Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Account Recovery Process #15133

Closed
miketheman opened this issue Jan 2, 2024 · 2 comments
Closed

Account Recovery Process #15133

miketheman opened this issue Jan 2, 2024 · 2 comments
Labels
needs discussion a product management/policy issue maintainers and users should discuss security Security-related issues and pull requests

Comments

@miketheman
Copy link
Member

Would it be possible to implement a password reset process for users that are locked out of their 2FA with recovery codes lost? Right now the manual recovery process takes several months which can be problematic if you need to update a package that has a security issue.

GH uses SSH keys, or previously used devices techniques, see https://docs.github.com/en/authentication/securing-your-account-with-two-factor-authentication-2fa/recovering-your-account-if-you-lose-your-2fa-credentials#requesting-help-with-two-factor-authentication

Happy to help implementing something, or contributing in any way
Thanks

Originally posted by @tarekziade in #14010 (comment)

@miketheman miketheman added needs discussion a product management/policy issue maintainers and users should discuss security Security-related issues and pull requests labels Jan 2, 2024
@miketheman miketheman changed the title Would it be possible to implement a password reset process for users that are locked out of their 2FA with recovery codes lost? Right now the manual recovery process takes several months which can be problematic if you need to update a package that has a security issue. Account Recovery Process Jan 2, 2024
@miketheman
Copy link
Member Author

@tarekziade Thanks for inquiring!

One of the key features of the recovery codes is to not lose them. Treat them like exactly what they are - recovery codes. In the catastrophic event that the user has lost their 2FA method, account recovery codes are there to help. Losing them doesn't accomplish the goal.

However, if you're thinking of other account recovery processes, happy to hear a proposal!

@miketheman
Copy link
Member Author

Closing this discussion due to lack of response and the addition of staffing that have been handling account recovery processes.
This isn't saying that we won't ever explore other account recovery techniques in the future.

@miketheman miketheman closed this as not planned Won't fix, can't repro, duplicate, stale Dec 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs discussion a product management/policy issue maintainers and users should discuss security Security-related issues and pull requests
Projects
None yet
Development

No branches or pull requests

1 participant