Live data from Hacker News

Gitlab Support is no longer processing MFA resets for free users

about.gitlab.com

211–220 of 228 posts

Re: Gitlab Support is no longer processing MFA resets for free users

#211

There was a discussion about the topic of MFA resets on the Risky Business podcast[0] in which the host, Patrick Gray, suggested companies require a one time fee for MFA resets. I think the suggested amount in the show was $50 which seems reasonable enough for western markets. It creates a deterrent for attackers and in the case of free products like GitLab allows the support costs to be covered. Additionally the act…

I wonder if it might bias the reset request.

Sort of like "If this person is paying for this, he's probably legit."

Re: Gitlab Support is no longer processing MFA resets for free users

#212
post #66

Earlier quoted context omitted.

I think they offer TOTP now, right? Started sometime last year? Do you have to activate SMS alongside it? I have been using TOTP with PayPal for (I think) a few years now. You used to have to run some weird local Python script that somehow imitated the one RSA (I think) dongle they supported in a way I don't understand, but the net result was that you just get a TOTP key that works fine.

I wasn't able to see any way to do even TOTP for PayPal when they insisted I enable SMS a few hours ago. I don't have any money in there, it just mediates broken payment interfaces (e.g. Patreon rejected all my payment cards, from multiple banks apparently they're all fraud or something? No idea, the cards remain working no problem everywhere else, but I wanted to give people money for what they do, so I used Paypal…

Check the instructions at https://authy.com/guides/paypal/. Those seem to work for me, I can indeed now add an authenticator app just as shown there.

Re: Gitlab Support is no longer processing MFA resets for free users

#213

Earlier quoted context omitted.

Support Manager for GitLab here. I appreciate this feedback, and you're right. We don't want folks to get themselves in a position where they lose access. Our current language when you enable MFA is here: https://gitlab.com/gitlab-org/gitlab/-/blob/adc7dbeb387adc69... > Should you ever lose your phone or access to your one time password secret, each of these recovery codes can be used one time each to regain access t…

I made this post on the forums: https://forum.gitlab.com/t/gitlab-support-is-no-longer-proce... In summary: Please consider some kind of exemption for non-commercial open source projects over a certain size. This change would force me to choose between unacceptable risk to my users, or severe impact on my hobby/life balance and mental health due to the extreme personal responsibility I would have to take to mitigate…

I print my recovery keys and put them next to the title for my house. Now, unless the bank burns down they are safe.

If anything takes out both me and my bank, it’s taken out the whole city so I have more to worry about than just 2FA.

Re: Gitlab Support is no longer processing MFA resets for free users

#214
post #170

This is a terrible idea which encourages people to use weak security: it's effectively telling people that if they enable MFA, GitLab will ensure that they suffer irrecoverable damages — but if they don't enable MFA, everything is recoverable. That is the opposite of what we want from a security perspective and it risks causing users to be less secure everywhere else because having seen that message will make them qu…

I'm on the community advocates team at GitLab and we really appreciate your feedback. I wanted to point out that our team responded to your post on the GitLab forum, you can see the response here: https://forum.gitlab.com/t/gitlab-support-is-no-longer-proce...

Thanks — I've been replying there but figured I should comment here since this is where I first saw it. I definitely hope this leads to some UX work, especially through the lens of thinking about how badly it will fail for vulnerable users.

Re: Gitlab Support is no longer processing MFA resets for free users

#215

There was a discussion about the topic of MFA resets on the Risky Business podcast[0] in which the host, Patrick Gray, suggested companies require a one time fee for MFA resets. I think the suggested amount in the show was $50 which seems reasonable enough for western markets. It creates a deterrent for attackers and in the case of free products like GitLab allows the support costs to be covered. Additionally the act…

This doesn't really solve the problem causing GitLab to enforce this change; I highly doubt the cost of providing support to users for MFA had any bearing on this discussion.

Meanwhile, Gray's suggestion would provide any attacker within enough capital to a backdoor, while legitimate users need to pay to unlock their account without any benefit to them from a security perspective.

I strongly disagree with such a concept -- unless, as you mentioned, payment could be used to verify the identity. That said, I think that's the same reason GitLab is now only offering MFA for paying customers, because they have a bit more PII to confirm your identity if you're a current customer -- in which case, why require payment at all?

Re: Gitlab Support is no longer processing MFA resets for free users

#216
post #154

This seems to create an interesting security loophole. If someone figures out our GitLab password (i.e. by looking over our shoulder), they can just log in, enable MFA and we are locked out, forever. Think about this. Any criminal who gets access to your Gitlab account can make it impossible for you to access it ever again. If I used GitLab, I would seriously consider moving somewhere else.

Or you can just enable MFA yourself, and prevent that from happening? Am I missing something?

In your world no one ever makes mistakes or errors, it must be nice.

Re: Gitlab Support is no longer processing MFA resets for free users

#217
post #3

> If you are caught where you are not able to provide your MFA token and without these backup methods, your account will be irrecoverable. This seems absurd. I vaguely remember another SaaS tool I used that had this policy, but I don’t understand it. Even crypto exchanges allow recovery if you lose all traditional recovery methods by submitting documentation like your scanned driver’s license among a couple other pie…

Crypto exchanges make money off most customers, though, so they can afford to dedicate support staff to recovering people's 2FA.

Does GitLab make any money at all on free users, or are they just a loss leader?

Note that paid GitLab users aren't losing the recovery option, only free ones.

Re: Gitlab Support is no longer processing MFA resets for free users

#218

Earlier quoted context omitted.

Don’t lose your recovery codes and you should be fine, right?

Yeah, sure, set up a recovery process I don't need anywhere else in life and hope I never mess that up. Then have several thousand people (or far more if I'm lucky) rely on it, I'm sure that'll go well! I don't need recovery codes for anything in my professional nor personal life outside open source programming.

You don’t have any other MFAs you need to manage in your digital life? That seems ... odd. It seems like you’re deciding to make an issue of, well, how MFA is _supposed_ to work.

Re: Gitlab Support is no longer processing MFA resets for free users

#219

Earlier quoted context omitted.

I wasn't able to see any way to do even TOTP for PayPal when they insisted I enable SMS a few hours ago. I don't have any money in there, it just mediates broken payment interfaces (e.g. Patreon rejected all my payment cards, from multiple banks apparently they're all fraud or something? No idea, the cards remain working no problem everywhere else, but I wanted to give people money for what they do, so I used Paypal…

Check the instructions at https://authy.com/guides/paypal/ . Those seem to work for me, I can indeed now add an authenticator app just as shown there.

Thanks, I think it worked. At least they are no longer asking me to confirm the mobile number, although I can't seem to delete the unconfirmed number so who knows if there is still a way to use it to take over the account :(. Along the way I found a disturbing number of TOTP utilities that want you to pass the key on the command line :(. I found this one as a simple version that doesn't do that and uses OpenSSL or LibreSSL:

https://github.com/arachsys/totp

Re: Gitlab Support is no longer processing MFA resets for free users

#220
post #154

Earlier quoted context omitted.

Or you can just enable MFA yourself, and prevent that from happening? Am I missing something?

In your world no one ever makes mistakes or errors, it must be nice.

Not sure how you get that conclusion from my comment, of course people make mistakes - my suggestion is one way to prevent such a mistake? i.e. if you have MFA enabled, it "doesn't matter" as much if you do make a mistake and accidentally reveal your password to someone
Post reply on HN