I just received an email from Github that they are now ofically begin to require users who contribute code need to have 2FA enabled.

Why isn’t password + email already sufficient? Why do I need to use a third FA to satisfy their requirements? Is it reasonable to feel stumped or angry about it?

Would like to hear your thoughts about this.

  • RovingFox@infosec.pub
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    More secure. If my phone is stolen, they have full acces to my mailbox but they will look long and hard at my passworded 2FA app.