Earlier quoted context omitted.
Um, no? Arguing against 2fa is I don't want to cede even more PII with the American tech oligopoly which, no doubt, will share said PII with the American regime.
What PII? You store a TOTP secret on your .... It's less PII than an ssh public key because it's literally just a random string, that *they* generated, and you only need it for the web UI. So please tell me how the Americans are going to track and identify you through a fucking TOTP secret.
GitHub now requiring 2FA for all contributors,what authenticator apps you using?
31–40 of 42 posts
Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?
#32Earlier quoted context omitted.
What PII? You store a TOTP secret on your .... It's less PII than an ssh public key because it's literally just a random string, that *they* generated, and you only need it for the web UI. So please tell me how the Americans are going to track and identify you through a fucking TOTP secret.
My phone number dumbo.
Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?
#33Google auth, first and the only 2FA authenticator I ever used.
Because some auth provider recommended it as the only app to use. While it is a good app, it does backup into Drive.
Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?
#34Re: GitHub now requiring 2FA for all contributors,what authenticator apps you using?
#35Earlier quoted context omitted.
Why? You’re against 2FA? You couldn’t contribute without an account before, could you?
I'd had a GH account for ages under my own name, I closed that as soon as Microsoft took it over, moved all my repos to GitLab, good move. I opened a new GH account under a silly name [1] so I could collaborate with people still on it. Now I'm not really against 2FA, but don't use it myself, it adds friction, adds risk (what if you lose it), it seems too "theatrical" for my liking. You want to use 2FA? be my guest, l…
All of the arguments against 2FA here could be made against requiring passwords longer than 8 characters.
It’s not secure. The fix is easy, effective, and has almost no downsides.