• surfrock66@lemmy.world
    link
    fedilink
    English
    arrow-up
    27
    arrow-down
    2
    ·
    2 days ago

    Unless your bitwarden has MFA and locks after an amount of time commensurate with your security needs

    • plateee@piefed.social
      link
      fedilink
      English
      arrow-up
      10
      ·
      2 days ago

      True, but how does GitHub know your bitwarden has MFA? It only knows something has a valid credential.

      • surfrock66@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 day ago

        I don’t think that github has to know that. You could be using a password manager and choose to make it a minimum character boring password or meet minimum complexity requirements or use the same password on a million sites. You have to secure your credentials; complying with the minimums of a service isn’t security.

        • plateee@piefed.social
          link
          fedilink
          English
          arrow-up
          2
          ·
          21 hours ago

          GitHub doesn’t need to know that - I think that’s why it’s a bit of a cop out for MFA. Sure, your bitwarden may implement MFA, but just a chrome browser isn’t MFA.

          Passkeys enable sites to offload the responsibility of securing accounts to the user, and if the user chooses a weaker way to implement them, GitHub doesn’t give a fuck.

      • Natanael@infosec.pub
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        1
        ·
        2 days ago

        Github doesn’t need to know how you implement it, just that your browser is handling it (and in this case the browser lets Bitwarden handle it lol)