Last modified: 2006-10-21 14:05:25 UTC
Today I got spammed. Over 30 new passwords... :S Some funny guy requested a new password for me over 30 times, and over 30 times i received an email. This is not really something fun, and is a way to get people a hard life. Is it possible to limit the request for a new password to once per hour for every user? Please, make that possible, because this is not the first time, however this is the first time it is in this amount. Thanks a lot, you prevent a very nasty kind of spamattack with this. Effeietsanders
*** Bug 5799 has been marked as a duplicate of this bug. ***
Fixed in SVN trunk, r14200. Requests can now be throttled with the rate limiter.
*** Bug 4227 has been marked as a duplicate of this bug. ***
see bug 7078 for the request to enable it on Wikimedia's wikis
A way to solve the use of this function to generate spam toward unknown address would be to ask the user to supply his/her e-mail address and only if the given e-mail address is the same of the one in the user configuration the password is sent. This system would however open a new problem: how to manage users that have lost their password and do not remember what e-mail address have used? (a possible way to solve this new problem would be to allow some very trusted user -like the one with checkuser privilege- to be able to generate the password sending without specifing the address)
note: this is not about *disabling* the possibility, but about limiting it. Like once per day. Don't tell me you forget your password more then once a day ;-)