# Remove Coordinator role of inactive coordinators on bugs.python.org

**URL:** <https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866>\
**Category:** Committers\
**Created:** [February 11, 2019, 7:20pm UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866 "2019-02-11T19:20:31Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![vstinner](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/vstinner/32/15130_2.png) [@vstinner](https://discuss.python.org/u/vstinner)\
**Post date:** [February 11, 2019, 7:20pm UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/1 "2019-02-11T19:20:31Z")

</div>

Hi,

I asked too many times Ezio Melotti and R. David Murray to give the bug triage permission to a contributor, so they decided to give me the “Coordinator” role on [bugs.python.org](http://bugs.python.org) 🙂 I was worried that we had not enough “Coordinators”, but there are 26 Coordinators!

Problem: in the list, they are core devs who are inactive for more than 5 years. I’m worried about the security of [bugs.python.org](http://bugs.python.org), since the authentication is a “simple” login/password: there is no 2-factor authentication (2FA).

For security reasons, I suggest to remove the Coordinator role from inactive coordinators. I’m not sure how to identify who is inactive. Maybe just iterate on the list and check online activity (mailing list, discourse, bug tracker, GitHub, etc.) of each coordinator?

Once we have a list of inactive coordinators: send them an email to ask them if they want to keep this role. If they want to keep it: do nothing. If they don’t reply in 1 month: remove the role.

If a coordinator comes back, we will give them immediately the role again. It’s only a matter of security.

Another issue with inactive coordinators is to have an idea of how many moderators we have to handle spam on [bugs.python.org](http://bugs.python.org). Maybe they are way less than 26 persons looking frequently for spam?

Victor

---

<div class="post-metadata">

**Author:** ![nad](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/nad/32/51_2.png) [@nad](https://discuss.python.org/u/nad)\
**Post date:** [February 11, 2019, 7:27pm UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/2 "2019-02-11T19:27:05Z")

</div>

I think this is a topic for @EWDurbin as director of infrastructure.

---

<div class="post-metadata">

**Author:** ![Mariatta](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/mariatta/32/30581_2.png) [@Mariatta](https://discuss.python.org/u/Mariatta)\
**Post date:** [February 11, 2019, 7:28pm UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/3 "2019-02-11T19:28:02Z")

</div>

Maybe the list of coordinators should be made public somewhere? At the moment I don’t actually know who the coordinators are.

Removing inactive people from the list of coordinators sounds good. But I don’t think we should make assumptions based on lack of visible online activities. Many people still read emails to keep up, and I suppose the act of “coordinating” is not a visible one.

To start, I suggest emailing all the current coordinators and ask if they’re still active/want to keep the coordinator status.

---

<div class="post-metadata">

**Author:** ![vstinner](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/vstinner/32/15130_2.png) [@vstinner](https://discuss.python.org/u/vstinner)\
**Post date:** [February 11, 2019, 7:45pm UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/4 "2019-02-11T19:45:05Z")

</div>

The list is public but I don’t want to share the link right now because I don’t want to invite hackers to attempt to hack these accounts 😁

When I proposed to check online activities, it is just to not spam coordonitors who are active. But since the list is short, we can maybe mail all coordinators 😉

---

<div class="post-metadata">

**Author:** ![EWDurbin](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/ewdurbin/32/3103_2.png) [@EWDurbin](https://discuss.python.org/u/EWDurbin)\
**Post date:** [February 11, 2019, 8:02pm UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/5 "2019-02-11T20:02:55Z")

</div>

I’m happy to work to implement whatever the Core Devs and Steering Council agree on and notify those affected. 🙂

---

<div class="post-metadata">

**Author:** ![barry](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/barry/32/42_2.png) [@barry](https://discuss.python.org/u/barry)\
**Post date:** [February 11, 2019, 10:48pm UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/6 "2019-02-11T22:48:20Z")

</div>

> [@Mariatta](#):
>
> Maybe the list of coordinators should be made public somewhere? At the moment I don’t actually know who the coordinators are.

I don’t know if I’m a coordinator, but I’m happy to relinquish this role.

---

<div class="post-metadata">

**Author:** ![njs](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/njs/32/204_2.png) [@njs](https://discuss.python.org/u/njs)\
**Post date:** [February 12, 2019, 12:11am UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/7 "2019-02-12T00:11:16Z")

</div>

Is there any kind of audit log for when people use their “coordinator” powers? One elegant way to do this would be to pull out a list of everyone who’s actually used this in the last, say, year, then email the rest to thank them and tell them that they’ll be removed from the list in X days unless they speak up.

---

<div class="post-metadata">

**Author:** ![Mariatta](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/mariatta/32/30581_2.png) [@Mariatta](https://discuss.python.org/u/Mariatta)\
**Post date:** [February 12, 2019, 12:41am UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/8 "2019-02-12T00:41:05Z")

</div>

> [@barry](#):
>
> I don’t know if I’m a coordinator, but I’m happy to relinquish this role.

Victor showed me how to find the list of coordinators. You’re in it!

---

<div class="post-metadata">

**Author:** ![barry](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/barry/32/42_2.png) [@barry](https://discuss.python.org/u/barry)\
**Post date:** [February 12, 2019, 12:42am UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/9 "2019-02-12T00:42:39Z")

</div>

Oh, yay! Feel free to remove these perms.

---

<div class="post-metadata">

**Author:** ![brettcannon](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/brettcannon/32/34895_2.png) [@brettcannon](https://discuss.python.org/u/brettcannon)\
**Post date:** [February 12, 2019, 1:47am UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/10 "2019-02-12T01:47:25Z")

</div>

> [@vstinner](#):
>
> For security reasons, I suggest to remove the Coordinator role from inactive coordinators. I’m not sure how to identify who is inactive. Maybe just iterate on the list and check online activity (mailing list, discourse, bug tracker, GitHub, etc.) of each coordinator?

We can make removing the role be part of becoming inactive. Otherwise we can clean up access like for GitHub admin access and simply heavily restrict it as we don’t need that many people to be able to add folks since it’s so low bandwidth.

---

<div class="post-metadata">

**Author:** ![vstinner](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/vstinner/32/15130_2.png) [@vstinner](https://discuss.python.org/u/vstinner)\
**Post date:** [February 12, 2019, 11:22am UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/11 "2019-02-12T11:22:54Z")

</div>

> [@brettcannon](#):
>
> We can make removing the role be part of becoming inactive.

There is an ongoing discussions about “inactive core developers”, but nothing happened in practice yet. So I propose to make the most obvious and least controversial change first: just remove the Coordinator role from inactive core devs on the bug tracker, for security reasons. It’s an hidden change, it doesn’t have to be announced or mentioned anywhere 🙂

By the way, I am a supporter of moving inactive core devs to a dedicated list. The [PEP 13 has a paragraph about that](https://www.python.org/dev/peps/pep-0013/#membership):

> There’s no time limit on core team membership. However, in order to provide the general public with a reasonable idea of how many people maintain Python, core team members who have stopped contributing are encouraged to declare themselves as “inactive”. Those who haven’t made any non-trivial contribution in two years may be asked to move themselves to this category, and moved there if they don’t respond. To record and honor their contributions, inactive team members will continue to be listed alongside active core team members; and, if they later resume contributing, they can switch back to active status at will. While someone is in inactive status, though, they lose their active privileges like voting or nominating for the steering council, and commit access.

Again, that would require more work: create such list of “inactive”/“emeritus” core devs, contact _all_ core devs (+150?), not just 28 coordinators.

I prefer to start with a small step.

To be more explicit, I’m concerned by that the fact that XXX (hidden name) is still a Coordinator whereas he didn’t show up in Python since 2013 (6 years ago). Again, I would be very happy to give him back the Coordinator role as soon as he comes back. But in the meanwhile, I prefer to reduce the attack surface. It’s not like leaked password databases are uncommon on the Internet nowadays. See for example [https://haveibeenpwned.com/](https://haveibeenpwned.com/) I checked his email address and this website says " Pwned on 8 breached sites and found 1 paste"… He didn’t change his [bugs.python.org](http://bugs.python.org) password since 2011…

If someone has a good reason to not remove the Coordinator role from inactive coordinators, maybe another option would be to set a random strong password and/or force their account to reset their password?

---

<div class="post-metadata">

**Author:** ![brettcannon](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/brettcannon/32/34895_2.png) [@brettcannon](https://discuss.python.org/u/brettcannon)\
**Post date:** [February 13, 2019, 12:26am UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/12 "2019-02-13T00:26:39Z")

</div>

> [@vstinner](#):
>
> So I propose to make the most obvious and least controversial change first: just remove the Coordinator role from inactive core devs on the bug tracker, for security reasons. It’s an hidden change, it doesn’t have to be announced or mentioned anywhere 🙂

I didn’t mean to come off like I didn’t agree with that. I’m just saying if we’re looking for clarification for a way to stay on top of things, tying it to when we update the list of (in)active core devs is an option.

---

<div class="post-metadata">

**Author:** ![vstinner](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/vstinner/32/15130_2.png) [@vstinner](https://discuss.python.org/u/vstinner)\
**Post date:** [February 13, 2019, 11:40pm UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/13 "2019-02-13T23:40:16Z")

</div>

So far, I didn’t see anyone was is opposed to my email, so I plan to send the following email next week. If someone doesn’t reply, I can try another ways to reach them (another email address, Twitter, whatever). If I really get no answer or if the coordinator asked to drop his role, I will send a list to @EWDurbin. Are you ok with this process? If you don’t reply, I consider that you agree. If you disagree, please speak up 🙂

Email:

> Action needed: please confirm that you are still using [bugs.python.org](http://bugs.python.org)
> 
> Hi NAME,
> 
> tl; dr If you don’t reply to this email before 1 month, I will remove the Coordinator role from your [bugs.python.org](http://bugs.python.org).
> 
> How are you?
> 
> I’m working on the security of the Python infrastructure. Currently, [bugs.python.org](http://bugs.python.org) doesn’t offer 2-factor authentication (2FA) yet, but only “basic” login/password authentication. Sadly, password breaches are becoming more and more common. For example, enter your email at [https://haveibeenpwned.com/](https://haveibeenpwned.com/) to check if one of your password leaked somewhere.
> 
> For this reason, I would like to ensure that bug tracker users with the “Coordinator” role (highest privilege) still have access to their email address and maybe also changed their password in the last 5 years. Your account has the Coordinator role.
> 
> My question for you is simple: are you still working on the Python project / are you still using the bug tracker?
> 
> Even if don’t use actively your Coordinator role, that’s fine. I’m only concerned about core developers who didn’t show up in Python the last year.
> 
> If I don’t get a reply to this email, I will remove the Coordinator role from your account. If you missed this email or if you want to get this role back, don’t worry! I will add it back to your account as soon as you ask for it!
> 
> Victor

Oh, about the password: I noticed [bugs.python.org](http://bugs.python.org) switched PBKDF2, but I don’t know when.

Maybe I can also ask coordinators who don’t have their password hashed by PBKDF2 to change their password? At [User 2377: [hidden] - Python tracker](https://bugs.python.org/user2377) (my account), I can read for example:

`2017-06-20 22:20:02 vstinner set password: {PBKDF2}*encrypted* -> {PBKDF2}*encrypted*`

---

<div class="post-metadata">

**Author:** ![nad](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/nad/32/51_2.png) [@nad](https://discuss.python.org/u/nad)\
**Post date:** [February 14, 2019, 12:07am UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/14 "2019-02-14T00:07:59Z")

</div>

Contacting the people with admin privs sounds fine but I think that we should let the Director of Infrastructure handle this. That’s what he’s being paid to do 🙂 And he’s already volunteered.

---

<div class="post-metadata">

**Author:** ![vstinner](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/vstinner/32/15130_2.png) [@vstinner](https://discuss.python.org/u/vstinner)\
**Post date:** [February 14, 2019, 12:10am UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/15 "2019-02-14T00:10:39Z")

</div>

> [@nad](#):
>
> Contacting the people with admin privs sounds fine but I think that we should let the Director of Infrastructure handle this. That’s what he’s being paid to do 🙂 And he’s already volunteered.

Hum, it seems like I misunderstood @EWDurbin message. I understood that he wanted me or someone else to send the email.

If @EWDurbin can or should do it, please go ahead! I only care about the security of [bugs.python.org](http://bugs.python.org), I don’t care who send the email and/or remove the role.

---

<div class="post-metadata">

**Author:** ![vstinner](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/vstinner/32/15130_2.png) [@vstinner](https://discuss.python.org/u/vstinner)\
**Post date:** [February 21, 2019, 4:46pm UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/16 "2019-02-21T16:46:33Z")

</div>

@EWDurbin: I sent you an email with a few more details. So, what do you think? Should we send an email to [bugs.python.org](http://bugs.python.org) coordinators?

---

<div class="post-metadata">

**Author:** ![EWDurbin](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/ewdurbin/32/3103_2.png) [@EWDurbin](https://discuss.python.org/u/EWDurbin)\
**Post date:** [February 27, 2019, 5:15pm UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/17 "2019-02-27T17:15:47Z")

</div>

I’m reviewing this now!

---

<div class="post-metadata">

**Author:** ![vstinner](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/vstinner/32/15130_2.png) [@vstinner](https://discuss.python.org/u/vstinner)\
**Post date:** [March 26, 2019, 11:51am UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/18 "2019-03-26T11:51:43Z")

</div>

@EWDurbin: Hello, any update on this topic? Have you contacted inactive coordinators? Do they still have the Coordinator role in the bug tracker?

---

<div class="post-metadata">

**Author:** ![vstinner](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/vstinner/32/15130_2.png) [@vstinner](https://discuss.python.org/u/vstinner)\
**Post date:** [June 25, 2019, 12:45pm UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/19 "2019-06-25T12:45:06Z")

</div>

Right now, [Martin v. Löwis](https://bugs.python.org/user8) still has the Coordinator role, whereas he is no longer contributing to Python for at least 5 years. The last time he changed his password was 8 years ago (hopefully, it’s hashed by PBKDF2).

@EWDurbin: Did you try to reach Martin?

There are currently [23 users with the Coordinator role](https://bugs.python.org/user?username=&realname=&roles=Coordinator&%40action=search). My question is if the following users are still around or want to keep their Coordinator role.

- georg.brandl
- jafo
- forsberg
- bwaliszewski
- loewis

---

<div class="post-metadata">

**Author:** ![vstinner](https://sea2.discourse-cdn.com/flex002/user_avatar/discuss.python.org/vstinner/32/15130_2.png) [@vstinner](https://discuss.python.org/u/vstinner)\
**Post date:** [June 25, 2019, 12:48pm UTC](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866/20 "2019-06-25T12:48:57Z")

</div>

> [@barry](#):
>
> I don’t know if I’m a coordinator, but I’m happy to relinquish this role.

@barry: Would you still like to lose your Coordinator role? I will remove it if you want. Or go to [User 19: [hidden] - Python tracker](https://bugs.python.org/user19) and remove “,Coordinator” from Roles and submit changes 😉

[Next page](https://discuss.python.org/t/remove-coordinator-role-of-inactive-coordinators-on-bugs-python-org/866.md?page=2)
