Raising the bar for software security: GitHub 2FA begins March 13
github.blog
github.blog
Nope, useless initiative if they allow people to use SMS codes. Sim-hijacking is so easy that I'd wager not having any 2FA is more secure than offering SMS 2FA, as people will also be able to social engineer Microsoft to give access to a GitHub account if they are the "telephone number owner", as long as they can prove they can solve the SMS 2FA.
Sad to see, but not surprising.
Maybe I should just self-host my few little open source projects...
Obviously, if your password manager gets broken into, you're fucked. But if the site only have the issue of exposing passwords, you'll be safe.
Why suggest an extra step to them if they're claiming it's unnecessary? Can you at least try to explain why you think it adds value?
I thought I already did? "But if the site only have the issue of exposing passwords, you'll be safe." is not clear enough?
Mostly the built-in Mac keychain, stored locally, no iCloud.
Of course. I have encrypted offsite backups, as one should. Doesn't everyone?
So yes, this is for the hardcore user and not for the students and people still trying to learn things. The latter are not part of the supply chain.
It seems like centralizing the idea of a “GitHub account” as a sort thing that needs to be secured and imbues a commit with trustworthiness. But wouldn’t it make more sense to use the already existing functionality to sign commits, with keys you control, if this is a real concern?
Prefer built in git functionality over GitHub-isms, right?
Last time I read through the T&C, they say you're not allowed to have multiple free accounts, but if you're paying for it, you should be fine. And if your employer requires you to have a GitHub account, they should pay for one for you to use.
This is Microsoft. Embrace (git) and extend (gittub-isms).
See the entire food delivery industry
Or “I don’t bring it to work, I want to focus on your issues 100% no distractions, boss :)”
If we decide to go with a BYOD or other telephony option, then I'm going to push for standardized 2FA hardware devices.
Hardware tokens cost <$50, compared to what companies pay employees on a monthly basis it's peanuts.
I feel the same about 2FA tokens. As a matter of convenience I install the tokens my employer gives me on my personal phone because it makes it easy for me to keep them available at all times.
If for some reason I was unable or unwilling to do so, though, I might expect to be allowed to expense a yubikey.
Not yet, it seems? "Lastly, we’re already testing passkeys internally, which we believe will combine ease of use with strong, phishing-resistant authentication. Keep an eye on this space for when this functionality is ready for you."
Passkeys are WebAuthn "discoverable credentials", meaning they contain a user identifier as well as a private key for signing.
When a site fully supports passkeys, you are able to sign in to your account without having to enter a username, just by using your site-specific passkey (e.g. https://www.passkeys.io).
GitHub's current implementation is based on pre-passkey WebAuthn that allows you to add a non-discoverable credential as 2nd factor. To sign in, you still need to enter your username, your password, and then get prompted for your WebAuthn credential, which can be stored on a physical security key, but also on your devices via the platform authenticator capability (Windows Hello, Touch ID, ...).
So, while GitHub's current 2nd-factor WebAuthn implementation (as awesome as it is) is not "passkey", I'm sure they will be among the first bigger websites to launch full passkey capabilities on their login page pretty soon.
I guess it’d be hard to require everybody to password protect their ssh keys.
Its these most common attacks that Github is addressing with this change.
I will not use 2FA, thus my github account goes into the trash bin.
I say this as someone with intentions to leave GitHub, but that has more to do with them ruining nixpkgs contribution history by MAKING ENTIRE ISSUES AND PULL REQUESTS UNVIEWABLE because a single banned user participated in them years ago. Love you GitHub, brilliant.
There are numerous devices you can use for TOTP 2FA, your computer, a hardware device and even your browser via authn.
Pick TOTP as your 2FA method and save the TOTP secret, which you can get on the TOTP setup page at Github by clicking the thing that says you want to use a text code instead of scanning a QR code.
It will give you a short text string. Save that string.
When you need the TOTP code for Github, use oathtool [1] or something similar. For oathtool:
oathtool --totp -b <aforementioned_string>
will give you the current TOTP code. The -b flag tells it the code is in base32. I think that is what Gitgub uses. If they use hex omit -b.The only case where it should be fine to have a single second factor is with your employer, where you have other means to authenticate (i.e. likely your boss knows you and can vouch for you on a 2FA reset).
Also making it mandatory for things that you may really don't care about is overkill.
I would prefer to have ID verification, rather than an anonymous account, for account recovery.
You lose the second factor, and you can re-authenticate by, let's say, making a small payment with a credit card in your name plus some photo id.
I can lose my authenticator app, printed backup code, my hardware key but I'd still have a way to get access to my account back.
Infact I was on the "sms is unsafe" bandwagon until I nearly lost access to my Google Account.
Never again. Sim jacking is not a real world issue for most people. I'm not special enough that someone, especially someone who has the means to do sim jacking to want access to my accounts.
People do what you are comfortable with, if you are that important, I'm sure whoever wants your stuff will find other ways to get it.[1]
- SMS
- Mobile app
What if someone doesn't have a phone?
What happens when my phone is eventually stolen? I must now depend on the goodwill of morose carriers?
I wonder if I will be able to connect and pull from a private repository without 2FA. Otherwise my personal web server setup breaks.
Per-repository deploy tokens should function for that purpose.
In Google's Workspace Admin just got to:
Security -> Authentication -> 2-step verification
Then choose "Any except verification codes via text, phone call". This allows them to use TOTP, a security key such as a usb key or if they have a phone like a Pixel or iPhone that has a security key built in, or TOTP. They can also approve logins from another device that is already logged in, and can generate long-lived backup codes.
You can also allow only a security key, no TOTP or prompts and if, you do that, you can disable backup codes as well.
Obviously, but I don't think they did good enough. Why enable SMS 2FA at all? It's horribly insecure.