{"thread":{"id":"32929","subject":"feature request","startedAt":"2013-02-18T18:52:38Z","lastAt":"2013-02-19T22:27:19Z","messageCount":5,"participants":["Jay Townsend","James Nylen","Jeff King","Drew Northup","Shawn Pearce"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"209700","messageId":"BLU0-SMTP2753D5BFC50D7334EDDE278E1F40@phx.gbl","threadId":"32929","inReplyTo":null,"subject":"feature request","fromName":"Jay Townsend","fromEmail":"townsend891@hotmail.com","sentAt":"2013-02-18T18:52:38Z","receivedAt":"2013-02-18T18:52:38Z","isPatch":false,"sender":{"key":"townsend891@hotmail.com","avatar":null},"body":"Hi everyone,\n\n\nJust would like to request a security feature to help secure peoples \ngithub accounts more by supporting 2 factor authentication like the \nyubikey more information can be found from this link \nwww.yubico.com/develop/ and googles 2 factor authentication. Hope it \ngets implemented as I think it would make a great feature\n"},{"id":"209711","messageId":"CABVa4NgsbeNGS2F2jQJ5d9bDcFb4=oEVrBg_-n2eYjwnfQzMqA@mail.gmail.com","threadId":"32929","inReplyTo":"BLU0-SMTP2753D5BFC50D7334EDDE278E1F40@phx.gbl","subject":"Re: feature request","fromName":"James Nylen","fromEmail":"jnylen@gmail.com","sentAt":"2013-02-18T19:54:30Z","receivedAt":"2013-02-18T19:54:30Z","isPatch":false,"sender":{"key":"jnylen@gmail.com","avatar":"https://gravatar.com/avatar/96804ac655933f5b6380e992610d6ff9029c6d04db1042d4bec381312ff7ff1b?d=mp&s=160"},"body":"On Mon, Feb 18, 2013 at 1:52 PM, Jay Townsend <townsend891@hotmail.com> wrote:\n> Hi everyone,\n>\n> Just would like to request a security feature to help secure peoples github\n> accounts more by supporting 2 factor authentication like the yubikey more\n> information can be found from this link www.yubico.com/develop/ and googles\n> 2 factor authentication. Hope it gets implemented as I think it would make a\n> great feature\n\nThis would most likely be something that users would set up with their\nSSH client, and GitHub would have to provide support for it on their\nservers as well.  It shouldn't require any changes to git.  Here is an\nexample of how this could be done:\n\nhttp://www.howtogeek.com/121650/how-to-secure-ssh-with-google-authenticators-two-factor-authentication/\n\nI like the idea, and I would probably use it if it were available.\nJeff, what do you think?\n"},{"id":"209720","messageId":"20130218204511.GA27308@sigill.intra.peff.net","threadId":"32929","inReplyTo":"CABVa4NgsbeNGS2F2jQJ5d9bDcFb4=oEVrBg_-n2eYjwnfQzMqA@mail.gmail.com","subject":"Re: feature request","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2013-02-18T20:45:11Z","receivedAt":"2013-02-18T20:45:11Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Mon, Feb 18, 2013 at 02:54:30PM -0500, James Nylen wrote:\n\n> > Just would like to request a security feature to help secure peoples github\n> > accounts more by supporting 2 factor authentication like the yubikey more\n> > information can be found from this link www.yubico.com/develop/ and googles\n> > 2 factor authentication. Hope it gets implemented as I think it would make a\n> > great feature\n> \n> This would most likely be something that users would set up with their\n> SSH client, and GitHub would have to provide support for it on their\n> servers as well.  It shouldn't require any changes to git.  Here is an\n> example of how this could be done:\n> \n> http://www.howtogeek.com/121650/how-to-secure-ssh-with-google-authenticators-two-factor-authentication/\n> \n> I like the idea, and I would probably use it if it were available.\n> Jeff, what do you think?\n\nWhen you are talking about something like GitHub, there are a lot of\ntimes and methods to authenticate: logging into the web service, using\nan ssh key for git-over-ssh, using a password for git-over-http, tokens\nfor API access, and probably more that I can't think of right now.\n\nLogging into the web page can add 2-factor auth pretty easily, since\nit's a web form.\n\nGit over ssh can also do so without changes to git, because we rely on\nssh to do all of the interactive authentication.  However, I wonder how\nmany people would be that interested in it, as key auth already provides\nsome degree of two factor protection, assuming you protect your key with\na passphrase (the threat model is different, of course, because the two\nfactors are happening on the client, and do not involve the server at\nall).\n\nGit over http _would_ need git client support, since it asks the user\nfor the password directly. Or at the very least some clever encoding\nscheme where your password becomes \"<real_password>:<2FA_pass>\" or\nsomething. But I'm not sure that people want raw two-factor\nauthentication for pushes. It's a giant pain, and people were recently\nhappy to move to password-less pushes via credential helpers; this would\nmove in the opposite direction.\n\nThe thing that makes 2FA usable in the web browser setting is that you\nauthenticate only occasionally, and get a token (i.e., a cookie) from\nthe server that lets you have a longer session without re-authenticating.\nI suspect a usable 2FA scheme for http pushes would involve a special\ncredential helper that did the 2FA auth to receive a cookie on the first\nuse, cached the cookie, and then provided it for subsequent auth\nrequests. That would not necessarily involve changing git, but it would\nmean writing the appropriate helper (and the server side to match). I\nseem to recall Shawn mentioning that Google does something like this\ninternally, but I don't know the details[1].\n\nSo yes. It's an interesting direction to go, but I think there's a fair\nbit of work, and it needs to be broken down into how specific services\nwill interact with it. The first step would probably be securing the web\nlogin with it, since that is the easiest one to do, and also the most\npowerful interface (the other ones just let you push or fetch code; the\nweb interface lets you delete repos, change passwords, access billing,\netc).\n\nBut that first step is something that would happen entirely at GitHub,\nwith no client support necessary. We don't have schedules or plans, and\nwe don't promise features. So I can neither confirm nor deny that people\nare working on it right now.\n\n-Peff\n\n[1] I don't know if Google's system is based on the Google Authenticator\n    system. But it would be great if there could be an open,\n    standards-based system for doing 2FA+cookie authentication like\n    this. I'd hate to have \"the GitHub credential helper\" and \"the\n    Google credential helper\". I'm not well-versed enough in the area to\n    know what's feasible and what the standards are.\n"},{"id":"209759","messageId":"CAM9Z-n=2vWS0MXx8GWZ0UpkfDQapRcHFhWKhiVvXx5oaz=YQ4w@mail.gmail.com","threadId":"32929","inReplyTo":"20130218204511.GA27308@sigill.intra.peff.net","subject":"Re: feature request","fromName":"Drew Northup","fromEmail":"n1xim.email@gmail.com","sentAt":"2013-02-19T03:26:25Z","receivedAt":"2013-02-19T03:26:25Z","isPatch":false,"sender":{"key":"n1xim.email@gmail.com","avatar":null},"body":"On Mon, Feb 18, 2013 at 3:45 PM, Jeff King <peff@peff.net> wrote:\n> On Mon, Feb 18, 2013 at 02:54:30PM -0500, James Nylen wrote:\n>> > Just would like to request a security feature to help secure peoples github\n>> > accounts more by supporting 2 factor authentication like the yubikey more\n>> > information can be found from this link www.yubico.com/develop/ and googles\n>> > 2 factor authentication. Hope it gets implemented as I think it would make a\n>> > great feature\n>>\n>> I like the idea, and I would probably use it if it were available.\n>> Jeff, what do you think?\n> [1] I don't know if Google's system is based on the Google Authenticator\n>     system. But it would be great if there could be an open,\n>     standards-based system for doing 2FA+cookie authentication like\n>     this. I'd hate to have \"the GitHub credential helper\" and \"the\n>     Google credential helper\". I'm not well-versed enough in the area to\n>     know what's feasible and what the standards are.\n\nI don't know what the specific infrastructure they (Google's\nengineers) are using is (something written in python if I'm not\nmistaken), but @$dayjob we've managed to authenticate to Google Apps\nusing SAML 1.1 & SAML2 wrappers \"living\" in both CAS and Shibboleth.\nSAML is a standard and is supported (in whole or in part) by a lot of\nsystems and SSOs out there. Given the way that systems like that work\nI don't see Git authenticating that way any time soon (but I've been\nsurprised before).\n\n-- \n-Drew Northup\n--------------------------------------------------------------\n\"As opposed to vegetable or mineral error?\"\n-John Pescatore, SANS NewsBites Vol. 12 Num. 59\n"},{"id":"209868","messageId":"CAJo=hJvmaj4Yn6ACDxQvnetfU+ay1hbfwsnCNN+tGG9MNoovkA@mail.gmail.com","threadId":"32929","inReplyTo":"20130218204511.GA27308@sigill.intra.peff.net","subject":"Re: feature request","fromName":"Shawn Pearce","fromEmail":"spearce@spearce.org","sentAt":"2013-02-19T22:27:19Z","receivedAt":"2013-02-19T22:27:19Z","isPatch":false,"sender":{"key":"spearce@spearce.org","avatar":"https://avatars.githubusercontent.com/u/34844?v=4"},"body":"On Mon, Feb 18, 2013 at 12:45 PM, Jeff King <peff@peff.net> wrote:\n>\n> The thing that makes 2FA usable in the web browser setting is that you\n> authenticate only occasionally, and get a token (i.e., a cookie) from\n> the server that lets you have a longer session without re-authenticating.\n\nRight, otherwise you spend all day typing in your credentials and\nsyncing with the 2nd factor device.\n\n> I suspect a usable 2FA scheme for http pushes would involve a special\n> credential helper that did the 2FA auth to receive a cookie on the first\n> use, cached the cookie, and then provided it for subsequent auth\n> requests. That would not necessarily involve changing git, but it would\n> mean writing the appropriate helper (and the server side to match). I\n> seem to recall Shawn mentioning that Google does something like this\n> internally, but I don't know the details[1].\n...\n> [1] I don't know if Google's system is based on the Google Authenticator\n>     system. But it would be great if there could be an open,\n>     standards-based system for doing 2FA+cookie authentication like\n>     this. I'd hate to have \"the GitHub credential helper\" and \"the\n>     Google credential helper\". I'm not well-versed enough in the area to\n>     know what's feasible and what the standards are.\n\nYes, it is based on the Google Authenticator system, but that's not\nrelevant to how Git works with it. :-)\n\nWe have a special \"git-remote-sso\" helper we install onto corporate\nworkstations. This allows Git to understand the \"sso://\" protocol.\ngit-remote-sso is a small application that:\n\n- reads the URL from the command line,\n- makes sure a Netscape style cookies file has a current cookie for\nthe named host,\n   - acquires or updates cookie if necessary\n- rewrites the URL to be https://\n- execs `git -c http.cookiefile=$cookiefile remote-https $URL`\n\nThe way 2FA works is the user authenticates to a special internal SSO\nmanagement point in their web browser once per period (I decline to\nsay how often but its tolerable). Users typically are presented this\nSSO page anyway by other applications they visit, or they bookmark the\nmain entry point. A Chrome or Firefox extension has been installed and\nauthorized to steal cookies from this host. The extension writes the\nuser's cookie to a local file on disk. Our git-remote-sso tool uses\nthis cookie file to setup per-host cookies on demand within the\nauthentication period.\n\nHorrifically hacky. It would be nice if this was more integrated into\nGit itself, where the cookies could be acquired/refreshed through the\ncredential helper system rather than wrapping git-remote-https with a\nmagical URL. I am a fan of the way our extension manages to get the\ntoken conveyed automatically for me. Much easier than the OAuth\nflows[2], but harder to replicate in the wild. Our IT group makes sure\nthe extension is installed on workstations as part of the base OS\nimage.\n\n[2] https://developers.google.com/storage/docs/gsutil_install#authenticate\n"}]}