-
Notifications
You must be signed in to change notification settings - Fork 6
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Require org owners to use exclusively secure two-factor authentication #57
base: main
Are you sure you want to change the base?
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
1000000%.
(Isn't the only other option SMS?)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I don't have a strong opinion on this, but it seems like a good idea
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Sounds reasonable.
Ideally, we would have GitHub enforce it but, unfortunately, it looks like it is not possible to force require it just for owners. It might be a good idea to eventually require it for everyone but not sure how many people it would affect as https://github.com/orgs/NixOS/people?query=two-factor%3Ainsecure shows the same list for me as https://github.com/orgs/NixOS/people?query=two-factor%3Asecure |
@jtojnar I don't think that needs to be discussed here, but it shows two different lists for me: 66 pages for secure and 57 pages for insecure, so secure 2FA seems to be at least a close majority already. |
not sure what I need to do that github deems my 2FA as secure :D |
@Lassulus As Winter said, I think SMS is the only method not considered secure, can you confirm that you have that enabled (direct link to account security settings)? If so, you'll have to turn that off |
Turns out @tomberek and @Lassulus don't right now, I think we should.