Damus
Sjors Provoost (possibly compromised) · 157w
Fwiw 2FA* saved my ass once, many years ago, when someone hijacked my domain**, set an email forward and reset the Github password. * = and the hackers lazyness, they could have done way more damage ** = where I forgot to set 2FA AND probably reused a password, despite having stopped reusing passwo...
RamenCoffee · 157w
The real threat is sim-swap attacks. I imagine the FBI can just request access to your github account with or without the 2FA.
waxwing · 157w
Yeah I'm less concerned about the NSA type threat (if they want to "do" my github account I'm sure they can), more the "uh oh because of a bug in the auth protocol or the auth app, hackers can take over accounts" or something like that. I mean, it is *2* FA, not 1 FA, so in theory it's not that sim...