Seems reasonable to me. Since github is a git-as-a-service provider it makes sense to do this. From the headline I had thought they were making their own variant on the git protocol.
Seems reasonable to me. Since github is a git-as-a-service provider it makes sense to do this. From the headline I had thought they were making their own variant on the git protocol.
To be fair, extending, extending, and extinguishing does sound like something Microsoft might do.
2. EEE is dead (at least in MS)
SSH is used to authenticate to GitHub as a specific user. GitHub can use this for access control and logging. This isn't new or surprising.
If you don't want to authenticate to GitHub as a specific user, you can clone repositories over HTTPS. This isn't new either. You can't authenticate over HTTPS anymore, but if you were concerned about being "controlled and recorded", you weren't doing that anyway.
You can, just no longer using username and password. Instead you must use an access token.
I see here [0] a few benefits listed:
> Unique – tokens are specific to GitHub and can be generated per use or per device
> Revocable – tokens can can be individually revoked at any time without needing to update unaffected credentials
> Limited – tokens can be narrowly scoped to allow only the access necessary for the use case
> Random – tokens are not subject to the types of dictionary or brute force attempts that simpler passwords that you need to remember or enter regularly might be
...but if you can trivially obtain it by supplying username/password, then it's effectively equivalent anyway.
[0] https://github.blog/2020-12-15-token-authentication-requirem...