Just wondering what people are using to meet the 2FA requirement GitHub has been rolling out. I don’t love the idea of having an authenticator app installed on my phone just to log into GitHub. And really don’t want to give them my phone number just to log in.

Last year, we announced our commitment to require all developers who contribute code on GitHub.com to enable two-factor authentication (2FA)…

  • privatizetwiddle@lemmy.sdf.org
    link
    fedilink
    arrow-up
    2
    ·
    7 months ago

    That’s still a single point of failure. What happens if someone finds an exploit that bypasses the login process entirely?

    I read this as someone bypassing the GitHub login entirely. Good luck 2FAing your way out of that one! 😜