Live data from Hacker News

Gitlab Support is no longer processing MFA resets for free users

about.gitlab.com

61–70 of 228 posts

Re: Gitlab Support is no longer processing MFA resets for free users

#61

Earlier quoted context omitted.

There have been many instances of attacks of people hijacking the connection, calling the service and saying "I forgot my password, can you reset it by verifying my SMS?", which wouldn't have been possible without a second factor.

I'd argue that it isn't truly a second factor if it can be used on it own...

And that's much of the problem.

Re: Gitlab Support is no longer processing MFA resets for free users

#63
post #45

Earlier quoted context omitted.

Good God, imagine the bad publicity that comes out of that. "This is advertised as a security measure, but it's clear it's just a way to extort the user at his most vulnerable!"

I don't know. Free service that isn't even paid for with ads or privacy-invasion, like legitimately free. If something happens on your end, you can pay them for service. What's wrong? Which is worse publicity: A) if you use this security feature, and something goes wrong on your side, you will lose your account forever B) if you use this security feature, and something goes wrong on your side, helping you get your ac…

> Which is worse publicity:

I think it's not so clear. If someone tells me "I can't authenticate, and so I'm locked out of my account", that sounds like his fault. If someone tells me "I can't authenticate, and they'll let me into my account, but only if I pay them money", then that sounds like their fault. I do carefully say sounds—I recognise the underlying tech is the same in both cases; but the nature of publicity is to attach much more about appearance than to technical facts.

Re: Gitlab Support is no longer processing MFA resets for free users

#64
post #43

Earlier quoted context omitted.

I really appreciate your good humour about this, but it seems to me to be less classy to delete the original comment; it invalidates later comments, and leaves people to infer what is missing from contextual clues (in this case ample, but not always). Why not just put a note up top saying "EDIT: I misread; thanks to jkaplowitz and toomuchtodo for setting me straight", while leaving the original post intact?

I also appreciate your good humor and sentiment. I deleted my comment because while I appreciate the context staying, I felt it was retained in children replies and I also feel that it’s my right as a human being to remove my own stupidity from the Internet as long as I’ve left a clear trail documenting it for others to learn from, so that’s why I deleted it :) I also added it back because I’m easily swayed by civili…

> I also added it back because I’m easily swayed by civility online. It’s in short supply.

Extra classy! Thanks.

Re: Gitlab Support is no longer processing MFA resets for free users

#65

I agree, but having worked in SaaS, and done a lot of partnerships, Microsoft has infinite leverage to turn something like MFA services into a co-branding exercise that pays for itself.

We detached this subthread from https://news.ycombinator.com/item?id=24056211.

Re: Gitlab Support is no longer processing MFA resets for free users

#66
post #46

Earlier quoted context omitted.

There have been many instances of attacks of people hijacking the connection, calling the service and saying "I forgot my password, can you reset it by verifying my SMS?", which wouldn't have been possible without a second factor.

I wish someone would convince Paypal. They require SMS for verification, no other options at all.

I think they offer TOTP now, right? Started sometime last year? Do you have to activate SMS alongside it?

I have been using TOTP with PayPal for (I think) a few years now. You used to have to run some weird local Python script that somehow imitated the one RSA (I think) dongle they supported in a way I don't understand, but the net result was that you just get a TOTP key that works fine.

Re: Gitlab Support is no longer processing MFA resets for free users

#67
post #35

Instead of just saying they won't do it for free accounts, they could charge a fee for the service.

This is the answer. Charge 2-4 years worth of basic subscription to recover. Or a 1 year up-front payment and recurring after that. Otherwise, with no path forward, this is just user hostile.

Then next post on HN will be how GitLab is "blackmailing" users who lost their credentials...

Re: Gitlab Support is no longer processing MFA resets for free users

#69
Good - 2FA is the responsibility of the user and resetting it kind of invalidates the security it helps bring.

I think the bigger issue is that people's 2fa codes are still tied to their phone. You can lose your phone at any moment, which is why i've always disliked apps like Google Authenticator which don't let you export 2fa keys (for good reason).

I personally use 1password, but there's definitely room for a cloud storage solution that safely holds 2fa credentials

Re: Gitlab Support is no longer processing MFA resets for free users

#70

As someone who had two phones break and loose my 2FA for github, this makes me sad They were willing to help me - took a week but I got my account back

Not sure about gitlab, but at least on github you get recovery codes that you can use if you don't have access to your phone.
Post reply on HN