Hacker News new | ask | show | jobs
by cxr 474 days ago
> ["2FA" stands for] Two factor authentication

Great. Now go ahead and try to argue the indefensible position that relying on an authenticator to supply a passkey is somehow not a form of two-factor auth.

> I'm not using anything other than my browser.

... as your authenticator. The fact that you're using your browser and its built-in support for this as your authenticator but are using the term "browser" when you're talking about it instead of the word "authenticator" (GitHub's term—here's their documentation about authenticators, which I'm sure you could have Googled: <https://docs.github.com/en/authentication/authenticating-wit...>) doesn't change its role.

> (which doesn't take longer than 15-20s)

Aside from the fact that the ~5 seconds that it takes to create an HN account is not even the same as the 15–20 second estimate that you're offering here, there's the minor problem that that estimate is bogus.

You are simply not being honest in your reckoning of the respective costs. Here's GitHub's own documentation for the process of adding a passkey to your account:

<https://docs.github.com/en/authentication/authenticating-wit...>

(I'm sure you could have Googled it.)

> as I stated it's my opinion, having a different opinion doesn't make me dishonest

Stating your opinion doesn't make you dishonest, but arguing about things that are matters of fact and not opinions—measurable, quantitative things—and doing it with bad quantities chosen in a dishonest way is, in fact, dishonest.

Here's the Wikipedia article about intellectual dishonesty:

<https://en.wikipedia.org/wiki/Intellectual_dishonesty>

I'm sure you could have Googled it.