troed wrote: 14 Nov 2023 16:25
I think that's fair. The other option would be to set new secure passwords and send out to those users who are "reconizable" - but it's more admin and you and others are already doing an immense effort bringing this back.
Working out who whos could be a lot of effort. For example..
One entry is simply this, no real name and it almost looks like a spam account. However whoever this is, must be something to do with Atari legend as there is a lot of game related posts if I remember rightly..
1.PNG
But then later there is a lot of these...
2.PNG
Most probably spam accounts, but the number of characters is not consistent. So "Rb" could get filtered out if I used "real name" as a detection field.
I don't think there is a massive amount of users anyway. Maybe 100. The database seems to be protecting the passwords from me changing them as well. But I have not tried a scripted method yet.. If users are kept I need to work out how to force the change of a new password..
Though there is also the question of how many of these people would still contribute to the wiki. A lot of the email addresses and accounts could be 10-20+ years old and no longer valid anyway. There is something like 1.8 million user accounts as well.
It is my preference to at least try and save the users because they are, for the most part, linked to posts on the wiki. Though some users both seem to have been edited by spam bots somehow as well.
Currently I'm still deleting out the spam from the main database. At least when I can get it down from a 39GB database, it should help allow me to run more scripts on lower amount of RAM required on the server. It's a bit of a 2-step problem of sorts. As the spam is deleted I get user IDs of who posted it, so I need to write a script that will delete any remaining posts by that user ID, but that might not be needed. I don't know yet. The users will get cleared out because there will be no corresponding posts to that account afterwards. It is just a matter of waiting for the scripts to finish to see what chaos is still left afterwards and then do more delicate scripts as the database gets in a more manageable size.
I have not looked at the tools for the wiki yet but if there is a tool to force reactivation of all accounts with a new password then that would probably be a useful tool. Anyone which does not reactivate will have their account deleted. Though people can always reregister anyway. The main issue is security in all this and having a lot of accounts with unknown password strengths from 20 years ago isn't exactly a good start.