I personally am fine with this.

you are viewing a single comment's thread
view the rest of the comments
[–] 3 points 3 years ago (1 child)

Normally you get a handful of recovery codes when you set up 2FA. If not, you can just create a backup of the QR-Code or secret when setting up 2FA and store it in a safe location. And even if all that fails there's usually a way to recover an account by going through support.

Although I wouldn't recommend it, there's also 2FA apps out there that have cloud-sync.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 3 years ago* (2 children)

    It's pretty hard to hand-write a QR code, I don't wish to pay the printer cartel $50 for the privilege of printing it, and it would of course be horribly insecure to print it with someone else's printer.

    And how would I use the QR code? I can't scan it with my phone's camera because allowing my phone access to my GitHub account is a security risk, and I can't scan it with my desktop because it doesn't have a camera.

    So, how is this going to work? How do I recover my GitHub account without making it less secure than it is with just a password?

  • source
  • parent
  • hideshow 4 child comments
  • [–] 3 points 3 years ago* (last edited 3 years ago)

    Is this some kind of joke that's going over my head?

    If not: The QR code alone doesn't give you access to the account. That's the entire point of 2FA. Plus, you always get a ~20 character code that can be backed up instead of the QR code. Screenshots are also a thing.

  • source
  • parent