3 ms·
> You can't authenticate over HTTPS anymore You can, just no longer using username and password. Instead you must use an access token.
by TimWolla 5y ago
> You can't authenticate over HTTPS anymore
You can, just no longer using username and password. Instead you must use an access token.
- hunter2_ 5y agoFor accounts without MFA enabled (which are the only ones who were able to use username/password via https in the first place), is the token granted after supplying just username and password, and if so, what's the real improvement? I see here [0] a few benefits listed: > Unique – tokens are specific to GitHub and can be generated per use or per device > Revocable – tokens can can be individually revoked at any time without needing to update unaffected credentials > Limited – tokens can be narrowly scoped to allow only the access necessary for the use case > Random – tokens are not subject to the types of dictionary or brute force attempts that simpler passwords that you need to remember or enter regularly might be ...but if you can trivially obtain it by supplying username/password, then it's effectively equivalent anyway. [0] https://github.blog/2020-12-15-token-authentication-requirements-for-git-operations/ https://github.blog/2020-12-15-token-authentication-requirem...
- jfrunyon 5y agoYou can not obtain the username/password from the token.
- hunter2_ 5y agoAh, that makes sense, for the case of losing control of (e.g., accidentally committing) the git connection credentials: better to just revoke a token than rotate the password after having potentially also lost control of whatever else uses the same password.
- simonklitj 5y agoYup, and when you create a token they advise to give it an expiration date, just in case it ends up somewhere down the road.