Live data from Hacker News

Gitlab Support is no longer processing MFA resets for free users

about.gitlab.com

81–90 of 228 posts

Re: Gitlab Support is no longer processing MFA resets for free users

#81
post #28

What are the current best options for hardware tokens then?

If you mostly use a desktop or laptop, purchase two different FIDO authenticators that match the form factor you need. If purchasing a new laptop (or having one purchased for you) and you run Windows or Mac OS consider fingerprint devices that can turn it into a "Platform Authenticator" able to prove that the person with the authorised fingerprint and the machine authorised are together and wish to sign in. If you mo…

Sites should be migrating to WebAuthn (and please people do not implement U2F instead of WebAuthn in 2020, for the same reason you wouldn't build a new Flash video site, nothing new supports that technology any more, stop it)

I think this is terrible advice because WebAuthn isn't supported by Linux browsers and I still want to be able to login to services on the internet.

Re: Gitlab Support is no longer processing MFA resets for free users

#82
post #7

This looks like a page that people would find after they lose access to their account permanently. There's a lot of CYA language here. Maybe they should have this at signup for MFA or force people to read next time they login.

CYA?

Re: Gitlab Support is no longer processing MFA resets for free users

#84
post #8

I generally support not resetting MFA credentials, and understand where Gitlab is coming from, but wish there were an easier way for the average user. I think that easier way is getting two FIDO2 keys (they're pretty cheap and will get cheaper), and have one on your keychain and one at home, as a backup.

For a casual user (unlikely to be specifically targetted for attack) I think SMS is a good option. If you lose your phone then you can just order a replacement sim card and you have your second facto back.

As someone who travels frequently and has moved to different countries, SMS is the absolute worst.

If a service asks me to verify my number after crossing a border, the chances of me ever being able to log into that account ever again are basically zero.

Then there's Google. Google doesn't have a phone number on file for me, but they sometimes demand that I input a phone number and enter a verification code to access my accounts. This has led to me needing to ask a total stranger to help me login to my accounts, potentially allowing them full access to all of my data in the name of "security." But hey, nobody ever said Google hires smart people.

Re: Gitlab Support is no longer processing MFA resets for free users

#85
post #7

This looks like a page that people would find after they lose access to their account permanently. There's a lot of CYA language here. Maybe they should have this at signup for MFA or force people to read next time they login.

CYA?

Cover Your Ass. We warned you, do it no longer is our responsibility/problem.

Re: Gitlab Support is no longer processing MFA resets for free users

#86

Good - 2FA is the responsibility of the user and resetting it kind of invalidates the security it helps bring. I think the bigger issue is that people's 2fa codes are still tied to their phone. You can lose your phone at any moment, which is why i've always disliked apps like Google Authenticator which don't let you export 2fa keys (for good reason). I personally use 1password, but there's definitely room for a cloud…

You can export to multiple devices now on Google authenticator, other 2FA apps have also supported that for quite a while. As far as cloud storage goes, standard notes might be a good option, I don't use it for 2FA, but it's an extension they provide.

Yes, I can confirm I've had the same google auth token on multiple devices both concurrently and when setting up new phones for a SaaS login for years now.

Re: Gitlab Support is no longer processing MFA resets for free users

#87

Earlier quoted context omitted.

Isn't there Authy?

Authy's SMS convenience/reliance undermines the whole thing. Avoid.

You can turn off Multi-Device at any time, which just disables the ability to add new devices. I think that's protection enough.

Re: Gitlab Support is no longer processing MFA resets for free users

#88

Good - 2FA is the responsibility of the user and resetting it kind of invalidates the security it helps bring. I think the bigger issue is that people's 2fa codes are still tied to their phone. You can lose your phone at any moment, which is why i've always disliked apps like Google Authenticator which don't let you export 2fa keys (for good reason). I personally use 1password, but there's definitely room for a cloud…

Google Authenticator now allows you to export your keys to another phone.

I keep my keys in analog form - I print QR code for every service. We know how to handle valuables stored on paper.

Re: Gitlab Support is no longer processing MFA resets for free users

#89

Good - 2FA is the responsibility of the user and resetting it kind of invalidates the security it helps bring. I think the bigger issue is that people's 2fa codes are still tied to their phone. You can lose your phone at any moment, which is why i've always disliked apps like Google Authenticator which don't let you export 2fa keys (for good reason). I personally use 1password, but there's definitely room for a cloud…

I use FreeOTP+ for Android because it allows me to backup its data.

I'm currently using andOTP. Just to throw some more news of good OSS MFA apps out there.
Post reply on HN