Background
Although Wikipedia:User account security has contained standard advice for password strength for some time, the English-language Wikipedia did not have password requirements for any user group for its first fourteen years. In late 2015, there was a security breaching incident involving users with advanced permisssions that led to a security review. That review resulted in password requirements for some users with advanced permissions, and advised changes to global policy and auditing and enforcement by the Wikimedia Foundation.
Application
While all users are strongly advised to maintain a strong password, the policy requirements are only binding on the following user groups:
Additionally, the community recommended that global policy require the steward and founder user groups follow these same requirements. Jimbo Wales, as sole member of the "founder" user group voluntarily agreed to comply with these requirements.
A password strength meter is to be added to the signup/change password screen in order to assist users in determining if their password is considered strong.
Requirements
- Passwords must be at least 8 bytes in length.
- Passwords should not be on the list of the 10,000 most common passwords. This list is not yet available.
Enforcement and auditing
A password strength bar (yet to be implemented) will help these users determine if they are meeting these requirements. Regular auditing of administrator and functionary passwords is to be done by the Foundation, through a process and at intervals as yet to be determined.
Users with advanced permissions who are found to be out of compliance with these requirements may have their permissions revoked until they have made adequate assurances that they have rectified the issue. Users who repeatedly fail to maintain a strong password may have their permissions permanently revoked by the Arbitration Committee.