Leaving GitHub
ratfactor.com
ratfactor.com
Open source today is absolutely security critical. If you have commit access to something like say, libjpeg or some other such widely used component, you make a very, very juicy target for attackers.
And it's hard to tell whether you are in such a category. You may not know that your small tool library happens to have made it into some big software product.
Also, Github's 2FA doesn't require SMS. You can use Google Authenticator just fine. It's just a secret obtained by scanning a QR code, your phone number is not involved. Yubikeys and similar are also supported, as well as authentication via the mobile app.
And, more and more keep bothering me with this, e.g., when trying to read Google mails via Thunderbird, you have to create 2FA in order to create an application token that can be used with Thunderbird. So many tokens and passwords. It really keeps getting on my nerves and I don't trust things that are locked onto my smartphone because it might get lost. The first reflex was to simply save the QR code, but then I also wanted to know how I could use it without Google authenticator and so I found oathtool. And as can be seen from the two necessary command line arguments, the default oathtool invocation also didn't work out of the box.
To be fair, Google and also Github, both, provide recovery codes, which can be used if you loose your 2FA device. But now you have basically 3 "passwords", two Yubikeys, plus your associated mail address, all of which you have to remember or store. All of this just for a single account out of a thousand, which you aggregate over a decade or more.
The author explicitly states in the post that that is not the issue:
"I have nothing against the concept of 2FA. I voluntarily use it elsewhere. That’s not what this is about."
I'm basically a nobody so of course Github doesn't care if I stay or go. But I don't have any investment in their issue tracker or proprietary features because I want to stay nimble and ready to drop GH from my remotes when the time comes.
https://f-droid.org/en/packages/com.beemdevelopment.aegis/
> Independent FOSS developers do not owe anything to companies, including the slightest effort to "secure the software supply chain" for "consumers." As the licenses say, THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND …
Right, the warranty has no protection against "the software also may be compromised by third parties and contain all kind of backdoors and exploits, which is also not my problem"
I'm sure Github is sad to see such contributors leave !
1. 2FA does not require your phone number.
2. If you don't already, you should use a public key for pushing your commits
It's highly unlikely that you lose commit access even if you don't complete the "enrollment" unless you use http authentication for pushing commits in which case you should realize that password security is a huge liability for any big web application and I recommend you reconsider your approach.
This statement does not appear to be correct.
According to the roadmap graphic[0] (that has no useful accessibility alt text) it says 7 days after deadline "Blocked from accessing GitHub features until you enable 2FA".
[0] https://github.blog/2022-12-14-raising-the-bar-for-software-...
First, with regard to comments re: SMS & phone numbers, it required a non-zero amount of research to discover that GH no longer requires or recommends use of SMS--so it's not unreasonable to not know this.
Second, there are a long list of issues that I have with both the policy & its roll-out but they can be summarised as "different people have different risk profiles" & "in this situation individual developers (the people whose free labour GH was built on) have the least amount of power".
There's a distinct lack of nuance in the implementation/roll-out & 2FA is being used as a blunt weapon because it's easier than accommodating individual developers needs.
At this current point in time the group of people affected is "all users who contribute code"[0] but it's presumably not--it's actually developers who have contributed code. There's no option to keep one's account & use it only for e.g. issue creation/commenting going forward.
(Also, it seems doubtful that this requirement is actually limited to people who "contribute code" but rather seems likely to also include people who "contribute" text files.)
Yes, security is important but it's also always a trade-off. Why isn't it up to individual projects to decide whether to only restrict code contributions to those people with 2FA?
The language used in communication about the changes is also twee[1] (for lack of a better word) and downplays the reality of the situation which is that if you don't enable 2FA or if you enable 2FA and then get locked out of your account you will lose access to the account & history--especially the "non-code" features.
At least on the main docs[2] it's more straight-forward about the situation.
If you don't understand what the problem is then, congratulations, you're probably not one of the people whose first thought in this situation is "if I enable 2FA there's a non-zero chance that in the future I'm going to lose access to all the possible account recovery methods". Which means you probably don't feel at risk of becoming homeless, don't have ADHD or exist in a myriad of contexts where such concerns do exist.
Did MS/GH consult with any disability/inclusiveness specialists when implementing the policy?
Also, the impact isn't just limited to GH when projects like Rust's crates.io also use GH for authentication.
[0] https://github.blog/2022-12-14-raising-the-bar-for-software-... Although in another place it says "active contributors" <https://github.blog/changelog/2022-11-21-updates-to-the-two-...>.
[1] "...it’s easy to start fresh with a new GitHub.com account and keep that contribution graph rightfully green." https://github.blog/2023-03-09-raising-the-bar-for-software-...
[2] https://docs.github.com/en/authentication/securing-your-acco...
- GitHub now requires 2FA
- Author reaction "Greaaaaaat, Microsoft wants to harvest more phone numbers."
- Author has a love/hate relationship with GitHub since 2012
- Author decides to not use GitHub anymore
I am not following the thinking process. And you can use a 2FA app, without giving your phone number to GH.
I can understand the stream of changes at GitHub does not resonates with the author opinions, but the "Microsoft wants phone numbers" is wrong I think.
I have to wonder if the author is deliberately misrepresenting 2fa to justify leaving, since they claim to understand it well.