4 ms·
I now regularly get messages and a constant banner across GitHub about needing 2FA. I don't want to hook my phone up to another service and I don't consider a p
by bArray 3y ago
I now regularly get messages and a constant banner across GitHub about needing 2FA. I don't want to hook my phone up to another service and I don't consider a phone proper security. I'll move my code somewhere else where they don't force their 'security measures' on me and have bots scraping my code to build an AI to replace me.
- heinrich5991 3y agoYou can do TOTP on any general purpose computer.
- circuit10 3y agoI can even do it on my calculator It’s also built into some password managers
- deleted 3y ago[deleted]
- master-lincoln 3y ago2FA != phone number needed There are other options
- rjmunro 3y agoThese messages are correct. You need 2FA. Passwords alone are not good enough security. It doesn't have to be via your phone if you don't want it to be. You can buy a YubiKey or similar, or use something like https://github.com/simnalamburt/macos-totp-cli https://github.com/simnalamburt/macos-totp-cli (I haven't tried it, just the first thing I found in a google search).
- martin_a 3y ago> Passwords alone are not good enough security. This made me think for a moment. Why not, though? My password manager generates random passwords with numbers, special characters and whatnot with a length of 24 characters. Even I don't know most of my passwords at this point, so what's the problem with (secure) passwords? Poor application security? That's not really my problem, is it? edit: to add this. I know that "test123" would be a problem, but my secure passwords can not be guessed by anybody or really be bruteforced. so, what does 2FA really protect me from in those cases?
- christofosho 3y agoIf someone does happen upon your password, they probably won't also have your 2fa. That's how I view it. Safety in layers.
- yreg 3y agoI think they probably will have my 2fa, because then they've probably pwned my computer.
- bArray 3y ago> You need 2FA. I don't trust Microsoft with my phone, and I don't want logging into my account to become a pain where I need a key. I'll just take my code elsewhere. > Passwords alone are not good enough security. Security will only ever be as good as the weakest part - and I happen to find phones pretty weak.
- circuit10 3y agoHere’s a video addressing all that: https://youtu.be/kvTdea7Uh3w https://youtu.be/kvTdea7Uh3w
- megous 3y agoGood for you. I left, too. They don't even offer redirects to a new location of the removed project, lol. Forced 2FA on everyone is non-sense. Everyone should decide on their own what is enough security. All I had was a Linux repo mirror, with signed tags for tested releases of my kernel branches. Zero security issues with that distribution method. 2FA is only useful for veryfying user logins, not repo content. Anyway, they can do whatever they want. GIT is thankfully fully distributed repository management system, so github.com is quite optional.
- CableNinja 3y agoFWIW gitlab has also done similar. I think MFA is important for something like code repositories.
- megous 3y agoGitlab has the best security. They don't even let me to the login page. https://megous.com/dl/tmp/egrdxmmfuiakyhkodsok.webm https://megous.com/dl/tmp/egrdxmmfuiakyhkodsok.webm This is what you get if you pay, too. > I think MFA is important for something like code repositories. I think it's not, because they can't be secured by it. As a code user I can't be sure repo was not tampered with, just because some service promises to use 2FA to authorize developer access to the repo.