19 ms·
GitHub will require 2FA by the end of 2023
- Destiner 4y agoWonder whether it's related to attack on Heroku.
- _fat_santa 4y agoAnyone that uses Github day to day at work and for side projects should have already enabled it. When I think of what the "most important" account is to me, my Github page is pretty damn close to the top. Mine is currently 2FA with an automated script that will scan my Github and back everything up to GitLab (at least the "important" projects), which is also 2FA'd. Insane setup to protect data in one account but if I loose access it would be beyond a bad day for me.
- WithinReason 4y agoAm I the only one that thinks that 2FA actually increases the probability of losing access to an account? It's only a matter of losing the 2nd factor.
- bamboozled 4y agoGithub has alternative recovery methods though too, such as 2FA over SMS.
- Fuzzwah 4y agoAnd support can help out as long as you can show that you can ssh into a github host using the private key of one of the public ssh keys assigned to your account.
- jrochkind1 4y agoThat makes some sense, and seems to me a nice option. Is it documented anywhere that that is an option, that they will do that?
- jwilk 4y agoDocumented here: https://docs.github.com/en/authentication/securing-your-account-with-two-factor-authentication-2fa/recovering-your-account-if-you-lose-your-2fa-credentials https://docs.github.com/en/authentication/securing-your-acco...
- zhfliz 4y agoeasily solved by adding multiple MFA options, e.g. multiple security keys.
- johannes1234321 4y agoFor that there are the revoke code. And the backup phone number.
- Biganon 4y agoOr even better than the one time codes they give you, you can simply store the secret itself, on a piece of paper in a safe.
- jason0597 4y agoWhat people should do is have a small SD card with all of their private keys and passwords stored away safely. This SD card should be kept in cold storage (e.g. in a safe where you keep personal belongings), and never be accessed unless in absolute emergency (lost your YubiKey etc and can't get in anywhere, etc.)
- Lifelarper 4y agoSD cards are horrendous for long term storage. Probably the worst medium for such a task.
- adamiscool8 4y agoWhat is the best? Cursory googling suggests SD cards last ~decades at normal usage [0], and in this context where it's barely accessed, maybe longer? [0] https://www.sdcard.org/consumers/faq https://www.sdcard.org/consumers/faq
- 0x073 4y agoIf you go to bluray.com you probably can read the same only for blu-ray. Better search for a neutral source.
- _whiteCaps_ 4y agoI wrote some scripts to generate QR codes, then printed them to photo paper. https://github.com/alexjh/gpg-backup/blob/master/Makefile https://github.com/alexjh/gpg-backup/blob/master/Makefile Back then I thought that QR codes were a bit of a gimmick but now I'm way more confident that I'll be able to read them in the future.
- Brian_K_White 4y agolaser print
- justinclift 4y agoProbably depends on the quantity of data. If you're talking GB's or TB's of digital data, then maybe "archival grade" DVD's or BluRay's. https://www.verbatim.com.au/product-category/data-storage/optical-media/archival/ https://www.verbatim.com.au/product-category/data-storage/op... If it's instead just a few short strings of text (eg GH password recovery codes), then you could use physical storage. eg engrave the codes into something that'll survive extremes (granite?), and keep them in a fire proof safe. Or something along similar lines. Probably don't engrave into glass though, due to that potentially shattering in some situations.
- deadbunny 4y agoYou can have multiple second factors. I have 2 YubiKeys (one on me, one in a safe place) and then I have the standard TOTP codes on my phone using Authy. If I manage to lose my phone, live and backup yubikeys then I have recovery codes. It's going to have to be something pretty drastic to cause me to loose all of that.
- rstuart4133 4y agoWell, I've lost control of accounts and I suspect a few of us have. Fortunately the one I lost wasn't important. But my response wasn't to turn off 2FA. It was the reverse - to turn on all forms of authentication made available, for all acccouts. If I lost control of it one way, I had another. By the by, if you read the spec, FIDO expects you to do this in preparation for the day you lose your token. So no you are not the only one - people think about it all the time.
- IYasha 4y agoNo, we're here with you. I'm also wondering if being responsible for storing and using passwords is THAT BIG OF A DEAL??? Even mathematically, probabilities of two failing points are adding. I've been locked away from mail, banks and gods know what else just because I didn't have my phone or computer nearby, was in different country, in a place without network coverage, haven't paid for cell in time, etc. etc. etc. and absolutely positive that 2FA (at least that requiring on-line presence) is evil. The ONLY THING that can really protect and help you - is good HUMAN tech support. Where you can call, explain yourself, prove ownership and regain access to a service. Up to the point of having to go to of video-call office yourself and beyond. Yeah, I'm completely aware that some corporations don't even have humans (hello, Goolag!) employed - and trying to stay clear from them.
- kevdev 4y agoI don’t think that’s an insane setup at all. Losing access to GitHub would be bad for a lot of folks on HN I suspect. My GitHub has 2FA with Yubikeys and I am planning to do something similar to yours with backing up to a personal Gitea instance… once I get around to it.
- b112 4y agoMeanwhile, some use github once a year to file a bug report against an OSS project. Tiered access would be better here. No commits, repos without 2fa.
- Symbiote 4y agoIt's clear in the article's title, subtitle, first paragraph and bold quote thing that this does not affect someone handling issues and not code.
- sudobash1 4y agoThe post is talking about 2FA for > active contributors (for example, those who commit code, open or merge pull requests, use Actions, or publish packages) So it may not be required to simply file a bug report.
- sebmellen 4y agoWould you be able to share the GitHub to GitLab backup script?
- rapind 4y agoNit pick, but I wanted to point out that backing up your cloud data (github) to another cloud (gitlab) is increasing (approximately doubling) your attack surface. Good for data retention though.
- LordDragonfang 4y agoThis assumes that the "attacks" you're concerned with preventing are exfiltration of data, rather than mutation/deletion of data.
- cardanome 4y agoI just use different accounts for work and private stuff. For me 2FA is super annoying because I run my browsers in private mode and I restart them multiple times a day, so I have to sign in quite often. It effectively makes it much harder for me to keep my privacy. Not to mention loosing the freedom to log in to my accounts from everywhere without needing my devices. Things do get stolen/lost/destroyed and that is a more realistic threat for me than getting my password stolen.
- Decabytes 4y agoI feel like with the recent hackings done by Lapsus, it shows that 2FA can actually make it easier to break into a system. Since they first break into telecom companies, they can then sim swap and reset peoples passwords.
- Hamuko 4y agoEasier than what? Not having any 2FA at all? I don't really understand how it can be easier to break into a system if you need the username, the password and an SMS code, than if you just need an username and a password. Obviously, SMS two-factor authentication is flawed. But one-time codes and WebAuthn are pretty good two-factor authentication methods to secure important credentials.
- asimops 4y agoUsing phone numbers as a second factor should be in line with using MD5 for password hashing. It doesn't mean that MFA (or hashing) are a bad idea, just that you need to deploy it properly for it to make a difference.
- Apreche 4y agoThat's because SMS is not 2FA. Proper 2FA implementation should require FIDO, TOTP, etc. and not even permit SMS as a valid method.
- MattPalmer1086 4y agoNitpicking, but it absolutely is 2FA. Two factors for authentication. Password (something you know) and phone (something you have). It's not good 2fa, but it is 2fa.
- chrismorgan 4y agoYou’re talking about a completely different thing, SMS for password reset. That’s completely distinct from SMS as a second factor for logging in, which is absolutely fine for almost all people’s threat models, even in places where SIM or telco attacks are feasible, since the SIM alone is insufficient to log in as you. Sure, it’s common for sites to use your phone number both for 2FA and account recovery (whether single- or multi-factor—and single-factor account recovery is obviously a serious problem in a two-factor authentication environment), but the problem you’re complaining about is nothing to do with 2FA. I think Fastmail hits the right balance, and explains it well: https://www.fastmail.help/hc/en-us/articles/360058752374-Using-two-step-verification-2FA- https://www.fastmail.help/hc/en-us/articles/360058752374-Usi..., heading “Why do I have to add a recovery phone number to set up two-step verification?”
- Am4TIfIsER0ppos 4y ago
- mataug 4y ago> 2fa is a scam in part to force them to give up more data and in part to try to force people to use a government tracking device. Just remember this is Microsoft behind this. How is 2FA a scam ? Nowhere in the article is a phone number mentioned which is the only potential "government tracking device". The second factor can be an authenticator app, or even a FIDO device
- Am4TIfIsER0ppos 4y agoSometime in the not so distant future > Those old yubikeys [or similar HW device] have a flaw and are weak so we [read: the government] are deprecating them. You can change them here for the next year or use your phone or install our app. Further in the future after a few cycles of the above > Too few people use HW tokens so boot up your spy device now to log in. Maybe it won't be HW flaws maybe it will be software. Maybe they'll mandate use of some chrome only feature. Maybe they bring out the Xbox authentication drink cans.
- dane-pgp 4y agoWhen we all have Neuralink chips in our brains, they will be able to read the data from our taste buds to check that we are really drinking a genuine can of Doritos™ Mountain Dew™.
- hqball 4y agoThen I have to trust an app (which can have vulnerabilities) or a USB device which can be exchanged for a BAD-USB exploit carrier. That looks like offloading security issues to the user. Sounds far fetched? If the code repositories are that valuable, why wouldn't state actors try to mess with the hardware and commit underhanded C or similar? The repository owners would detect the malicious commit? Well, in that case, why do we need 2FA in the first place?
- 4y ago
- dimensionc132 4y ago
- sonicggg 4y agoLet's just remind ourselves that we're not born with attached cellphones. These things get broken, lost, stolen, etc. Besides, some people do not own one. How will they solve the problem of folks getting locked out? And if anyone says there is a workaround for cases like this, then what problem is it solving?
- jedberg 4y agoAuthy synchronizes across devices and works on a computer. If you're using Github then you at least have a computer. And using 2FA on your own computer at least guarantees that the access is from your computer. Sure, someone could hack your computer and get access to your GitHub, but if they're already on your computer, they can just change the code and do a git push too.
- fs111 4y agogithub will give you backup codes you can print out and use in case somthing bad happens. I personally have 2 yubikeys registered as the second factor and it works great. They last years w/o any problem.
- protomyth 4y agoWe had to buy yubikeys for various things since the whole cellphone thing wasn't going to work. You do have to buy multiple because of breakage or loss.
- cesarb 4y ago> github will give you backup codes you can print out and use in case somthing bad happens. The backup codes have a "nearly never used" issue: since they're nearly never used, it's easy to forget where you put that piece of paper (I vaguely know where mine might be located, but I'd have to lose some time searching for it if I ever needed it). And there's also the risk that the "something bad" affects both the TOTP device and the backup codes. If your home is flooded, for instance, you might lose to water damage both the piece of paper where the backup codes are and your mobile phone.
- mfer 4y ago
- AtNightWeCode 4y ago425% cost increase to enable SSO on Github. Just saying.
- deleted 4y ago[deleted]
- sebmellen 4y agoSo ridiculous. Really hurts for smaller startups.
- mbesto 4y agoIf you're small then the benefits of SSO aren't really there anyway. When you're a team of 10, what benefit is SSO really giving?
- orphean 4y agoI work in a small company and we have to have SSO for compliance reasons (SOC II, HIPAA, NIST, etc) It’s dumb but without it trying to tick all the compliance boxes is much more annoying.
- AtNightWeCode 4y agoYou go through a review, and somebody asks who this guy xxx123 is that made this change, and somebody vaguely recalls it is some consultant that for some reason still have access to everything but quit two years ago. Love those meetings.
- sebmellen 4y agoUnfortunately this is not true when you're trying to undergo a SOC 2 audit.
- mbesto 4y agoFirst, there is no requirement by SOC2 that says you "must use SSO for all applications". SOC2 talks about "logical access controls". For a team of 10, you would simply have a policy that states "any time a new developer comes on, they have to use MFA to access GitHub and this is enforced because we check the box in GH, blah blah" and "any time a developer leaves the company, we revoke all access, blah blah". Also, if you're going to spend $20k+ on SOC2 because your clients require it, then spending the $20k on GitHub shouldn't be a problem because your clients should be paying for it (i.e. your ACV should be high enough to cover these things).
- Longhanks 4y ago> At GitHub, we believe that our unique position as the home for all developers means that we have both an opportunity and a responsibility to raise the bar for security across the software development ecosystem. The fact that GitHub assumes to be in this position is alarming. Combined with this enforcement which I do not appreciate, I’m reconsidering my investment and will actively start migrating off of GitHub.
- kmlx 4y ago> The fact that GitHub assumes to be in this position is alarming. it's kind of true, isn't it (for certain programming languages)?
- staticassertion 4y ago
- natly 4y agoA nicer tone wouldn't hurt.
- staticassertion 4y agoI don't see what's mean about what I said, I'm quite excited to see this change already having positive impact.
- tarboreus 4y agoGoing to second that your tone is a bit on the snooty side. I'll go ahead and join OP and "self-select" my way out of the all-encompassing developer community that GitHub represents, leaving you pro coders to it. Enjoy the walls around your garden.
- staticassertion 4y agoExcellent stuff :)
- DocTomoe 4y agoIf this breaks my 'check in code automatically with ssh key authentication' workflow, I'll be shopping for another option.
- 101008 4y agoA colleague lost their phone and send an email to GitHub asking for a password and 2FA reset. It was sent from his account email and it was succesful. I found it weird because it means someone got access to his email Github would provide access to their account.
- teknopaul 4y ago2Fa is an excuse for we want more sales channels. You can put an auth cookie in a browser and achieve 2FA for 99% of use cases without bothering anyone. But nobody does that when they can use 2FA as an excuse to force people to install their app or hand over more personal information. No reason 2FA can't be just two passwords.
- tastyfreeze 4y ago2FA satisfies the "something you have" authentication type. Passwords satisfy the "something you know" type.
- na85 4y ago>2FA satisfies the "something you have" authentication type. In the general sense perhaps. As it's commonly implemented, no not really.
- staticassertion 4y ago> You can put an auth cookie in a browser and achieve 2FA for 99% of use cases without bothering anyone. Confusing, obviously incorrect. > No reason 2FA can't be just two passwords. Maybe somewhat less obviously incorrect, but still incorrect. Passwords can be phished easily, are managed by users, etc.
- jacobsenscott 4y agoIf you can phish the pw you can phish the totp. People type it in right after they type in the pw.
- jotm 4y agoOK, what's wrong with requiring a very strong password and not having any recovery option? If you lost/forgot your password, that's it, kiss your account goodbye. It puts the responsibility on the user, which is good imo. I've never lost a password. And the only time I lost a somewhat important account (Google) was because of their automated recovery system. If I could select "disable account recovery" the account would've never been highjacked... OK maybe it would've in a few decades when the average PC could bruteforce a 128 bit password in a reasonable amount of time and Google disabled rate limiting for some reason.
- jesushax 4y agoAllow me to commit career suicide with my counter argument. My laptop random shuts off at least once a day (the screen goes freeze, then goes pink, it's an M1 mac if that helps). My phone's screen is mostly crunched glass shards, and when I charge it, the correct voltage doesn't go through. I think the problem is the outlets where I'm living? Anyway, my own devices are the biggest risk in my threat model. Both my laptop (where I'd store the backup codes for GH MFA) and my phone (normal MFA authenticator app) turning into bricks is a WAY higher risk than someone stealing my Github password. I'm not even a part of any orgs, no maintained packages (not on the account I use now, anyways). So I could store my backup codes on the cloud, but Google is getting fussier every day about 'lack of backup device' or whatever. I could use a one time pad (and just memorize it), and store the encrypted backup codes on some kind of decentralized, permanent db. So a blockchain. But that costs money, and this is basically a venial irrelevant problem that I'm only complaining about to be a naysayer on this thread. So let's look for a free solution... Well, what about... free anonymous blogging solutions! I can publish it to a bunch of these. I can use memorable usernames. Now, I just have to remember the platform(s, plural, cause one platform is still risky, could get the account banned or something by doing this, so I'll want to use all the big ones, reddit, twitter, and so on), the usernames (which will all be the same, to accommodate memorization lol), the 2fa backup code one time pad, and of course the password itself. But I could use the password as the one time pad to lighten the load. And the username could be really easily made memorable. Yes! How easy is that? Okay, I'm going to try it out. If my approach is flawed, feel free to steal my GH account (as you can probably ascertain, it's a throwaway GH account, which is the only reason I'd be annoyed at having to 2FA for it). I'll report back to this threat and leave a response to myself once I have this set up, in case anyone else is curious.
- cmeacham98 4y agoWhy not just ... print out or write down the backup codes?
- jesushax 4y ago1. Don't own a printer 2. Don't want my hand to cramp 3. I'm being silly, everyone should use MFA
- coding123 4y agoBy 2030 all websites will require 2FA, SSL Client Checks, Real ID Verified and a blood pin prick.
- dane-pgp 4y agoYou joke, but device attestation is the next step, and the NSA are publicly pushing for it.[0] It's already impossible to get a burger from McDonald's using their app if you're using an unlocked bootloader.[1] [0] https://art.tools.ietf.org/id/draft-fedorkow-rats-network-device-attestation-01.html https://art.tools.ietf.org/id/draft-fedorkow-rats-network-de... [1] https://c.mi.com/thread-3882246-1-0.html https://c.mi.com/thread-3882246-1-0.html
- aaaaaaaaata 4y agoYou don't need a phone, or great deals, to interact with a food place.
- dane-pgp 4y agoFor now. Even before the pandemic, "delivery-only" restaurants were replacing brick-and-mortar ones: https://www.forbes.com/sites/michelinemaynard/2017/03/28/as-delivery-only-restaurants-spread-will-you-order-food-from-a-restaurant-that-doesnt-exist/ https://www.forbes.com/sites/michelinemaynard/2017/03/28/as-...
- butz 4y agoAre there any downsides to security keys as 2FA? Are they using a single standard that shouldn't accidentally change or be deprecated for some reason? Is it possible to use them on mobile devices? Are there any risks they might break? Any issues with Linux support? Which particular security key would you recommend and why?
- otachack 4y agoNot that I know of, but you should definitely at least enable a second form of 2FA like the recovery codes OR a second security key, then print/write/store the file/key somewhere. If you lose your primary, then you can use that secondary. Never just have 1 form of 2FA without a fallback.
- mzs 4y agoI don't have a cellphone or usb dongle and don't want them.
- waynesonfire 4y agoyou can get a tiny one and keep it plugged into your laptop
- mzs 4y agoOkay so which one do I buy and how do I use it with ssh. The documentation is not specific.
- waynesonfire 4y agoyubikey 5 nano, get two. i use it w/ ssh. took a little googling to integrate the gpg authentications key w/ ssh. instead of using ssh-agent, you'd use gpg-agent to manage the keys. there are other integrations, for example, i can also unlock my mac w/ the yubikey.
- newjersey 4y ago
- polote 4y agoThey do not give a single argument to show why they need to require 2FA, the same way they did not provide an argument for removing git password login. The more they will annoy users the more it will create space for a new service to compete with Github. Thanks Microsoft. The biggest problem with Github in my opinion, is that personal accounts are usually the same as the one we use in the company we work for. So we are mixing personal and professional security
- rapind 4y agoI think the argument has already been made for 2FA often enough though. So they probably just assumed everyone had heard it (wrongly perhaps?).
- egberts1 4y agoThat’s my cue … to exit GitHub … and Google mail as well I don’t have a phone number (that I am willing to fork over) so there’s that. Welcome me, GITLAB!
- tarentel 4y agoYou don't need to give your phone number to enable 2FA on github. They'll annoy you every few months to give them your phone number as a backup but you don't need to do that. I hope it's never required either.
- egberts1 4y agoThis is a Microsoft-owned subsidiary. They too will fall in line of choking you for a phone number.
- svnpenn 4y agoDon't they already offer a 2FA option now? Why not just let people use it who want to, and leave everyone else alone? I am an adult. If I want to sacrifice some security in the name of convenience, I should have that option. All this is doing, is pissing me off, and giving me one more reason to move to another platform.
- rapind 4y agoI think a good compromise is to allow organizations to opt to require 2FA in order to access their repositories, and allow individuals to opt to require 2FA for write permissions in their repositories (public or private).
- diablerouge 4y agoThe organizational control is already the case :) I had to set it up when I was added to my work's GitHub org.
- danirod 4y agoPSA: you should ALWAYS download the recovery codes when you enable 2FA. Reading a lot of "phone broken; locked out of account" comments here and I don't know whether they understand that local one-time only recovery codes should be downloaded and stored safely (maybe even printed and stored in a safe, I do not know). If you lose access to your 2FA device, use the "recovery code" option and use one of your recovery codes to unlock your account.
- kmlx 4y agoisn't it just better to use an app such as 1Password that can keep all your one-time passwords?
- photon-torpedo 4y agoThen if the password manager is compromised, the second factor wouldn't add any protection over just a password. Then again, people that use password managers at all usually have stronger passwords and less password reuse, so it can be an acceptable tradeoff.
- tomrod 4y agoAye, but it assumes the company isn't keep the password in plain text.
- tarentel 4y agoIn my case it wouldn't anyway. Almost all of my 2FA is tied to my password manager as well. I am sure I am not alone in this. It is kind of scary to think about though.
- tuckerman 4y agoI do the same but, for me, the threat of my password manager being compromised is much much smaller than the threat me not enabling 2FA out of laziness or the concern I might lose my 2FA codes. I keep my main email codes out of the password vault and that is enough to calm my nerves. Not everyone has the same risk profile/tolerance, but I just wanted to say that I don't think anyone should feel bad about doing the best they can, even if that stops short of the absolute best.
- hqball 4y agoWe need someone like Homakov again (https://arstechnica.com/information-technology/2012/03/hacker-commandeers-github-to-prove-vuln-in-ruby/ https://arstechnica.com/information-technology/2012/03/hacke...) so people can access their own repositories without this bureaucratic nonsense. If you have a strong password, is that really the biggest security threat? I highly doubt that. 2FA is used to get unique identifiers and data mine people. It is a breach of confidence that large parts of the open source scene has trusted GitHub and now has to jump through new hoops practically every year.
- akerl_ 4y agoTOTP doesn’t have any shared identifier, just a shared randomly generated secret. FIDO2 generates unique IDs for each user/site pair, so there’s no mining possible even if a user uses the same hardware token for multiple sites.
- potatoz2 4y agoI don’t think it’s true for the hardware token. The initial registration sends information about the token to the website (but the website can tell the browser it doesn’t need it, IIRC).
- TimWolla 4y agoWebAuthn supports sending an attestation certificate during the initial registration. But with an implementation according to the spec this certificate only identifies the model of the security key used and thus is shared across a 5 to 6 digit number of physical keys. This attestation is meant to allow the service to verify that you use a "blessed" security key with certain security properties (e.g. only a YubiKey 5 they verified to be secure and not some random $5 key with broken RNG off Amazon).
- codedokode 4y agoThis is bad. This, for example, allows sites to accept only government-approved hardware keys with backdoors and do not accept self-made secure keys.
- MikeKusold 4y agoThe blog post only mentions Mobile Push and WebAuthN. Is Github deprecating TOTP 2FA? I also can't believe how many people are complaining about requiring 2FA. I have 2FA enabled for every single service that gives you the option. Backup Codes live in my password manager, and I have multiple yubikeys that I enroll whenever it's an option. It's been 10 years since I started doing this, and I've never been locked out.
- 0xbadcafebee 4y agoFree services with 2FA are a recipe for problems. You will eventually have your phone stop working, you will lose your hardware fob, and you will lose your recovery codes that you forgot where you hid. There is no paid support, so you get what you pay for. Trying to get back into your account, if it's even possible, will take a long time and lots of work. If you are abroad and need access, you might be screwed. If it's not hard to get back into your account at that point, their security sucks. I think we all need to consider the possibility of moving off of GitHub, or at least keeping a mirror of everything on another provider, and making sure any long-lived services that pull from GitHub know the other provider to use. You don't want an account lockout to mean you've lost all your work.
- deleted 4y ago[deleted]
- throwntoday 4y agoAll great points and very common cases, yet services that force 2FA seem completely oblivious to this or just don't care about responsible users. In instances where it must be a phone number it is obviously for data mining. It is a lazy way to cater to the lowest common denominator of users who will eventually fall for a phishing scam or install some keylogger and have their password end up in a dump.
- jpalomaki 4y agoHaving support that is able to resolve 2FA problem creates new issues - how to prevent attacker from social engineering their way around support to gain access to your account. It’s hard to verify the identity online, across borders. IMHO there’s no good answers on global scale. Identity should be handled on local level. Government already has process for issuing me new tokens even if I would loose all my existing ways of proving my identity. Local organizations know how to verify my identity using those tokens. I already put lots of trust on my own bank on this, so maybe they could also manage my digital identity.
- 0xbadcafebee 4y agoOther providers do recovery by asking for a "secret code" that was only transmitted to you when you first signed up, or you can tell them to put a passphrase on your account. The first is more like a recovery code (but smaller), the latter is a second password you never use for anything else. Another solution is for users to upload identification documents when they sign up for the service. To recover your account, the service asks you to provide the documents again. This way it doesn't matter what the locality is, and you can provide literally anything (a picture of a duck!). Some providers have asked me to send a copy of my Driver's License before, but I don't think I had provided it to them before recovery, so that wasn't great. A couple startups are beginning to build "identity" products that I imagine will cover a lot of this space. I expect soon there will be one company that everyone uses for identity, and then rather than be at the mercy of GitHub, we'll be at the mercy of Sauron's Eye.
- staticassertion 4y agoWonderful news. Supply chain security is a disaster because developers won't opt into any kind of security features in the majority. Mandating 2FA is the obvious solution, and we'll all be radically safer for it. Glad to see Github pushing this, I hope package repositories follow suit!
- dane-pgp 4y agoThis change would certainly have helped against the infamous "Gathering weak npm credentials" research[0] from 2017, but I think that most recent supply chain security issues (in NPM, at least) have been due to: 1) typosquatting, 2) developers deliberately adding malicious (or unwanted) code into their own packages, and 3) deep transitive dependencies on packages that have genuine bugs that lead to vulnerabilities. It's not clear that this 2FA requirement would fix any of those problems, but it could one day allow package management tools to flag up when one developer has given/sold control of their package over to someone else who has less of a reputation and might be malicious, as was the case with the event-stream package.[1] [0] https://github.com/ChALkeR/notes/blob/master/Gathering-weak-npm-credentials.md https://github.com/ChALkeR/notes/blob/master/Gathering-weak-... [1] https://www.eweek.com/security/node.js-event-stream-hack-exposes-supply-chain-security-risks/ https://www.eweek.com/security/node.js-event-stream-hack-exp...
- staticassertion 4y agoYes, it definitely does not solve every problem.
- dane-pgp 4y agoFortunately no one is claiming that it does solve all problems, and I wasn't arguing against that non-claim. My point was, what percentage of supply chain issues (since that 2017 research) would have been mitigated by this policy change? To be extra clear, I'm not saying "This is a bad policy because it only stops some attacks", I'm just trying to get a sense of scale for how much this will help and how much more work needs to be done.
- cosmiccatnap 4y agoMeanwhile Spotify and Hulu still dont provide it as an option...
- gernb 4y agowhy do you need 2fa for either of those?
- spookthesunset 4y agoDo content creators have ask area to manage whatever songs they upload to Spotify? I actually don’t know! But if they do, I could see the need for 2FA on the content creator side.
- gernb 4y agoI wish they'd let me stay logged in longer. I use about 9 machines. On each machine I use 2-3 browsers. On some of those browsers I have several profiles. GitHub logs me out if I haven't used it in about 2 weeks. The result is I have to login with 2FA almost daily. it's super annoying
- waynesonfire 4y agobank sites do this too.. but they log you out after like 10 minutes of inactivity. The other day I was thinking of installing a plugin for firefox that will refresh a tab periodically. Not sure if that'll help the issue but worth a try.
- wink 4y agoMy bank's website is even worse. They won't let me log in if I had the landing page open for 10 minutes before logging in until I refresh...
- mzs 4y agoHow do I actually do this? I want to keep using ssh. I don't have and don't want a cellphone. I use FreeBSD. I can't find a simple explanation in the docs.
- scrollaway 4y agoUse any password manager (you should already be using one) that has TOTP support such as keepassxc or 1Password. No cellphone needed.
- throwntoday 4y agoWhy should someone be using a password manager? Generating needlessly complex, unique passwords for each service seems like a good way to lock yourself out of your own accounts in an emergency. Laptop or phone stolen? No access to your own devices? Oops guess you can't login to anything.
- technovader 4y agobecause it makes your passwords significantly less likely to be guessed
- throwntoday 4y agoI don't know of a single competent service that allows you to just guess passwords more than a few times.
- Beltalowda 4y agoThe biggest problem is re-using passwords. Remember when that LinkedIn password database with plaintext/md5 (easily brute-forced) was leaked a few years back? And who knows what's going on with Heroku right now. There's been dozens, hundreds, thousands of leaks like this, from well known sites like LinkedIn to that small independent webshop where you ordered something a few years ago. And for at least some people those credentials that worked on LinkedIn may also work on GitHub. Having a unique password per service solves that particular issue. But you're right that there's a "price" in that losing access to your passwords would leave you screwed. I'd strongly recommend making sure you at least memorize your email password, as well as backing it up in several places.
- adg001 4y agoIf for 2FA they mean a cellphone for the "offband" communication of a code, I am out.
- scrollaway 4y agoThey don’t. Reading the article would have answered that question.
- aseipp 4y agoIt's an article concerning GitHub and security --- so you can rest assured nobody will read the article and they will instead flail wildly about how this is Basically George Orwell Doing 1984.
- adg001 4y agoI don't know about you, but I don't have time for reading everything gets published on the web – this is why I framed my sentence in the hypothetical. Reading my comment would have clarified my own point of view.
- koolba 4y ago> Today, only approximately 16.5% of active GitHub users and 6.44% of npm users use one or more forms of 2FA. That's atrociously low. I know it's caveat emptor when it comes to FOSS, particularly as the nominal price is usually $0, but that really needs to be bumped up for anyone that is publishing packages to a public registry. I hope they both mandate it for NPM and publicly flog^Wflag any existing accounts as "2FA Not Enabled" so that users can use that information to make their own choices about which dependencies to include in their projects.
- svnpenn 4y ago> flag any existing accounts as "2FA Not Enabled" so that users can use that information to make their own choices about which dependencies to include in their projects. Fine, do that. I don't care. Just don't force me to use 2FA if I don't want to. I prefer the convenience over the extra security. This change removes that choice from everyone.
- deadbunny 4y agoHave you tried using something like a YubiKey? You literally just tap it and you're authenticated. No pulling out your phone and typing anything.
- svnpenn 4y agoI don't want to use 2FA, and I certainly don't want to have to buy something to use 2FA. What is hard to understand about that?
- deadbunny 4y agoIt sounded like you didn't like the hassle of using TOTP from a phone which is most people's complaint when using 2FA. I was offering a basically zero friction, more user friendly alternative which provides both convenience and security.
- 4y ago
- mdb31 4y agoWell, given that Github today doesn't seem to support meaningful 2FA (only TOTP and SMS), wouldn't it be good to fix that issue before starting to talk about requirements like these? Maybe it's just my account, but I can't currently enroll my hardware token with Github in any way whatsoever. Sure, they offer some 1.5FA, but why would I bother with that?
- einichi 4y agoThey let you enroll a hardware token after you enable either a TOTP or SMS 2FA method. No idea why, seems to defeat the point of the additional security that a hardware token offers.
- procombo 4y agoAuthenticator apps, and SMS help them derive you have identity -- which is more secure for them and you. Hardware token via WebAuthn (etc) is only more secure for you. When they say "for the sake of security" they mean for them too. There's a reason they want you to verify using one of the first two methods first.
- dns_snek 4y ago> Authenticator apps, and SMS help them derive you have identity How do they do that? TOTP (i.e. authenticator apps) is a simple algorithm where the value is derived from a secret key and current time. It certainly doesn't verify anything about you.
- anticensor 4y agoBy making the initial TOTP secret different for everyone.
- klaustopher 4y agoU2F has been supported for a while: https://docs.github.com/en/authentication/securing-your-account-with-two-factor-authentication-2fa/configuring-two-factor-authentication#configuring-two-factor-authentication-using-a-security-key https://docs.github.com/en/authentication/securing-your-acco...
- tedunangst 4y agoExcept it's not actually 2FA if all it takes is an ssh key to push. That's only one factor. Doesn't address the threat model of compromised developer machine.
- svnpenn 4y agoPlease, don't give them any more "good" ideas.
- newjersey 4y agoYes, if I need to fish out my phone and put in a code every time I need to git fetch a private repo, I will do everything I can to convince anyone who will listen away from GitHub
- aseipp 4y agoBut it's significantly easier, like way way easier, to phish someone versus compromise a filesystem and extract SSH keys. And you can just add keys afterwords if you phish them, so why wouldn't you go the easy route? That's why phishing is still such a massive problem: because it works.
- potatoz2 4y agoIf your SSH key is encrypted, it’s 2FA. Either way, it’s not phishable (unlike passwords) so it’s way safer.
- deadbunny 4y agoDerive you SSH key from a GPG key stored on a YubiKey[1] and even if you comprise the machine you don't get the keys. 1. https://github.com/drduh/YubiKey-Guide https://github.com/drduh/YubiKey-Guide
- throwntoday 4y ago2FA has screwed me over in multiple instances over the years across different services. Realizing one weekend away that I forgot to do a quiz for a uni course, trying to login to the course website on my phone and then remembering my hardware key is at home in my laptop. Being forced to add a phone number to secure accounts I could not give less of a shit about but have to use for one reason or another, coming back months later to login, and realizing it's an old number and I'm locked out. Emailing support in those cases and them just removing the phone number or changing it without any additional proof making the 2FA utterly useless. Or emailing support and them asking me to send some drivers license or ID, then politely telling them to just delete my account because they never had that much info about me anyway. 2FA is a scourge. Just let me worry about my own security, if I care about your service, I won't make my password "asdfghjkl". In 99% of cases, that is fine and I have never had an issue.
- exabrial 4y agoI wish my PGP key could be used as a root identity for my 2FA keys :/
- exabrial 4y agoGet rid of the stupid requirement for SMS or TOTP.
- abetusk 4y agoI appreciate that there's a response to the 'supply chain attack' issue, but this also seems like we're raising the bar further for participation. I'm still dubious as to whether a phone is required but even if it's not, this now puts a high bar for anyone who doesn't have a phone and creates all sorts of anonymity issues for people that do. Git is decentralized. My feeling is we should be focusing on technologies that lean into that idea. Inter-Planetary Version Control [0] looks to be a defunct project but hits the keywords that fit what I imagine to be a viable alternative. Does anyone know other alternatives? [0] https://github.com/martindbp/ipvc https://github.com/martindbp/ipvc
- throwaway92394 4y agoThere isn't be a need for a phone. TOTP (time based one time passwords) which Github supports is just an algorithm, you can (and many password managers have it too) run TOTP on the desktop. Whether this is a good idea or not is up for debate, but it doesn't require a phone, or even internet technically, just an accurate (within ~1 minute) time. EDIT: Typo should -> shouldn't EDIT2: to be more clear- shouldn't -> isn't
- abetusk 4y agoCan you provide some more context? In theory TOTP doesn't need a mobile phone (I guess) but in practice this is about whether GitHub, or anyone else, provides non-mobile 2FA options, either as an app running on the phone or by receiving a text message, say. See https://docs.github.com/en/authentication/securing-your-account-with-two-factor-authentication-2fa/configuring-two-factor-authentication https://docs.github.com/en/authentication/securing-your-acco... . I've only skimmed but I don't see anything in that list that doesn't require a mobile phone in one form or another.
- adolph 4y agoI wonder what this will mean for the relatively easy onramp for kids through Micro:bit and other tools? Maybe kids aren't supposed to directly access GitHub?
- aaaaaaaaata 4y agoDo they have an option for no SMS, just MFA?
- blippage 4y agoCan anyone ELI5? It seems that I will requires either SMS, a mobile app, or USB dongle. I'm not happy about any of these options. I'm not going to give away my phone number, I don't have a smartphone (I have a Nexus from 2012 though), and I don't want to fork out on dongles. Someone mentioned that keepassx being able to do it, but I'm a bit hazy on that. I've registered for a gitlab account just now, and I'll be messing around with that for awhile to see if I like it. If it proves tolerable, I'll probably be yanking the plug on github.
- jwilk 4y agoTOTP is one of the supported 2FA method. There's a lot of TOTP implementations that don't require having a separate device. And if you're not happy with any of them, this is such a simple protocol, you can write your own in one evening.
- blippage 4y agoSo, my understanding so far is that Github (or anyone, in general) will provide a private key consisting of 24 alphanum chars. Github also has a copy of the key. To authenticate, a password is generated based on the private key, which acts as a seed. That seed is combined with a timestamp in order to generate a password, which has an expiry time of about 1 minute. The algorithm that generates the password is a standard one, so once you know the algorithm, you can generate valid passwords. Linux provides "oathtool", which is suitable for such a purpose. Is my understanding correct on this?
- jwilk 4y ago> private key It's a "shared secret". ("private key" implies only one party knows it.) > 24 alphanum chars Hmm, https://datatracker.ietf.org/doc/html/rfc4226#section-4 https://datatracker.ietf.org/doc/html/rfc4226#section-4 says the key "MUST be at least 128 bits", meaning at least 26 (base-32) chars. My current TOTP secret (generated in 2018) for GitHub is only 20 chars. :-/ > Is my understanding correct on this? Yes.
- blippage 4y ago
- panny 4y agoWell, it seems like a good time to start migrating away from GitHub. When they can't be bothered to remove malware accounts like the node-ipc dudebro, but then claim they need a phone number from me to keep logged in for "security" ... I'll just leave. It's been a good run, I've had the account over 10 years, but I recently discovered Gitea is API compatible with GitHub. I can just make that my drop in replacement. I can even allow federated login with Keycloak + Gitea OIDC for anyone on GitHub who wants to log in on it and collaborate. Thanks for all the fish.
- KolenCh 4y agoYears ago when I setup a GitHub organization for our research collaborators, I initially mandates 2FA. But someone protested and brought up a point I’ve never considered—many of them needs to be on-site, like the Chile desert or South Pole, which has extreme environments. One collaborator briefed people going to Chile saying “if you love your device, don’t bring it to the site in Chile.” It is very high in altitude that can causes spinning HDD to fail. And the fine dust there getting into your device is no fun. So the consequence is that that don’t bring their phone to the site. They would leave it somewhere else before going up to the site. Needless to say that this 2FA requirement is a huge pain to them. There’s no second device for them. And even if someone could have a hardware key, those can becomes broken due to the reason above, and they don’t want that single point of failure to cause them trouble. So those people would basically try to defeat 2FA because of this. Eg our university requires 2FA to login to their network. They come up with a method to get the secret of the HOTP (from Duo, which is much less popular than TOTP that Eg Google use.) I also made a suggestion for those people to use SMS for 2FA and use Google Voice for the phone no. Again, another way to make 2FA works on a single device. P.S. needless to say on site they have servers and computers to collect data and analyze them. So they need to log in even if they don’t have a phone with them.
- itsTyrion 4y agoI disagree with requiring it in general. As soon as you admin repos, sure.
- jakeogh 4y agoIt's not 2 factor, it's ultimately 3rd party. I'll leave before I enable it.