Not super related but it's funny that Twitter basically shed text 2FA unless you pay for it with their monthly blue checkmark thing, demoting anybody who had text 2FA to authenticator style app to save on cost, whereas Microsoft/GitHub are forcing everybody to enroll, which would inverse what Twitter did and send their 2FA SMS costs through the roof.
Tell HN: GitHub forcing 2FA on users has no basis in their ToS
11–15 of 15 posts
Re: Tell HN: GitHub forcing 2FA on users has no basis in their ToS
#12Are you going to cry because a company wants your data to be a bit more safe?
Then you won't objective to 3fa or 20fa. More steps is safer right? If your account is unimportant to you github shouldn't force you to add layers of security when they literally throw you under the bus in the TOS telling you it is your responsibility.. good let me decide my level of risk.
If you do not have the good sense to lock up such a weapon, then please delete your account.
Re: Tell HN: GitHub forcing 2FA on users has no basis in their ToS
#13Earlier quoted context omitted.
Then you won't objective to 3fa or 20fa. More steps is safer right? If your account is unimportant to you github shouldn't force you to add layers of security when they literally throw you under the bus in the TOS telling you it is your responsibility.. good let me decide my level of risk.
If a lot of people trust code that comes from your account, then it can and will be weaponized for a supply chain attack. If you do not have the good sense to lock up such a weapon, then please delete your account.
To my (well-founded) knowledge nobody distributes my code; and if they did they'd have full responsibility. That's what "THE SOFTWARE IS PROVIDED 'AS IS'" means. You don't have to like it and you don't have to use it.
There really is no middle ground unless you develop a relation. Who says i can be trusted? Not me!
Re: Tell HN: GitHub forcing 2FA on users has no basis in their ToS
#14Earlier quoted context omitted.
Then you won't objective to 3fa or 20fa. More steps is safer right? If your account is unimportant to you github shouldn't force you to add layers of security when they literally throw you under the bus in the TOS telling you it is your responsibility.. good let me decide my level of risk.
If a lot of people trust code that comes from your account, then it can and will be weaponized for a supply chain attack. If you do not have the good sense to lock up such a weapon, then please delete your account.
Re: Tell HN: GitHub forcing 2FA on users has no basis in their ToS
#15the main reason they want your phone number is to tie you to a more expensive profile for ad impressions.