▲ 396 ▼ GitHub to require 2FA on accounts by October 6, 2023 (github.blog) submitted 3 years ago* by Xylight@lemmy.xylight.dev to c/technology@lemmy.ml 125 comments fedilink hide all child comments I personally am fine with this.
[–] Oha@lemmy.ohaa.xyz 13 points 3 years ago (2 children) 2fa should be mandatory everywhere permalink fedilink source hideshow 4 child comments replies: [–] faerbit@feddit.de 19 points 3 years ago (1 child) Hard disagree. I do not want to have 2FA for every shittly little thing I do not care about. permalink fedilink source parent hideshow 2 child comments replies: [–] CoderKat@lemm.ee 1 point 3 years ago Yeah. GitHub makes sense because most users are writing code that can be executed by others. That makes GitHub accounts security critical. But a Lemmy account? Naw, you lose almost nothing if that gets compromised. A little bit of history and subscriptions, mostly. I'm in a discord that for some reason "requires" 2FA. Based on searching, I think they give everyone some kinda admin role or something? It doesn't actually require 2FA, but it shows a very annoying warning that covers up a bunch of the channel selection screen. But despite that, I don't really wanna deal with the hassle of 2FA on a chat app that's basically consequence free for me if it gets exploited. permalink fedilink source parent [–] sugar_in_your_tea@sh.itjust.works 1 point 3 years ago Specifically app-based 2FA, ideally Google Authenticator based. There are tons of great authenticator apps available that are all compatible, so it should absolutely be preferred over SMS or email. permalink fedilink source parent
[–] faerbit@feddit.de 19 points 3 years ago (1 child) Hard disagree. I do not want to have 2FA for every shittly little thing I do not care about. permalink fedilink source parent hideshow 2 child comments replies: [–] CoderKat@lemm.ee 1 point 3 years ago Yeah. GitHub makes sense because most users are writing code that can be executed by others. That makes GitHub accounts security critical. But a Lemmy account? Naw, you lose almost nothing if that gets compromised. A little bit of history and subscriptions, mostly. I'm in a discord that for some reason "requires" 2FA. Based on searching, I think they give everyone some kinda admin role or something? It doesn't actually require 2FA, but it shows a very annoying warning that covers up a bunch of the channel selection screen. But despite that, I don't really wanna deal with the hassle of 2FA on a chat app that's basically consequence free for me if it gets exploited. permalink fedilink source parent
[–] CoderKat@lemm.ee 1 point 3 years ago Yeah. GitHub makes sense because most users are writing code that can be executed by others. That makes GitHub accounts security critical. But a Lemmy account? Naw, you lose almost nothing if that gets compromised. A little bit of history and subscriptions, mostly. I'm in a discord that for some reason "requires" 2FA. Based on searching, I think they give everyone some kinda admin role or something? It doesn't actually require 2FA, but it shows a very annoying warning that covers up a bunch of the channel selection screen. But despite that, I don't really wanna deal with the hassle of 2FA on a chat app that's basically consequence free for me if it gets exploited. permalink fedilink source parent
[–] sugar_in_your_tea@sh.itjust.works 1 point 3 years ago Specifically app-based 2FA, ideally Google Authenticator based. There are tons of great authenticator apps available that are all compatible, so it should absolutely be preferred over SMS or email. permalink fedilink source parent