3 ms·
We need someone like Homakov again (https://arstechnica.com/information-technology/2012/03/hacker-commandeers-github-to-prove-vuln-in-ruby/ https://arstechnica.
by hqball 4y ago
We need someone like Homakov again (https://arstechnica.com/information-technology/2012/03/hacker-commandeers-github-to-prove-vuln-in-ruby/ https://arstechnica.com/information-technology/2012/03/hacke...) so people can access their own repositories without this bureaucratic nonsense.
If you have a strong password, is that really the biggest security threat? I highly doubt that. 2FA is used to get unique identifiers and data mine people.
It is a breach of confidence that large parts of the open source scene has trusted GitHub and now has to jump through new hoops practically every year.
- akerl_ 4y agoTOTP doesn’t have any shared identifier, just a shared randomly generated secret. FIDO2 generates unique IDs for each user/site pair, so there’s no mining possible even if a user uses the same hardware token for multiple sites.
- potatoz2 4y agoI don’t think it’s true for the hardware token. The initial registration sends information about the token to the website (but the website can tell the browser it doesn’t need it, IIRC).
- TimWolla 4y agoWebAuthn supports sending an attestation certificate during the initial registration. But with an implementation according to the spec this certificate only identifies the model of the security key used and thus is shared across a 5 to 6 digit number of physical keys. This attestation is meant to allow the service to verify that you use a "blessed" security key with certain security properties (e.g. only a YubiKey 5 they verified to be secure and not some random $5 key with broken RNG off Amazon).
- codedokode 4y agoThis is bad. This, for example, allows sites to accept only government-approved hardware keys with backdoors and do not accept self-made secure keys.
- akerl_ 4y agoThis is intentional, given that “self-made” keys have plenty of ways to be insecure, and the average user cannot tell the difference between a well made key and one that is either accidentally or intentionally defective in ways that affect their security. FIDO2 is designed to maximize security for the majority of users, and the majority of users are using Yubikeys or other hardware-backed tokens provided by big players in their space.
- TimWolla 4y agoThis doesn't make sense. As a website author, why would I visibly restrict the security keys to backdoored government keys, when I can simply give the government an invisible backdoor API or direct database access?
- vel0city 4y ago> 2FA is used to get unique identifiers and data mine people. How do they get unique identifiers from TOTP?