Live data from Hacker News

Gitlab Support is no longer processing MFA resets for free users

about.gitlab.com

191–200 of 228 posts

Re: Gitlab Support is no longer processing MFA resets for free users

#191
post #7

This looks like a page that people would find after they lose access to their account permanently. There's a lot of CYA language here. Maybe they should have this at signup for MFA or force people to read next time they login.

Support Manager for GitLab here. I appreciate this feedback, and you're right. We don't want folks to get themselves in a position where they lose access. Our current language when you enable MFA is here: https://gitlab.com/gitlab-org/gitlab/-/blob/adc7dbeb387adc69... > Should you ever lose your phone or access to your one time password secret, each of these recovery codes can be used one time each to regain access t…

I made this post on the forums: https://forum.gitlab.com/t/gitlab-support-is-no-longer-proce...

In summary:

Please consider some kind of exemption for non-commercial open source projects over a certain size.

This change would force me to choose between unacceptable risk to my users, or severe impact on my hobby/life balance and mental health due to the extreme personal responsibility I would have to take to mitigate it.

It's already terrifying enough to publish applications that users run on their systems. If I make an error I can cause all sorts of harm. But at least I only have to worry about that when developing.

Now, if I enable MFA, I can never relax. If I lose my work MFA, there's a perfectly safe process to recover. If i lose my personal MFA it's a few hours of calling banks. If I lose my GitLab MFA I harm hundreds of people. So, I have to permanently vigilant for something I already give so much to for free.

Re: Gitlab Support is no longer processing MFA resets for free users

#192
post #177

I don't care how high up you are on your infosec high horse, but the likelihood and potential damage caused by a developer losing access to their 2F device is far higher in nearly every scenario than someone being hacked. The only correct response to this is for companies to make it against internal policy for developers to enable 2FA. Which is sad.

Gitlab allows you to have multiple U2F tokens. From what I can tell it is is at least 10. I myself probably own eight U2F tokens. Anyone of the U2F tokens I have registered can be used to log me into Gitlab, assuming I remember my username/password ;) Besides the somewhat minimal cost of $20 for a U2F token I don't see any reason people should not have multiple U2F tokens and register them to their accounts.

I don't feel the need to go beyond SMS/TOTP MFA for my personal, private, security. I can just call my banks and recover if I lose my phone and SIM somehow.

However, I have an open source project with at least a thousand users who could be severely harmed by both compromise of my account (malicious code changes) or loss of my account (having to fork without being able to update the original).

With this change, in order to protect my users I have to go beyond an anti-compromise standard of MFA to an anti-loss standard of MFA (e.g. by buying many physical devices). I also have to be constantly vigilant as if I mess up and break my MFA, lose that piece of paper, have my house burn down, I harm many people.

So, do I choose to disable MFA, and risk my users machines being compromised?

Or do I enable MFA, and risk my mental health?

Or do I just stop supporting this open source project?

Re: Gitlab Support is no longer processing MFA resets for free users

#193
post #190

Earlier quoted context omitted.

What happens if your phone gets crushed by a runaway elephant?

Hopefully they will have already activated a couple U2F hardware tokens as backup. Having only one copy of the MFA device is of course a bad idea.

Sure but now the "very simple process" is no longer so simple and in fact the simplicity merely a dangerous limitation.

Re: Gitlab Support is no longer processing MFA resets for free users

#194
post #123

Earlier quoted context omitted.

Not op, but my usual process is: * when setting up 2FA, a website shows a QR code * I screenshot the QR code, and print it out on an A4 sheet, with an annotation of what service it is for * I scan the QR code from the A4 sheet on two different phones. * Back on the website, I continue 2FA setup process only after the A4 sheet is printed, and both phones show the same codes * The A4 sheet goes in a folder for safe kee…

interesting idea. I wonder what the minimum you need for a 2FA-only device would be.

The Passport by Foundation Devices is a device that's pretty close to this, it just happens to do more than only 2FA: https://foundationdevices.com/

Re: Gitlab Support is no longer processing MFA resets for free users

#195

There was a discussion about the topic of MFA resets on the Risky Business podcast[0] in which the host, Patrick Gray, suggested companies require a one time fee for MFA resets. I think the suggested amount in the show was $50 which seems reasonable enough for western markets. It creates a deterrent for attackers and in the case of free products like GitLab allows the support costs to be covered. Additionally the act…

So, not only are developers working on open source projects in their free time expected to maintain and provide support for free, they're now also expected to pay in order to provide baseline security for their users?

If NPM or any other package repository introduced this, do you think maintainers of commonly used open source projects wouldn't feel obliged to pay up? Generally immediately after a traumatic event such as having their phone stolen.

Even if you never plan to update your package, you can't fix a security vulnerability without spending money.

Re: Gitlab Support is no longer processing MFA resets for free users

#196
post #190

Earlier quoted context omitted.

Hopefully they will have already activated a couple U2F hardware tokens as backup. Having only one copy of the MFA device is of course a bad idea.

Sure but now the "very simple process" is no longer so simple and in fact the simplicity merely a dangerous limitation.

Who said security was a "very simple process"?

It is of course up to people if they want to enable additional security and of course have to put up with increased friction and difficulty.

Myself I consider what would it mean if someone got access to my Github, Gitlab, and/or email accounts and have decided that I will put up with the cost (buying U2F tokens) and hassle (having to use the U2F token to login).

The alternative is the much higher chance that someone could at some point get into one of my accounts.

Re: Gitlab Support is no longer processing MFA resets for free users

#197

There was a discussion about the topic of MFA resets on the Risky Business podcast[0] in which the host, Patrick Gray, suggested companies require a one time fee for MFA resets. I think the suggested amount in the show was $50 which seems reasonable enough for western markets. It creates a deterrent for attackers and in the case of free products like GitLab allows the support costs to be covered. Additionally the act…

So, not only are developers working on open source projects in their free time expected to maintain and provide support for free, they're now also expected to pay in order to provide baseline security for their users? If NPM or any other package repository introduced this, do you think maintainers of commonly used open source projects wouldn't feel obliged to pay up? Generally immediately after a traumatic event such…

Don’t lose your recovery codes and you should be fine, right?

Re: Gitlab Support is no longer processing MFA resets for free users

#198

As someone who had two phones break and loose my 2FA for github, this makes me sad They were willing to help me - took a week but I got my account back

Not sure about gitlab, but at least on github you get recovery codes that you can use if you don't have access to your phone.

GitLab does have this, here is a link to our docs with more info: https://docs.gitlab.com/ee/user/profile/account/two_factor_a... and how you can regenerate them if you lose them: https://docs.gitlab.com/ee/user/profile/account/two_factor_a...

Re: Gitlab Support is no longer processing MFA resets for free users

#199
post #196

Earlier quoted context omitted.

Sure but now the "very simple process" is no longer so simple and in fact the simplicity merely a dangerous limitation.

Who said security was a "very simple process"? It is of course up to people if they want to enable additional security and of course have to put up with increased friction and difficulty. Myself I consider what would it mean if someone got access to my Github, Gitlab, and/or email accounts and have decided that I will put up with the cost (buying U2F tokens) and hassle (having to use the U2F token to login). The alte…

> Who said security was a "very simple process"?

The post I responded to basically did:

> That's it. Did a bunch of complicated stuff happen? Yes, but the user didn't do any of that, so they needn't care

Re: Gitlab Support is no longer processing MFA resets for free users

#200

Earlier quoted context omitted.

So, not only are developers working on open source projects in their free time expected to maintain and provide support for free, they're now also expected to pay in order to provide baseline security for their users? If NPM or any other package repository introduced this, do you think maintainers of commonly used open source projects wouldn't feel obliged to pay up? Generally immediately after a traumatic event such…

Don’t lose your recovery codes and you should be fine, right?

Yeah, sure, set up a recovery process I don't need anywhere else in life and hope I never mess that up. Then have several thousand people (or far more if I'm lucky) rely on it, I'm sure that'll go well!

I don't need recovery codes for anything in my professional nor personal life outside open source programming.

Post reply on HN