1) They are my repos. I should get to decide the appropriate level of security.
2) 2FA is often used as a pretext for identity harvesting which are then abused for other purposes.
3) If there is account recovery via email then the whole thing is a charade anyway.
Okay, but there are many options, like TOTP code generators, that do not even require the internet to work.
> 3) If there is account recovery via email then the whole thing is a charade anyway.
You can disable all account recovery options in Settings.
GitHub is not forcing you to use 2FA to store your repos elsewhere. Just to interact with their website.
> I should get to decide the appropriate level of security.
People are really bad at deciding the appropriate level of security.
GitHub hosts a lot of very important projects that have impact in the real world. Forcing people to use the bare minimum to keep that environment relatively secure is probably not a bad idea.
That way when you set your password as "batman123" and are given commit access to some obscure project that is included as a dependency in 1000 other projects, your account is much less likely to be taken over as a means of pushing a malicious commit.
1) They are my repos. I should get to decide the appropriate level of security.
Can you really say they're yours if you host them on GitHub and it can restrict your access to them for basically any reason?And GitHub does have a spam problem (if you haven’t dealt with it yet, consider yourself lucky). Just the other day someone opened an issue in one of my repos and in less than a minute two spam accounts replied with links to download malware. Fortunately I caught them right then and there, deleted the comments, and reported the accounts to GitHub which banned them soon after.
If someone can open the handle they can kick down the door as well.
Protecting the security of multiple devices is much easier than maintaining, rotating, and securing cryptographically secure passwords. Ideally, as with most things in security, do both. There’s no real reason to eschew 2FA other than “I hate typing in a code sometimes.”
Certainly. If we're considering password manager compromise, it's also reasonable to include compromises of all 2FA mechanisms. Users can often have 2FA creds phished just by calling them ("something is wrong with your account, please read the 2FA code to verify your identity"). Sure, you and I wouldn't fall for this, but there are plenty of retirees out there who have. At that point, neither 2FA nor password manager would save them. You could compromise the password manager by social engineering ("add evilsite.ru to the allowed sites") or even by supply chain attacks (create a build that permits evilsite.ru). Since supply chain attacks are a reasonable hack against password managers, the same could be said about 2FA apps.
Consequently, we don't get anywhere productive in this discussion by assuming software compromise into the threat model.
Right, I said that even if you do both, both can still be compromised simultaneously and independently. The discussion is more productive if we assume that the password manager can be made secure in the same way that 2FA can be made secure.
This returns to my original argument that “assuming a secure password manager with phishing protection, 2fa+password provides no more security than a high entropy password.” Before we go there, this also includes the unstated assumption that the website also leaks only useless information to an attacker (salted hashes that would require centuries to brute force).
Not even that is a good reason for someone who uses a password manager. Most of them today allow storing your 2FA key and auto-fill them.
I don’t like that Spotify asked me for a valid credit card, so I’m cancelling my 30 day free trial. I don’t listen to much music anyway.