Just wondering what people are using to meet the 2FA requirement GitHub has been rolling out. I don’t love the idea of having an authenticator app installed on my phone just to log into GitHub. And really don’t want to give them my phone number just to log in.

Last year, we announced our commitment to require all developers who contribute code on GitHub.com to enable two-factor authentication (2FA)…

  • @Dymonika@beehaw.org
    link
    fedilink
    223 days ago

    Do you think the SMS codes are not time-based on the companies’ ends? How are they deriving the digits, then?

        • @delirious_owl
          link
          2
          edit-2
          22 days ago

          Best practice for a cryptographic nonce is to generate them randomly every time