Authy but I’m considering moving to Apple Passwords so it’s all together.
GitHub now requiring 2FA for all contributors,what authenticator apps you using?
21–30 of 42 posts
Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?
#22Google auth, first and the only 2FA authenticator I ever used.
Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?
#23That's been pending for a while, I'll just stop contributing code.
Why? You’re against 2FA? You couldn’t contribute without an account before, could you?
Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?
#24Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?
#25Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?
#26Earlier quoted context omitted.
Why? You’re against 2FA? You couldn’t contribute without an account before, could you?
I'd had a GH account for ages under my own name, I closed that as soon as Microsoft took it over, moved all my repos to GitLab, good move. I opened a new GH account under a silly name [1] so I could collaborate with people still on it. Now I'm not really against 2FA, but don't use it myself, it adds friction, adds risk (what if you lose it), it seems too "theatrical" for my liking. You want to use 2FA? be my guest, l…
Lose what exactly? Decent 2FA setups make you confirm you've recorded a set of backup codes somewhere (they often recommend print and store in a safe, I find a secure note in a password manager works well) before activating it.
Furthermore plenty of TOTP applications offer secure backup and syncing features.
So again, what specifically do you think you're going to "lose"?
Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?
#27Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?
#28Microsoft showing 2FA down everyone's throat is quite painful. I don't for a second believe they are only using my phone number for authentication. They are storing the data and they are correlating it with other apps they force 2FA on.
So don't give them your phone number. Arguing against 2FA is like arguing that they shouldn't bash your password because it means you can't see your password to help remember it.
Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?
#29Microsoft showing 2FA down everyone's throat is quite painful. I don't for a second believe they are only using my phone number for authentication. They are storing the data and they are correlating it with other apps they force 2FA on.
So don't give them your phone number. Arguing against 2FA is like arguing that they shouldn't bash your password because it means you can't see your password to help remember it.
Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?
#30Earlier quoted context omitted.
So don't give them your phone number. Arguing against 2FA is like arguing that they shouldn't bash your password because it means you can't see your password to help remember it.
Um, no? Arguing against 2fa is I don't want to cede even more PII with the American tech oligopoly which, no doubt, will share said PII with the American regime.
You store a TOTP secret on your ....
It's less PII than an ssh public key because it's literally just a random string, that *they* generated, and you only need it for the web UI.
So please tell me how the Americans are going to track and identify you through a fucking TOTP secret.