4 ms·
There isn't be a need for a phone. TOTP (time based one time passwords) which Github supports is just an algorithm, you can (and many password managers have it
by throwaway92394 4y ago
There isn't be a need for a phone. TOTP (time based one time passwords) which Github supports is just an algorithm, you can (and many password managers have it too) run TOTP on the desktop.
Whether this is a good idea or not is up for debate, but it doesn't require a phone, or even internet technically, just an accurate (within ~1 minute) time.
EDIT: Typo should -> shouldn't
EDIT2: to be more clear- shouldn't -> isn't
- abetusk 4y agoCan you provide some more context? In theory TOTP doesn't need a mobile phone (I guess) but in practice this is about whether GitHub, or anyone else, provides non-mobile 2FA options, either as an app running on the phone or by receiving a text message, say. See https://docs.github.com/en/authentication/securing-your-account-with-two-factor-authentication-2fa/configuring-two-factor-authentication https://docs.github.com/en/authentication/securing-your-acco... . I've only skimmed but I don't see anything in that list that doesn't require a mobile phone in one form or another.
- abraham 4y ago#1 says TOTP mobile app but any desktop app would work.
- akerl_ 4y ago1Password is in that list.
- vel0city 4y agoYou should try reading it instead of just skimming it. Their steps for using TOTP (the first list of steps!) do not say anything about putting in a mobile phone or list any requirements about adding a mobile phone. Then at the bottom for using a security key, it says "You must have already configured 2FA via a TOTP mobile app or via SMS". A TOTP app does not give out your phone number, does not rely on network connectivity, and does not require you use a mobile phone to use. So 2/3 of the options absolutely do not require you give Google your phone number.
- abetusk 4y agoThe answer is that many of the applications listed under "mobile apps" have a desktop version that one can use. I did only skim but doing a little more link diving on the prompting of other siblings comments in this thread shows that most of those programs have desktop versions. Your comment would leave the reader confused, including myself had I not dug deeper into each of those links, because you don't address the fundamental issue. The GitHub page says "mobile app" even though many of the applications can be installed on desktop. The line "You must have already configured 2FA via a TOTP mobile app or via SMS" further confuses the issue because this implies anyone wanting to use 2FA would need a mobile phone, which was precisely my point. A TOTP that doesn't give out your phone number, but still requires a mobile phone to use, technically doesn't need a working phone to use but practically does require a phone, so it's a kind of pedantic point you're making. Phones are a huge attack surface, if not from scammers then from applications, businesses or governments wanting to use it to monitor usage.
- vel0city 4y ago> implies anyone wanting to use 2FA would need a mobile phone I will acknowledge they probably shouldn't use the terminology "mobile app", but the most common way for people to use TOTP is with a mobile app which does TOTP. FWIW, there are many ways you can run a "mobile app" without using your primary phone, tablets also run "mobile apps" and there are tools to run such apps on your computer locally. This doesn't in any way give the service any kind of connectivity or access or tracking of your phone, and TOTP does not use any kind of network connectivity to operate. I'll agree the above is a pedantic point to be making, and I agree their documentation could be better worded, and I can understand there being a bit of confusion. However whether or not you need to use a mobile phone, if the solution is TOTP a la Google Authenticator/Microsoft Authenticator/LastPass/Authy/1Password (RFC 6238), the answer is always no. RFC 6238 does not require phone numbers, it does not require network access, its purely hashes on the current time and an initial shared secret. https://www.rfc-editor.org/rfc/rfc6238 https://www.rfc-editor.org/rfc/rfc6238
- SahAssar 4y agoI use TOTP on my desktop via a hardware key. There are many ways to do 2fa without phones as long as the provider does not consider 2fa to equal sms.
- dane-pgp 4y ago> There isn't be a need for a phone. You might need an "EDIT3", I'm afraid, because "isn't be" doesn't make that sentence much more clear.
- davchana 4y agoYes,all good points. Many vanilla javascript scripts are available to get this TOTP. The service provider can increase this 30 seconds (technically not, they just accept any 1 current time token = 30 seconds, any 3 token, 1 past, 1 current, 1 next = 90 seconds, and any number of past present tokens) to any multiple of 30 seconds. My personal scripts use 3 minutes.
- rsync 4y agoShow me a TOTP implementation that doesn’t require a phone number to sign up for or initialize… IME, they not only require a phone number at setup but, further, reject VOIP/twilio numbers. This shows that it’s not at all about security, but about slowing (but not solving) their brutal, unrelenting, spam and sock puppet problems. EDIT: Thanks - very interesting. I guess I am jaded by my experiences with 'authy' and twilio, etc.
- roblabla 4y agoTOTP never requires a phone number. On GitHub, they either show you a qr code you can scan in an app, or a text you can import. All apps support this sign up process, from google authenticator to console-based tools like totp[0]. Other 2FA implementations may require phone numbers. But HOTP and TOTP don't. [0]: https://github.com/arcanericky/totp https://github.com/arcanericky/totp
- istillwritecode 4y agoTOTP itself doesn't require a phone number, but the Authy phone app from Twilio managed to screw up their TOTP implementation and it requires a phone number. I filed a bug with them and they finally acknowledged that it's deeply embedded in their implementation.
- vel0city 4y agoWell, for starters, Github. I don't have a phone number on file with them and I have TOTP and FIDO available. The vast majority of sites I use TOTP on didn't require a phone number for the account.