How is 2FA a scam ? Nowhere in the article is a phone number mentioned which is the only potential "government tracking device". The second factor can be an authenticator app, or even a FIDO device
How is 2FA a scam ? Nowhere in the article is a phone number mentioned which is the only potential "government tracking device". The second factor can be an authenticator app, or even a FIDO device
That looks like offloading security issues to the user.
Sounds far fetched? If the code repositories are that valuable, why wouldn't state actors try to mess with the hardware and commit underhanded C or similar?
The repository owners would detect the malicious commit? Well, in that case, why do we need 2FA in the first place?
> Those old yubikeys [or similar HW device] have a flaw and are weak so we [read: the government] are deprecating them. You can change them here for the next year or use your phone or install our app.
Further in the future after a few cycles of the above
> Too few people use HW tokens so boot up your spy device now to log in.
Maybe it won't be HW flaws maybe it will be software. Maybe they'll mandate use of some chrome only feature. Maybe they bring out the Xbox authentication drink cans.