3 ms·
The code I upload to github is not part of "the software supply chain". Adding 2fa makes it more likely that I will lose access to my account. There is no way I
by usea 4y ago
The code I upload to github is not part of "the software supply chain". Adding 2fa makes it more likely that I will lose access to my account. There is no way I'm going to participate in this. I'm especially not giving github my phone number or in any way associating my mobile device with their website.
- capableweb 4y ago2FA != associating your mobile device. There are numerous devices you can use for TOTP 2FA, your computer, a hardware device and even your browser via authn.
- usea 4y agoI'm familiar with 2fa. It increases my risk and I'm not using it. I said I'm especially not using my phone. I did not say that 2fa = associating my mobile device.
- tzs 4y agoIt's pretty easy to add 2FA with almost no detectable increase in the risk of losing one's account. Pick TOTP as your 2FA method and save the TOTP secret, which you can get on the TOTP setup page at Github by clicking the thing that says you want to use a text code instead of scanning a QR code. It will give you a short text string. Save that string. When you need the TOTP code for Github, use oathtool [1] or something similar. For oathtool: oathtool --totp -b <aforementioned_string> will give you the current TOTP code. The -b flag tells it the code is in base32. I think that is what Gitgub uses. If they use hex omit -b. [1] https://www.nongnu.org/oath-toolkit/oathtool.1.html https://www.nongnu.org/oath-toolkit/oathtool.1.html
- usea 4y agoThank you. I was wrong, and I'm grateful for you taking the time to show me something.