<blockquote>
<p>Why would someone take over someone else's OSM account? I can delete all your edits with an account I create afresh, why would I want to take over yours?</p>
</blockquote>
<p>I've no interest in taking over <a class="user-mention" data-hovercard-type="user" data-hovercard-url="/hovercards?user_id=899988" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/matkoniecz">@matkoniecz</a> user account. But as for yours, <a class="user-mention" data-hovercard-type="user" data-hovercard-url="/hovercards?user_id=705471" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/woodpeck">@woodpeck</a> - well, moderator privileges make a juicer target! Even more so for an admin account. We can't currently make any account-security checks before handing out elevated privileges, and there's a bunch of stuff which is hard to undo if a moderator or admin account with weak access gets hacked. Even a normal account has who-knows-what in the private messaging system, and "well password complexity is entirely up to the user to worry about" isn't something I want to hear.</p>
<p>So I'm supportive of this suggestion. But I would strongly suggest that it waits until we move our account signup process over to Devise. Implementation would be best then as a devise-compatible extension, or using existing extensions like <a href="https://github.com/devise-security/devise-security">https://github.com/devise-security/devise-security</a></p>
<p style="font-size:small;-webkit-text-size-adjust:none;color:#666;">—<br />You are receiving this because you are subscribed to this thread.<br />Reply to this email directly, <a href="https://github.com/openstreetmap/openstreetmap-website/issues/2285?email_source=notifications&email_token=AAK2OLPLAVHZYN2VJOKVOO3P6NGQVA5CNFSM4H4J4M52YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGODZNJKUQ#issuecomment-509252946">view it on GitHub</a>, or <a href="https://github.com/notifications/unsubscribe-auth/AAK2OLOI7OOC555W6H4YZBDP6NGQVANCNFSM4H4J4M5Q">mute the thread</a>.<img src="https://github.com/notifications/beacon/AAK2OLLUWKU7LGONH44TO2TP6NGQVA5CNFSM4H4J4M52YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGODZNJKUQ.gif" height="1" width="1" alt="" /></p>
<script type="application/ld+json">[
{
"@context": "http://schema.org",
"@type": "EmailMessage",
"potentialAction": {
"@type": "ViewAction",
"target": "https://github.com/openstreetmap/openstreetmap-website/issues/2285?email_source=notifications\u0026email_token=AAK2OLPLAVHZYN2VJOKVOO3P6NGQVA5CNFSM4H4J4M52YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGODZNJKUQ#issuecomment-509252946",
"url": "https://github.com/openstreetmap/openstreetmap-website/issues/2285?email_source=notifications\u0026email_token=AAK2OLPLAVHZYN2VJOKVOO3P6NGQVA5CNFSM4H4J4M52YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGODZNJKUQ#issuecomment-509252946",
"name": "View Issue"
},
"description": "View this Issue on GitHub",
"publisher": {
"@type": "Organization",
"name": "GitHub",
"url": "https://github.com"
}
}
]</script>