Live data from Hacker News

Raising the bar for software security: GitHub 2FA begins March 13

github.blog

11–20 of 90 posts

Re: Raising the bar for software security: GitHub 2FA begins March 13

#11

This is just shenanigans to get our phone numbers. As if forcing keys over password was not bad enough. I wonder if I will be able to connect and pull from a private repository without 2FA. Otherwise my personal web server setup breaks.

You don’t need to provide a phone number to enable 2FA. GitHub supports OATH applications that generate one-time codes and webauthn so you can use it with a yubikey and not bother with pesky codes.

Re: Raising the bar for software security: GitHub 2FA begins March 13

#16

This is just shenanigans to get our phone numbers. As if forcing keys over password was not bad enough. I wonder if I will be able to connect and pull from a private repository without 2FA. Otherwise my personal web server setup breaks.

You are not required to use your phone number for 2FA. In fact, they discourage users from using SMS for 2FA.

Re: Raising the bar for software security: GitHub 2FA begins March 13

#17
post #6

A quick off topic question related to 2FA. If an employee is required to complete the 2FA to access to the company's system, is the company responsible to provide the employee a necessary device (either phone or hardware token) to complete the 2FA?

We are factoring this into our "should we buy company iPhones for all employees?" conversation right now.
Post reply on HN