11 ms·
GitHub will disable non-2FA accounts?
I just got a big splash in my profile page:
GitHub users are now required to enable two-factor authentication as an additional security measure. Your activity on GitHub includes you in this requirement. You will need to enable two-factor authentication on your account before September 28, 2023, or be restricted from account actions.
- sergiotapia 3y agoI'm sick of 2FA, if I wasn't forced I wouldn't use it for anything.
- warrenm 3y agoWhy would you intentionally not want to be more secure?
- yungporko 3y agoi swear the only thing that github actively work on is making it difficult to use. is there any similar free service that doesn't take an hour of troubleshooting every time you need to provide credentials?
- Am4TIfIsER0ppos 3y ago[flagged]
- mtmail 3y agogithub supports 2FA using authentication challenges, those work without phones or phone numbers.
- justinclift 3y agoIsn't that something that can only be set up after going through a process of enabling 2FA using your phone? Pretty sure I remember someone on here a few months ago trying to get GitHub 2FA set up, but as they have no (smart) phone there didn't seem to be any way of making it happen.
- egberts1 3y agoOnly a matter of time before they demand your phone number. You know, as part of their embrace, engulf, and extinguish strategy.
- deleted 3y ago[deleted]
- jjgreen 3y agoOther origins are available: https://gitlab.com/ https://gitlab.com/, https://codeberg.org/ https://codeberg.org/, ...
- countWSS 3y agoThanks, but many orgs and projects are basically locked in to github and wouldn't move without consensus(unless Github gets really shitty).
- jjgreen 3y agoTrue enough, crates.io being one of them https://github.com/rust-lang/crates.io/issues/326 https://github.com/rust-lang/crates.io/issues/326
- stephenr 3y agoSo enable 2fa. What's the problem here?
- johngladtj 3y agoI don't like 2fa and don't want to use it.
- warrenm 3y agoGuess you're allowed to not like something ...but not wanting to use something that demonstrably makes you more secure (and is practically cost-free) does not make you look good
- bsder 3y agoBecause it's not about 2FA. It will almost certainly be some shitty "We'll SMS your phone" thing in order to get your phone number. And this will enable attacks from my phone that weren't there before. Which actually makes me less secure. It also means that Apple or Google can screw me on Github because they can lock me out of my phone.
- jcotton42 3y agoNot only does GitHub not require SMS for 2FA, they discourage it https://docs.github.com/en/authentication/securing-your-account-with-two-factor-authentication-2fa/configuring-two-factor-authentication#configuring-two-factor-authentication-using-text-messages https://docs.github.com/en/authentication/securing-your-acco...
- bsder 3y agoA TOTP phone app is the same problem as SMS--my phone is the authenticator. It also provides a bunch of attack vectors like DDoSing my authenticator in order to get me to accidentally approve something. And if my phone battery is dead, I can't log in. And if my phone is stolen, I'm screwed. None of these things improve MY security experience.
- phendrenad2 3y agoGithub is just too annoying for use for personal projects now. This is the last straw for me. I already moved my projects to FTP.
- Reviving1514 3y agoAre you able to share some more info about your setup? How do you handle branches etc over FTP? My git usage is pretty basic but I've always been a bit uncomfortable about the idea of pushing my code to the "cloud" so would love to learn more.
- phendrenad2 3y agoWell for personal projects, I have no need for branches really. My commit history (if I were using git) would be entirely linear. So I really just need backup copies of my code at various points in the past, in case I need to revert a file or diff to find a bug. FTP is fine for my purposes, I just tar my code and copy it up to the server.
- vlod 3y agoNot sure if ftp is the most ideal way. That's how it was done in the old days and usually got screwed up with multiple people. If you have a server with ssh access, you can set up a 'bare' git repo (obviously you should back it up to somewhere else. i.e. s3 as a tar ball) and that should work for you.
- Lanedo 3y agoSpeaking of solutions, when you want to avoid using a phone, there is oathtool. For example for a GitHub 2FA Link like this: otpauth://totp/GitHub:username?secret=BLAHBLUBBLAH&issuer=GitHub You extract the secret and use it like this: oathtool --totp=sha1 --base32 BLAHBLUBBLAH 268685
- gettodachoppa 3y agoNot on my dev PC now (and dont want to access GH on this one). How do you get that 'otpauth://totp/GitHub:username?secret=BLAHBLUBBLAH&issuer=GitHub' path? Is it something you have to grab from the browser console?
- mistrial9 3y agowhat is that otpauth:// part about? $oathtool --totp - -b <enter 16digit code> 6digit result for MSFT-Github that works daily CLI; oathtool is packaged as part of OpenStack on GNU-Debian-Ubuntu
- SaberTail 3y agootpauth:// is a de-facto standard, since Google Authenticator uses it: https://github.com/google/google-authenticator/wiki/Key-Uri-Format https://github.com/google/google-authenticator/wiki/Key-Uri-... The TOTP QR codes decode to one of these URIs
- vczf 3y agoI was annoyed by this, because I really don't want to go back to relying on a third-party like Authy or Microsoft for 2FA, but I need to be able to sync my 2FA keys cross-platform and integrate with my backup system. Had the idea to store my 2FA inside keepass. To my delight, this feature already exists and is supported in KeepassXC and Keepass2Android.
- jasonjayr 3y agoThat's a handy feature; but PROBABLY should keep your 2FA token in a separate place than your passwords. At the very least, keep them in a separate keepass database with a different password .....