Live data from Hacker News

GitHub now requiring 2FA for all contributors,what authenticator apps you using?

news.ycombinator.com

21–30 of 42 posts

Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?

#21

Authy but I’m considering moving to Apple Passwords so it’s all together.

Same. To add some details, I used Authy because at the time it was the only app that would just work after upgrading my iphone. I never enabled their cloud mode, so only local 2FA codes.

Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?

#23
post #3

That's been pending for a while, I'll just stop contributing code.

Why? You’re against 2FA? You couldn’t contribute without an account before, could you?

I'd had a GH account for ages under my own name, I closed that as soon as Microsoft took it over, moved all my repos to GitLab, good move. I opened a new GH account under a silly name [1] so I could collaborate with people still on it. Now I'm not really against 2FA, but don't use it myself, it adds friction, adds risk (what if you lose it), it seems too "theatrical" for my liking. You want to use 2FA? be my guest, live and let live etc. What I don't like is being told what to do with my account, particularly by someone like MicroSlop. I won't add 2FA to my GH account, so I'll not contribute any code to GH based projects, ho hum. As I understand it, I'll still be able to raise issues without 2FA, fine, and when 2FA becomes mandatory for that, I'll stop doing that too.

[1] https://github.com/noproblemwiththat

Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?

#26
post #23

Earlier quoted context omitted.

Why? You’re against 2FA? You couldn’t contribute without an account before, could you?

I'd had a GH account for ages under my own name, I closed that as soon as Microsoft took it over, moved all my repos to GitLab, good move. I opened a new GH account under a silly name [1] so I could collaborate with people still on it. Now I'm not really against 2FA, but don't use it myself, it adds friction, adds risk (what if you lose it), it seems too "theatrical" for my liking. You want to use 2FA? be my guest, l…

> adds risk (what if you lose it)

Lose what exactly? Decent 2FA setups make you confirm you've recorded a set of backup codes somewhere (they often recommend print and store in a safe, I find a secure note in a password manager works well) before activating it.

Furthermore plenty of TOTP applications offer secure backup and syncing features.

So again, what specifically do you think you're going to "lose"?

Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?

#27
post #9

Using GitHub MFA via the app on my iPhone.

So now I need my damn phone to push something. Great. What's next, my national ID?

If by need you mean, can choose to use, and if by push you mean, login to the GitHub web ui, then sure.

Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?

#28
post #13

Microsoft showing 2FA down everyone's throat is quite painful. I don't for a second believe they are only using my phone number for authentication. They are storing the data and they are correlating it with other apps they force 2FA on.

So don't give them your phone number. Arguing against 2FA is like arguing that they shouldn't bash your password because it means you can't see your password to help remember it.

s/bash/hash/

Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?

#29
post #13

Microsoft showing 2FA down everyone's throat is quite painful. I don't for a second believe they are only using my phone number for authentication. They are storing the data and they are correlating it with other apps they force 2FA on.

So don't give them your phone number. Arguing against 2FA is like arguing that they shouldn't bash your password because it means you can't see your password to help remember it.

Um, no? Arguing against 2fa is I don't want to cede even more PII with the American tech oligopoly which, no doubt, will share said PII with the American regime.

Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?

#30
post #29

Earlier quoted context omitted.

So don't give them your phone number. Arguing against 2FA is like arguing that they shouldn't bash your password because it means you can't see your password to help remember it.

Um, no? Arguing against 2fa is I don't want to cede even more PII with the American tech oligopoly which, no doubt, will share said PII with the American regime.

What PII?

You store a TOTP secret on your ....

It's less PII than an ssh public key because it's literally just a random string, that *they* generated, and you only need it for the web UI.

So please tell me how the Americans are going to track and identify you through a fucking TOTP secret.

Post reply on HN