Hacker News new | ask | show | jobs
by pocksuppet 21 days ago
No, I didn't, because I quit GitHub when they started demanding mandatory SMS 2FA
2 comments

> No, I didn't, because I quit GitHub when they started demanding mandatory SMS 2FA

They haven't demanded that of me. I have 2FA with a Yubikey and a TOTP app.

I don't ever recall giving them my phone number.

Huh? Just to make sure I wasn't missing something, I checked and my GitHub account has only a TOTP app and hardware security key configured, no SMS/phone number.

As a matter of fact GH even has a red "Less secure" badge on the SMS 2FA in the settings discouraging its use, as well as the following text in the description: "We strongly advise against using SMS because it is susceptible to interception, does not provide resistance against phishing attacks, and deliverability can be unreliable."

This option must have been added later.
U2F was always an option, because I used it since they added the MFA requirement (and like others here never gave Github my phone number). I think TOTP was also available from the start. The warning to not use SMS for MFA might have been added later.
I’ve been using GitHub with TOTP since they added it in 2013, and other non-SMS methods since then. No phone number on my account.