4 ms·
Its a huge change and increased burden to ordinary users and "ordering users to use 2FA or else" is not the tone i'd expect from website that thrive on volunta
by countWSS 3y ago
Its a huge change and increased burden to
ordinary users and "ordering users to use 2FA or else"
is not the tone i'd expect from website that
thrive on voluntary participation, suddenly
dictating that i could only login with specific
setup from specific devices.
- stephenr 3y agoBy that logic, they should remove passwords too and just work on the honour system. Seriously though, if using a TOTP generator or physical security key is a "burden" for someone, I really doubt they're the target audience for GitHub. The benefits of 2FA are well known, and even if you have to enter the code manually (ie no browser integration) it's still arguably several orders of magnitude simpler in concept than most git operations.
- lesserknowndan 3y agoEverything is fine until you realise the person that had 2FA for your organisation’s github admin account left the company six months ago and has deleted their 2FA key. Also phones don’t seem to think it’s important to backup 2FA secrets so when you move devices you’re out of luck.
- warrenm 3y ago> Everything is fine until you realise the person that had 2FA for your organisation’s github admin account left the company six months ago and has deleted their 2FA key. What "organization" only has one person with access to the repositories? These hypotheticals become goofier with each iteration
- lesserknowndan 3y agoAccess to the Owner privilege is very different to having access to repositories. Many small organisations may only have one person with an Owner account for the very reason that they don’t _need_ to have multiple people with access to that account as you share out access to repositories to team members that have less privileged accounts. It is much “goofier” to assume that every organisation using Github has two people that have been granted an “Owner” level account.
- warrenm 3y agoI've yet to meet any organization that doesn't have at least 2 "owners" of a repo (that's in prod) Once you pass from single user to "organization", multiple "ownership" is du jour Maybe there are some out there - but they're stupid, if they are
- stephenr 3y ago> the person that had 2FA for your organisation’s github admin account Why doesn't your organisation have at least two people with the Owner role? > Also phones don’t seem to think it’s important to backup 2FA secrets I've been using a TOTP app with backup functionality since at least 2014, so its not exactly a new concept. If you choose not to avail yourself of one, that's on you.
- grayhatter 3y ago>Why doesn't your organisation have at least two people with the Owner role? It's simple, just never make any mistakes. > I've been using a TOTP app with backup functionality since at least 2014, so its not exactly a new concept. If you choose not to avail yourself of one, that's on you. You're right! how dare they not know everything that you know.... it's insane that someone might not do everything exactly the way you think it should be done! I get that's not what you're trying to say, but all you're doing is blaming humans for ignorance, or making mistakes. I'd assert, that given you clearly understand both security, and best practices, you'd be better equipped to help offer solutions instead of accusations, or blame.
- stephenr 3y agoNo, I'm blaming humans for wilful ignorance and insisting that there is no solution to problems they haven't tried to solve.
- mattl 3y ago