Skip Navigation
38 comments
  • I don't think so. Enforcing two-factor auth to be allowed to do certain things with an account just makes sense. It's definitely not an attempt to squeeze profit out of users per se, but rather an attempt to limit liability and the risk of costly support problems caused by passwords being compromised.

    • I think it's even more important with contributors of large projects and libraries used by a vast amount of software out there.

      It's not inconceivable that someone's account gets hijacked, and someone uses their trusted account to add a small snippet of malicious code in a commit, enabling a supply-chain attack.

  • Which part of this is infuriating you? The fact that a message is popping up or what it’s asking you to do? Or is it the fact that it’s all in comic sans? Honestly, 2FA is a really simple way to greatly improve security on your account. I’m no expert, so maybe it’s got major flaws that I don’t know about, but just set it up really quick and choose to remember your device. Now you’ll never need to worry about it and you won’t see this message

    • I've had numerous accounts of people getting my password through a breach or something and 2fa being the only thing that stopped them from getting into my account. On GitHub that's my strongest logins, don't know why anyone would be against securing their code

    • Unless you use a VPN/browser security addons (don't know which breaks it). The "register your device" has never stuck for me. But it's not a big deal even then, just another step as long as there are a few options to choose in case one method isn't possible at the time. The "are you a robot" ones though...I really need to get a bot to solve the ones that still pop up for me (definitely VPN).

    • I think what's infuriating me is that it's an inconvenience that's being paternalisticly imposed on me. That's what makes it feel like enshittification. I don't really care that much about the security of my account, and having to find my phone and wait for an app to open is just a hassle that I'd prefer to avoid. The fact that they unilaterally decided what ought to be best for me is what annoys me I guess.

38 comments