4 ms·
SMS has been removed from the GitHub.com sudo page
- NoZebra120vClip 3y agoBravo. Let us encourage tech companies to take the lead in eliminating bad forms of 2FA such as SMS. Let them drive adoption of passkeys, U2F, FIDO, hardware keys, and other open standards. Someday, banks will join the 21st century.
- pjmlp 3y agoGood luck getting the elderly customers to adopt such practice. Naturally is their fault for not getting them, and should be punished with the 5 to 10 € for going to the counter.
- klohto 3y agoMy gran is gonna be pissed she cannot fork linux kernel now
- cmelbye 3y agoI’m probably missing something, but is there a reason why passkeys can’t entirely replace password+2FA and create a much simpler experience for everyone?
- pjmlp 3y agoPlenty of people don't have smartphones, or don't understand how to use them beyond phone calls and SMS, even if they do. Additionally there are plenty among them that are technology illiterate. These approaches only push them further away from society where only people that understand computers thrive.
- zb3 3y agoWhat if I lose my devices?
- zb3 3y agoThis will mean no 2FA for me and many others. I'll never set up a method that depends on me not losing a particular device or an account.
- zalyalov 3y agoUm, is SMS not tied to not losing a particular SIM card? I guess you can try to restore your number, do all operators provide this functionality?
- zb3 3y agoMy number is tied to my government issued ID. If I lose the SIM card I can get another one simply by showing my ID. If my ID gets stolen I can get another one by visiting the Police and so on. The point is - I have some kind of an enforceable legal right to that number, whereas I currently have no such right to any particular account (and such rights can't be practically enforced for physical objects such as devices)
- KirillPanov 3y agoIt sounds like what you really want is to outsource your security to the government. Maybe you should just say that's what you want.
- zb3 3y agoI'm pretty sure you're doing this already. We have courts for a reason, technocracy is a step backwards.
- prepend 3y agoYes, that’s what I want. There’s a much lower risk, for me, or government tyranny than me losing my yubikey. Note though that it varies depending on the thing protected. For GitHub, I’m cool with the risk that the government gets a subpoena to seize my phone or SIM card and log into GitHub. For some other services like messaging, I’d rather have stronger controls.
- gbraad 3y agoGood riddance. In my region I am unable to receive most of these messages (blocked), so I hate when webservices force phone verification onto me.
- AmenBreak 3y agoAnybody else opting out of passkeys and etc?