Live data from Hacker News

Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

news.ycombinator.com

91–100 of 108 posts

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#91
post #75

Earlier quoted context omitted.

The problem with this tactic is the need to go get the Yubikey every time you make a new account.

Actually, this is now a solved problem. Root-of-trust pattern. - Use Bitwarden or similar - Set BW to recognize the Yubikey as one (of several, incl. TOTP ('Authenticator') code) second factor. - On all other sites and services, generate passkeys (which are essentially virtual yubikeys) and save them in BW. - In BW, save the password and TOTP. BW itself, on another device (or in a separate incarnation - e.g. the desk…

Apologies for asking you to repeat yourself. I'm not following this step.

"In BW, save the password and TOTP. BW itself, on another device (or in a separate incarnation - e.g. the desktop app when authenticating the browser extension) is now your everyday means of authenticating to BW."

Can you rephrase it and be specific which passwords and TOTP you mean?

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#92

I'm perpetually worried (and partially prepared) for this sort of scenario, as more of my accounts require 2FA. I dread the day I lose or break my phone, have my items stolen, there's a weather disaster etc. I try to make my hobby repos public and/or backed up in multiple places as a hedge.

Yubikey in a safe deposit box is about as good as we can get, at least for the services that allow it.

I've always wondered how people manage this in practice. Is seems great if you never sign up for anything new, but I end up creating one account per week or something. How do you keep the key in your safe deposit box current?

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#93
post #75

Earlier quoted context omitted.

Actually, this is now a solved problem. Root-of-trust pattern. - Use Bitwarden or similar - Set BW to recognize the Yubikey as one (of several, incl. TOTP ('Authenticator') code) second factor. - On all other sites and services, generate passkeys (which are essentially virtual yubikeys) and save them in BW. - In BW, save the password and TOTP. BW itself, on another device (or in a separate incarnation - e.g. the desk…

Apologies for asking you to repeat yourself. I'm not following this step. "In BW, save the password and TOTP. BW itself, on another device (or in a separate incarnation - e.g. the desktop app when authenticating the browser extension) is now your everyday means of authenticating to BW." Can you rephrase it and be specific which passwords and TOTP you mean?

So Bitwarden can store _the password and TOTP for Bitwarden itself_. (!) I actually keep this in an entry entitled 'How meta!' because I'm cute and silly.

So, let's say you're sitting down in front of a fresh install of Bitwarden. You can go to your phone in your pocket and get the password and TOTP and then set Bitwarden to not require a password for 30 days.

Similarly, let's say you've installed the desktop app for Bitwarden but not yet the browser extension. You can look up the BW password and TOTP in the desktop app and use that to authenticate the browser extension. Or vice versa! T

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#96
post #35
post #6

> I can't, however, provide any 2FA codes or backup codes because they are printed on paper that has, I assume, been destroyed. The situation you are in is very unfortunate and I am sympathetic but in GitHub's defence, this is exactly what I hope would happen when I enable 2FA. I would be very perturbed to find out that GitHub would grant access to my account given identity documents. There are some creative solution…

The person should be able to walk in the service provider's office and get an in-person help, restoration of access, by presenting ID docs.

If you are not European, I will be amazed.

If you set up 2FA and then lose your 2FA, then that’s just life. Happens sometimes and you move on. GitHub absolutely doesn’t need to provide an in-person recovery service.

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#99
post #24

Earlier quoted context omitted.

I for one would appreciate the option to put an ID on file ahead of time, at least for important stuff like this. I like digital-only accounts for play, but for work stuff with real-world consequence, I’d like to link it to a real-world identity system… Not unlike the signature cards banks used long ago, I guess. Sure, maybe somebody motivated could defraud the government into issuing them a replacement ID in my name…

The issue is less about having an ID on file, and more about verifying ID. In a world of excellent real-time deepfakes, how would GitHub verify ID at scale? A fake ID is pretty easy to create, along with a fake face for a video chat where you can hold up your fake ID.

You don't have to do things "at scale". Github could require a substantial financial transaction to cover all the costs associated with ID verification and account re-instatement, as well as keep backups before that point so if it's proven after the fact that it was fraud, they could restore to the original state.

Like my data center (not US based) has a process where if you lose all of the documentation proving that a server is yours, you can go on site physically with ID, and the police and/or national identity service will verify on the spot that your finger prints match what is on file for the ID. It costs something like $300 and you risk being arrested if you're a criminal.

Re: Ask HN: Went to prison for 18 months, lost access to my GitHub. What can I do?

#100
post #8

Earlier quoted context omitted.

That's the same stance I have and why I'm torn. The little quirk here—where it makes slightly more sense—is that they received a legal notice at one point (from the US Government) about my account, there are plenty of online articles to corroborate me as me, and I have a fancy prison release ID that can help me identify me. Unfortunately this context is probably lost on the individuals who work their Zendesk. The pol…

Why do I feel most of this is ai created text...whoever is posting will probably adjust their prompt, but who uses '-' mid text?

I do.
Post reply on HN