Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
GitHub requiring personal device ID (freecad.org)
5 points by app4soft on Aug 1, 2023 | hide | past | favorite | 2 comments


I'm confused about the comment referring to a WebCam? What does that have to do with 2FA?

FYI you can create a virtual WebAuthn device in Chrome DevTools and use that as a 2FA method (just don't lose it lol). I did this with Google where it was required to provide a phone number or hardware token in order to unlock the ability to switch to a simple TOTP method. I created the WebAuthn device, generated a TOTP, set TOTP as the default method, and then removed the WebAuthn device.

I'm not sure this applies to the GitHub situation (I am having trouble understanding the linked forum post), but it's a useful tip regardless.


I have yet to receive an email from GitHub about this. As it is, GitHub will send me a TOTP code by email when it sees that my IP address has changed. It isn't forced for every login. I don't see why this arrangement would change. In any case, a TOTP device is easy to build. I made a simple web page that can do this. It's a small snippet of code that you could download and run locally if it comes to that. There is no need to use a personal phone or other device. TOTP is a well-known standard (RFC 6238 & RFC 3548). No need for panic, lol.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: