GitHub education pack requesting real name on public profile
github.com
github.com
https://computersciencewiki.org/index.php/Right_to_anonymity
https://www.theverge.com/2018/2/12/17005746/facebook-real-na...
https://www.oaic.gov.au/privacy/australian-privacy-principle...
So, yeah, I assume there are many people using it on a daily basis, more than anyone else at one point in history for a particular geographic distribution.
However, this may actually have been a myth, since I can't seem to find any data to back up this claim.
Short answer:
- Free GitHub Pro
- A few hundred bucks of free credits on DigitalOcean, Azure, Heroku
- A few different free domain registration offers
- A few coding courses
- Some other software and SaaS at no cost
I almost never see anywhere to easily get educational discounts that doesn't require some kind of verification you are currently a student. Seems like Apple is the only major company without hard verification, but they seem to have a soft policy that allows buying devices at a discount for your child's, niece's, cousin's, etc school expenses
It was interesting, because I happened to graduate from college in May, much to my own surprise, and ID.me soon notified me that my student status had expired. I don't know if it was on a timer-deadline, or linked to the graduation event, but whichever it was, they were on the ball.
LinkedIn uses email addresses to verify employees, for example my own employer set up a thing, but it doesn't accept either of the work email addresses I've been issued, perhaps because we've got "two tiers" of employees and my email looks different from the full-timers'.
And you're right about folks keeping our .edu addresses in perpetuity. I worked for an .edu for 4 months, 24 years ago, and I still have access to, and control of, my email address there, in terms of where it forwards. I have no storage or other access, just the ability to point it somewhere.
It’s also built into some password managers
Mine is a Casio CG50 and this tool can do it: https://github.com/gbl08ma/utilities
There are other options
It doesn't have to be via your phone if you don't want it to be. You can buy a YubiKey or similar, or use something like https://github.com/simnalamburt/macos-totp-cli (I haven't tried it, just the first thing I found in a google search).
This made me think for a moment. Why not, though?
My password manager generates random passwords with numbers, special characters and whatnot with a length of 24 characters. Even I don't know most of my passwords at this point, so what's the problem with (secure) passwords?
Poor application security? That's not really my problem, is it?
edit: to add this. I know that "test123" would be a problem, but my secure passwords can not be guessed by anybody or really be bruteforced. so, what does 2FA really protect me from in those cases?
I don't trust Microsoft with my phone, and I don't want logging into my account to become a pain where I need a key. I'll just take my code elsewhere.
> Passwords alone are not good enough security.
Security will only ever be as good as the weakest part - and I happen to find phones pretty weak.
Forced 2FA on everyone is non-sense. Everyone should decide on their own what is enough security. All I had was a Linux repo mirror, with signed tags for tested releases of my kernel branches.
Zero security issues with that distribution method. 2FA is only useful for veryfying user logins, not repo content.
Anyway, they can do whatever they want. GIT is thankfully fully distributed repository management system, so github.com is quite optional.
I think MFA is important for something like code repositories.
https://megous.com/dl/tmp/egrdxmmfuiakyhkodsok.webm
This is what you get if you pay, too.
> I think MFA is important for something like code repositories.
I think it's not, because they can't be secured by it. As a code user I can't be sure repo was not tampered with, just because some service promises to use 2FA to authorize developer access to the repo.
The change being discussed is not about sharing your name with Microsoft GitHub but about having it on your profile. Your profile is shared to third-party such as apps with the right OAuth scope.
This IS the Internet for most people... And it was built by people like us who should know better :(
Practically everything around me in the 20s-30s age range is organised on walled garden social media. I also hear offhand that when seeking relationships you need some online presence or you will be seen as suspicious.
(Disclosure: although I worked for Google years ago and did read an internal memo back then from employees which complained about this policy, my comment is not based on any secret internal knowledge. My own job had nothing to do with Google+ or the real names policy.)
You can put your name out there without doxxing yourself.
I would be more worried about what Google is doing with Chrome than GitHub requiring a name.
No, you literally cannot in 2023. It's trivial to put together a very comprehensive profile on a person from all the data that has been leaked or is being sold with nothing but a name as a starting point.
> If you believe in something you sign your name to it
I do not see why that should ever be a requirement. You are free to take a project less seriously solely because you don't know the authors' legal names (although this makes literally no sense to me), but why should that be a rigid requirement?
Or for sale by advertising data brokers!
Without a beat, the next thing from this is "If you believe in this, you deserve to be fired." No thanks.
99.999999999999999% of all open source code has this following statement in some form
>THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS “AS IS” AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED
There is absolutely zero need for a real name and nobody believes in their own code ;)
The fundamental aspect of open source isn't about "believing" in what you are doing. You are simply sharing something you wrote. That's it. The vast majority of people are not trying to save the world by becoming the next JS web framework.