3 ms·
I'm glad that someone had the energy to write about this because it bothered me too. First, with regard to comments re: SMS & phone numbers, it required a non-
by follower 3y ago
I'm glad that someone had the energy to write about this because it bothered me too.
First, with regard to comments re: SMS & phone numbers, it required a non-zero amount of research to discover that GH no longer requires or recommends use of SMS--so it's not unreasonable to not know this.
Second, there are a long list of issues that I have with both the policy & its roll-out but they can be summarised as "different people have different risk profiles" & "in this situation individual developers (the people whose free labour GH was built on) have the least amount of power".
There's a distinct lack of nuance in the implementation/roll-out & 2FA is being used as a blunt weapon because it's easier than accommodating individual developers needs.
At this current point in time the group of people affected is "all users who contribute code"[0] but it's presumably not--it's actually developers who have contributed code. There's no option to keep one's account & use it only for e.g. issue creation/commenting going forward.
(Also, it seems doubtful that this requirement is actually limited to people who "contribute code" but rather seems likely to also include people who "contribute" text files.)
Yes, security is important but it's also always a trade-off. Why isn't it up to individual projects to decide whether to only restrict code contributions to those people with 2FA?
The language used in communication about the changes is also twee[1] (for lack of a better word) and downplays the reality of the situation which is that if you don't enable 2FA or if you enable 2FA and then get locked out of your account you will lose access to the account & history--especially the "non-code" features.
At least on the main docs[2] it's more straight-forward about the situation.
If you don't understand what the problem is then, congratulations, you're probably not one of the people whose first thought in this situation is "if I enable 2FA there's a non-zero chance that in the future I'm going to lose access to all the possible account recovery methods". Which means you probably don't feel at risk of becoming homeless, don't have ADHD or exist in a myriad of contexts where such concerns do exist.
Did MS/GH consult with any disability/inclusiveness specialists when implementing the policy?
Also, the impact isn't just limited to GH when projects like Rust's crates.io also use GH for authentication.
[0] https://github.blog/2022-12-14-raising-the-bar-for-software-security-next-steps-for-github-com-2fa/ https://github.blog/2022-12-14-raising-the-bar-for-software-... Although in another place it says "active contributors" <https://github.blog/changelog/2022-11-21-updates-to-the-two-factor-authentication-setup-flow/ https://github.blog/changelog/2022-11-21-updates-to-the-two-...>.
[1] "...it’s easy to start fresh with a new GitHub.com account and keep that contribution graph rightfully green." https://github.blog/2023-03-09-raising-the-bar-for-software-security-github-2fa-begins-march-13/ https://github.blog/2023-03-09-raising-the-bar-for-software-...
[2] https://docs.github.com/en/authentication/securing-your-account-with-two-factor-authentication-2fa/recovering-your-account-if-you-lose-your-2fa-credentials https://docs.github.com/en/authentication/securing-your-acco...