel free to ask.
Relevant resources:
* https://www.wikidot.com/account/settings (changing password)
* [https://random.org/passwords/ Random.org (random string password generation)]
* [https://diceware.dmuth.org/ Diceware (word-based password generation)]