TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Two-factor Authentication

267 pointsby tanokuover 11 years ago

18 comments

shmageggyover 11 years ago
I'd just like to point out that this is another example of the failure of the overly-rigid submission title policy here. This title tells me almost nothing about the content I'm about to see or whether it's relevant to me. Expecting to see something about 2FA in general or maybe even a library that eases implementation (given the github domain), I was let down when I opened the link and realized I didn't care in the least about this content. I wasted my time browsing, and I wasted even more time writing this rant.
评论 #6325222 未加载
评论 #6325148 未加载
评论 #6324967 未加载
pilifover 11 years ago
The issue I have with third-party token applications like the Duo Security one that the github guys are recommending is that due to the way how TOTP works (shared secret), I&#x27;m practically giving away my second factor to whoever produces the app.<p>Google Authenticator has the advantage that it&#x27;s Open Source, but I can&#x27;t really control whether the thing I downloaded in the app store is actually built from the public sources. But at least I can build my own if I have a developer account. Apparently people are having issues with GA on iOS7 though (it tends to forget the keys), so now I&#x27;m kinda out of luck.<p>Authy is both closed source and wants my cell phone number, Duo Security is just closed source.<p>I know it&#x27;s crazy inconvenient in the long run, but I&#x27;d much rather install a github official authenticator app than to trust a third-party app with the github token.
评论 #6323953 未加载
评论 #6324653 未加载
评论 #6325220 未加载
评论 #6324773 未加载
评论 #6323971 未加载
评论 #6326132 未加载
Umofomiaover 11 years ago
Excellent! Unless I&#x27;m missing it, it would be nice if there were a way to enforce a policy that members of an organizational team must have two-factor authentication enabled on their accounts.
mwwwover 11 years ago
It&#x27;s great to see another big web service implementing two-factor authentication. Looks like 2FA is going to be a standard option in web apps in the near future.
评论 #6322673 未加载
obilgicover 11 years ago
I am an international student and I literally hate when they don&#x27;t let me put in 2 different numbers. I get locked out when I travel. For example, twitter
评论 #6322898 未加载
评论 #6322912 未加载
评论 #6322897 未加载
jcurboover 11 years ago
What&#x27;s the best hardware TOTP token to get?
gbraadover 11 years ago
Shameless plug as this is another great use of my webapp <a href="http://gauth.apps.gbraad.nl/" rel="nofollow">http:&#x2F;&#x2F;gauth.apps.gbraad.nl&#x2F;</a> (<a href="http://bit.ly/g2fauth" rel="nofollow">http:&#x2F;&#x2F;bit.ly&#x2F;g2fauth</a>) Just bookmark and use it offline. keys are stored locally.<p>The Chrome extension was forcibly removed from the Chrome Store as BigG was somehow not happy; you can however still install it from here: <a href="http://bit.ly/g2fachrome" rel="nofollow">http:&#x2F;&#x2F;bit.ly&#x2F;g2fachrome</a>
chealdover 11 years ago
This has been needed for a long time. Glad to see it finally materialize!
jcastroover 11 years ago
Cool, I enabled it but had forgotten to download the recovery codes, next time I visited the site it bothered me to download them just in case, nice touch!
jarydover 11 years ago
How long before we see it in Github Enterprise?
评论 #6322896 未加载
aufreak3over 11 years ago
I&#x27;m beginning to wonder whether &quot;support for 2FA&quot; is a way for companies to get your telephone number into their database. Does using an authenticator application also provide the same information to the company?
评论 #6327415 未加载
markstanislavover 11 years ago
Great move by the GitHub team! Glad to see they went with TOTP rather than SMS-only. As they mentioned on their site, Duo Security&#x27;s mobile application supports TOTP and we&#x27;ll have an Octocat logo in soon :)
评论 #6325917 未加载
movingaheadover 11 years ago
I cannot use an Indian fallback SMS number. Wonder, what is behind that.
评论 #6323424 未加载
评论 #6323625 未加载
nathan_f77over 11 years ago
Hooray! Very nice implementation.
ing33kover 11 years ago
its very good to see github adding 2FA, but I wish they could also support their Indian users for using it via SMS.<p>edit : genuinely interested to know why they are not able to support SMS in some countries and mainly India.
评论 #6323650 未加载
评论 #6323624 未加载
评论 #6323626 未加载
eric59over 11 years ago
Does anyone have a good way of storing recovery codes? I currently keep them on paper, in my wallet, but with more and more sites using 2fa I&#x27;m having to carry more and more recovery codes around.
评论 #6324048 未加载
评论 #6323370 未加载
评论 #6325368 未加载
评论 #6326289 未加载
buro9over 11 years ago
Love it.<p>But Yubikey support as well please.
评论 #6324066 未加载
bitsweetover 11 years ago
Nice. Wish it integrated with Authy though
评论 #6322849 未加载
评论 #6322538 未加载
评论 #6322541 未加载
评论 #6323114 未加载