SMS has been removed from the GitHub.com sudo page
github.blog
github.blog
Naturally is their fault for not getting them, and should be punished with the 5 to 10 € for going to the counter.
Additionally there are plenty among them that are technology illiterate.
These approaches only push them further away from society where only people that understand computers thrive.
The point is - I have some kind of an enforceable legal right to that number, whereas I currently have no such right to any particular account (and such rights can't be practically enforced for physical objects such as devices)
Note though that it varies depending on the thing protected. For GitHub, I’m cool with the risk that the government gets a subpoena to seize my phone or SIM card and log into GitHub.
For some other services like messaging, I’d rather have stronger controls.
You can even turn it into a QR code and tatoo it on your cat's butt.
Each backup might decrease the overall security, but while theoretically you can still remember TOTP tokens or write them down and put inside a safe (possible but impractical), with passkeys that's no longer possible.
> Then store your github TOTP token on multiple devices
> The first option has the same problem I mentioned
Math it again.
I don't want to depend on me not losing them (for example in a fire).