git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [QUESTION]Is it possible that git would support two-factor authentication?

From
Konstantin Ryabitsev <konstantin@linuxfoundation.org>
Date
Aug 11, 2021, 13:50 UTC
Message-ID
<20210811135055.tqdblurgk3vw5lgm@nitro.local>
In-Reply-To
<66e42438fa9311ebaeb60026b95c99cc@oschina.cn>
On Wed, Aug 11, 2021 at 07:00:50PM +0800, lilinchao@oschina.cn wrote:
> Many websites support two-factor authentication(2FA) to log in, like Github, I wander if we can support it in application layer.
> When client clone something, they need  input username and password, it is like a website login process. For security, we can
> enable  2FA during this process.

As you well know, "cloning" a repository can be done via any number of mechanisms:

1. locally from another repository on disk
2. locally, from a git bundle file
3. remotely, using the anonymous git:// protocol
4. remotely, using ssh or http(s) protocols

2-factor authentication does not make sense in the first three cases (you already have access to all the objects with 1 and 2, and the git:// protocol is public and anonymous by design). For the ssh/https scheme, 2fa is already supported by the underlying protocol, so it does not make sense for git to implement it again on the application level.

Hope this helps.
-K
Previous: lilinchao@oschina.cnNext: Theodore Ts'o
Message 2 of 8 in “[QUESTION]Is it possible that git would support two-factor authentication?”
  1. lilinchao@oschina.cnAug 11, 2021
  2. Konstantin RyabitsevAug 11, 2021
  3. Theodore Ts'oAug 11, 2021
  4. brian m. carlsonAug 13, 2021
  5. Derrick StoleeAug 11, 2021
  6. lilinchao@oschina.cnAug 13, 2021
  7. Johannes SchindelinAug 14, 2021
  8. Matthew CheethamAug 17, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.