Hacker News new | ask | show | jobs
by Nzen 1506 days ago
Github requires [0] the first 2FA mechanism to be totp or sms. Thereafter, you can add a webauthn compatible hardware key.

[0] https://docs.github.com/en/authentication/securing-your-acco...

1 comments

Why though? That makes absolutely no sense.
Just technically it makes no sense. WebAuthn is a great technology that addresses many privacy concerns, but once they had an excuse collecting phone numbers they don't want to stop. Even though it's not the most secure method. Google, and many others are the same way.

2FA is often used as an excuse to obtain more PII from people, and to verify your identity, as a whole. Most businesses want to match logins to individuals, not roles. And that's what 2FA provides them.

How do they get my phone number from TOTP?