I think it's a misconception.
Unless you just let everyone write anything in your repo, one would expect that what is there is what it says on the tin.
Every public software project takes measures to stay authentic and not let random and unreviewed, potentially malicious bits in. This is how they keep their users' trust.
Very roughly, "public" = read access is unrestricted, and "insecure" = write access is unrestricted.
I wish there was some way of _manually_ identifying via a simple link or QR code or whatever.
It suggests SSH commands by default for me, I assume this depends whether you have added an SSH key to your account or not.
(Git for Windows default installs GCM Core. Some Linux distros do to. You may even already be using it. I think I've seen some confusion in comments here and elsewhere that they don't realize they are already typing in their username/password to a GCM dialog and that's going to keep working. This is about removing HTTPS Digest auth with direct password transmission over the wire.)
I'm the same, and it's reassuring to know that I'm not the only one just using it as a free web host for personal projects.
Until starting a new job in January 2021, I "knew git" to the extent of git pull, git add, git commit -m, and git push. For everything else I just made a copy of the repo. Now I've learned a little more about branches and merge requests, but I still make a copy of the repo and copy my changes over when things go wrong. https://xkcd.com/1597/
Like you, I got some password-related warnings on GitHub, and honestly it's scaring me away. I know it'll take an hour or so to figure out what went wrong, regenerate a ton of SSH keys for every computer I own and link them to my account, disable 2FA because my phone number is in another country... I'd rather just upload a file, thanks.
The increased overhead means I'd rather just use FTP to upload some files to an HTTP server, but I don't think that such free FTP web hosts exist any more. At least, not ones with a domain that people recognise. That said, peterburk.github.com is no longer accessible, only peterburk.github.io, so maybe it is time for me to go looking for a free .com subdomain.
I'm grateful for GitHub hosting all the junk I decide to share, and I'm obviously not their target market if I'm not paying. I just wish there were a place I could drag & drop to upload content publicly.
You could do a single one per computer. You could even do a shared single one across all computers (it’s recommended against but not strictly worse than a shared password)
> disable 2FA because my phone number is in another country
Don’t use SMS for 2FA. Use TOTP (Google Authenticator or similar app. There are alternatives that let you sync) or U2F (hardware key)
I've tried setting up SSH keys many times and have somehow failed many times. The UX for security stuff just isn't there. I finally have gotten a workflow sort-of figured out and documented to remind myself in the future.
What you need is to install Git for Windows. It will include ssh-keygen (if it's not already there) and you can do the usual dance.