Live data from Hacker News

Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

news.ycombinator.com

41–50 of 108 posts

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#41
post #24

Earlier quoted context omitted.

These (for good reason) draconian policies are the reason I am still hesitant to embrace 2FA. I understand the significant improvement in your security posture, and I would not want someone not-me to be able to reset my credentials. But the failure mode is just too catastrophic. You lose one thing and you are shit out of luck. We need something better. I don't know what it would be.

I for one would appreciate the option to put an ID on file ahead of time, at least for important stuff like this. I like digital-only accounts for play, but for work stuff with real-world consequence, I’d like to link it to a real-world identity system… Not unlike the signature cards banks used long ago, I guess. Sure, maybe somebody motivated could defraud the government into issuing them a replacement ID in my name…

The issue is less about having an ID on file, and more about verifying ID. In a world of excellent real-time deepfakes, how would GitHub verify ID at scale?

A fake ID is pretty easy to create, along with a fake face for a video chat where you can hold up your fake ID.

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#42
There are alarming statistics about phone snatching in London. Plus, we are NOT OUR PHONES. Doesn't GitHub have a way for people to verify and prove somebody's identity? Given that's a fact, isn't it best to disable 2FA and stop recommending it to people?

Following this post, I have reviewed all my main accounts, created recovery codes, set up backups, and added alternative email addresses, among other tasks. Hope for the best.

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#43
post #9

Earlier quoted context omitted.

I think the disconnect between you and GitHub support is that you're positioning this as a problem of proving your identity whereas for GitHub support it is a policy. The GitHub policy is: you lose your 2FA, you lose your account. Verifying your identity is not relevant. GitHub provides extensive tooling to protect your account (multiple methods of 2FA, recovery codes etc.) and so from their perspective, while this i…

These (for good reason) draconian policies are the reason I am still hesitant to embrace 2FA. I understand the significant improvement in your security posture, and I would not want someone not-me to be able to reset my credentials. But the failure mode is just too catastrophic. You lose one thing and you are shit out of luck. We need something better. I don't know what it would be.

You can use a TOTP authenticator with backup support (I use Aegis on Android, and less critical ones in Bitwarden), and backup your recovery codes.

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#44
post #33
post #24

Earlier quoted context omitted.

I for one would appreciate the option to put an ID on file ahead of time, at least for important stuff like this. I like digital-only accounts for play, but for work stuff with real-world consequence, I’d like to link it to a real-world identity system… Not unlike the signature cards banks used long ago, I guess. Sure, maybe somebody motivated could defraud the government into issuing them a replacement ID in my name…

> I for one would appreciate the option to put an ID on file ahead of time, at least for important stuff like this. I'm at that point of agreement. I don't want to say "national SSO ID" because that can get really Orwellian obviously. Being able to put an ID on file is a reasonable ask.

a passport is orwellian? i don't really get this fear of government issued IDs. if your government is so bad that it will abuse IDs for surveillance, then your government is the problem, and not having a national ID is not going to protect you.

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#45

[flagged]

You sound paranoid and schizophrenic you should honestly try explaining your situation to someone you know or a professional. I think you’ll realize that your thinking is a bit delusional. I can’t really understand what you’re saying here.

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#46
What you might consider doing is try contacting Ruby Central, or whoever it is that runs Ruby Gems. Even if they can't/won't give you access to the account, I'm wondering if they could/would freeze publishing updates to these gems until the account "owner" proves they are who they say they are. That way they don't risk giving control to someone who is hard to verify (you) and they prevent malware from being uploaded by the person who now controls your email until they verify the you are (which obviously they shouldn't be able to do).

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#47
post #24

Earlier quoted context omitted.

I for one would appreciate the option to put an ID on file ahead of time, at least for important stuff like this. I like digital-only accounts for play, but for work stuff with real-world consequence, I’d like to link it to a real-world identity system… Not unlike the signature cards banks used long ago, I guess. Sure, maybe somebody motivated could defraud the government into issuing them a replacement ID in my name…

The issue is less about having an ID on file, and more about verifying ID. In a world of excellent real-time deepfakes, how would GitHub verify ID at scale? A fake ID is pretty easy to create, along with a fake face for a video chat where you can hold up your fake ID.

An idea might be to require a financially meaningful deposit to pursue an account recovery like this. The deposit would be forfeit if the identity verification failed.

Though now that I write this, it creates a perverse incentive for a company to collect deposits and deny account recovery.

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#48

[flagged]

You sound paranoid and schizophrenic you should honestly try explaining your situation to someone you know or a professional. I think you’ll realize that your thinking is a bit delusional. I can’t really understand what you’re saying here.

Don't do this. We don't diagnose people on HN. Just flag the comment and move on, or, if you're worried, mail hn@yc.

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

(I'm not a mod, just someone who cares a lot about this particular rule.)

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#49
post #6

> I can't, however, provide any 2FA codes or backup codes because they are printed on paper that has, I assume, been destroyed. The situation you are in is very unfortunate and I am sympathetic but in GitHub's defence, this is exactly what I hope would happen when I enable 2FA. I would be very perturbed to find out that GitHub would grant access to my account given identity documents. There are some creative solution…

I agree that simply emailing in copies of identity documents after the fact shouldn't be sufficient. However, there should be a verification process that includes verification of identity documents through legal means, including perhaps a processing fee. The fee would preclude many attackers from even trying to break this process.

Maybe this would only work for new accounts as you'd probably need to provide identity information on before losing access.

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#50

I'm perpetually worried (and partially prepared) for this sort of scenario, as more of my accounts require 2FA. I dread the day I lose or break my phone, have my items stolen, there's a weather disaster etc. I try to make my hobby repos public and/or backed up in multiple places as a hedge.

[deleted]
Post reply on HN