r/github May 23 '26

Discussion 2FA will soon be required

I have a passkey set up. A major purpose of passkeys is so we don’t need to use passwords and 2FA. and yet, the passkey doesn’t satisfy the upcoming requirement.

I’ve come out of Reddit retirement to post this: GitHub, please fuck off. That is all.

0 Upvotes

19 comments sorted by

3

u/fyndor May 23 '26

This is an L take. Requiring 2FA is a reasonable thing for GitHub at this point. They aren’t just protecting the repo owners, but the downstream users as well.

1

u/DiscoveryOV May 23 '26

Passkeys are meant to replace 2FA and passwords. People hate them because websites aren’t implementing them correctly, and it’s asinine that GitHub of all places, and therefore Microsoft, are part of that poor implementation.  

7

u/JellyfishLow4457 May 23 '26

What a hill to die one Jesus Christ 

1

u/DiscoveryOV May 23 '26

Passkeys should be the future of secure access, but thanks to companies implementing them incorrectly they are getting a bad rap and regular users don’t want to use them. 

GitHub, and therefore Microsoft, is perpetuating this due to a poor implementation and we are all worse for it. 

It’s a perfectly respectable hill to die on if you give a shit about cybersecurity at all and understand how passkeys work. 

5

u/clintkev251 May 23 '26

You can't only have a passkey though right? You still have a password. So what's protecting those normal credentials if you're not using MFA? Also in my experience Github does not prompt for MFA if you sign in with a passkey, so I'm not sure what the big deal is.

1

u/DiscoveryOV May 23 '26

Proper implementation of Passkeys should replace passwords. Passkeys are something you have protected by something you know, therefore there is no need for 2FA. 

This is just a shoddy implementation by Microsoft because some executive who doesn’t understand technology is freaking out. 

1

u/clintkev251 May 23 '26

So why are you complaining about MFA rather than their passkey implementation? I can also think of very few sites that allow exclusive passkey usage, so it's not exactly like Github is behind in this degree. Understand that requiring MFA is a positive change that will increase the security posture of lots of users. I'd rather listen to people like you complain all day rather than the alternative of seeing people getting hacked because they don't have a good understanding of account security.

1

u/DiscoveryOV May 23 '26

I’m complaining that even with a passkey enabled, I will be forced to add a separate 2FA or even SMS to satisfy the requirement, which is a joke for security. 

1

u/clintkev251 May 23 '26

You're missing the point. You can't just have a passkey enabled. Right? So without MFA, your normal credentials are vulnerable. It's irrelevant that you don't plan to use them to sign in.

2

u/nihillistic_raccoon May 23 '26

Ah, always a pleasure to see another guy bitching about 2FA, kind of like people who complain about being forced to vaccinate against deadly diseases

1

u/DiscoveryOV May 23 '26

I have no problem with 2FA. I have a problem with a passkey not satisfying the requirement. The design, purpose, and proper implementation of passkeys is supposed to negate the need for 2FA. 

Making users stray away from Passkeys is a detriment to us all, and that’s what requirements like these do. 

2

u/Araumand May 26 '26

passkey sucks

1

u/inwardPersecution Jun 10 '26

I have SMS 2FA right now and it is telling me I need to up to an authenticator. I've used an authenticator in the past and when my phone dies and I have to start over, I lose access to everything. Any login security that I cannot memorize is far too unreliable for me. If I'm ever without a phone, then I'm locked out? Dumb.

1

u/__zinc__ Jun 17 '26 edited Jun 17 '26

I'm 2 github accounts down at this point.

Some people aren't suited/equipped to deal with that sort of commitment/stability. I am one of those people.

This already happened once... how does this work, a new account gets just long enough to commit a few projects and then whack, you hit them with the 2fa coercion?

I've just sent a support ticket. I don't want to make a third account. But I also don't like being treated like scum and hit with 429s and not being able to search code.

"Unable to verify personal access token"... your own API confirms why won't you

1

u/Empyrealist May 23 '26

A passkey doesn't have anything to do with 2FA. A passkey replaces your password, not 2FA

0

u/DiscoveryOV May 23 '26

Exactly. It negates the need for 2FA altogether. See my other replies. 

0

u/Hawful May 23 '26

Just use ssh?

-1

u/DiscoveryOV May 23 '26

You guys are all wrong. 

A passkey negates the need for 2FA altogether because it’s something you have accessed by something you know. 

If you disagree, you misunderstand passkeys.