Microsoft Open-Sources Git Credential Manager for Mac and Linux
blogs.msdn.com
blogs.msdn.com
> We ported this tool to Mac and Linux to simplify their authentication to remote Git repositories, in particular those hosted in Visual Studio Team Services (VSTS).
Edit: Apparently they are. But I still think it would've been better to layer two-factor auth on top of SSH keys, since that can be done securely in a 100% offline manner.
Perhaps it's just a cultural difference, since Windows doesn't ship with an SSH client?
These are (roughly) orthogonal issues: regardless of whether we support SSH or not, we are going to support HTTPS access to Git repositories. And if we support HTTPS, we must support two-factor authentication. A lot of organizations require this. (In fact, Microsoft itself requires this internally: our authentication to any internal web site uses 2FA.)
So Visual Studio Team Services must support HTTPS with two-factor authentication. This is awfully painful to use git core on the command-line without a credential manager to assist you.
No, because SSH.
No?
This tools is meant to help those users.
I think the big problem here is that they're using HTTP(S) as a transport for Git. And there's just not very many options left for layering on extra security if you do that.
[1]: I'm a big fan of Yubikeys for credential storage. You can put them in PGP Smartcard mode, and then use the PGP key with SSH: https://www.esev.com/blog/post/2015-01-pgp-ssh-key-on-yubike...
1. Embrace
2. Extend
3. Extinguish
We're at step 2. They've gotten pretty fast at it, I must say.
3 mentions of Visual Studio, 2 mentions of Microsoft, 1 mention of ASP.NET
Yes, yes, yes Microsoft are still bleeding edge with the software :)