Re: Gitlab update, 2FA now mandatory

2022-10-31 Thread Dan Leinir Turthra Jensen
On Friday, 28 October 2022 21:57:16 GMT Ben Cooksley wrote: > Hi all, > > Following some additional analysis of the situation I've now adjusted the > policy surrounding enforced use of 2FA. > > Going forward it will only be enforced on people who are one of the > following: > - KDE Developers >

Re: Gitlab update, 2FA now mandatory

2022-10-29 Thread Christoph Cullmann (cullmann.io)
On 2022-10-28 22:57, Ben Cooksley wrote: Hi all, Following some additional analysis of the situation I've now adjusted the policy surrounding enforced use of 2FA. Going forward it will only be enforced on people who are one of the following: - KDE Developers - KDE e.V. Members (including the

Re: Gitlab update, 2FA now mandatory

2022-10-28 Thread Ben Cooksley
Hi all, Following some additional analysis of the situation I've now adjusted the policy surrounding enforced use of 2FA. Going forward it will only be enforced on people who are one of the following: - KDE Developers - KDE e.V. Members (including the Board) - KDE e.V. Staff (whether they be

Re: Gitlab update, 2FA now mandatory

2022-10-27 Thread Christoph Cullmann (cullmann.io)
On 2022-10-25 20:53, Albert Astals Cid wrote: > > Hi, > > > > whereas I can see the security benefit, this raises the hurdle for one > > time contributors again a lot. > > > > Before you already had to register to get your merge request, > > now you need to setup this too (or at least soon it is

Re: Gitlab update, 2FA now mandatory

2022-10-26 Thread Jack
On 2022.10.26 16:33, Tobias Leupold wrote: Am Montag, 24. Oktober 2022, 01:16:30 CEST schrieb Jack: > On 2022.10.23 02:32, Ben Cooksley wrote: > > Hi all, > > > > This afternoon I updated invent.kde.org to the latest version of > > Gitlab, > > 15.5. > > Release notes for this can be found at > >

Re: Gitlab update, 2FA now mandatory

2022-10-26 Thread Tobias Leupold
Am Montag, 24. Oktober 2022, 01:16:30 CEST schrieb Jack: > On 2022.10.23 02:32, Ben Cooksley wrote: > > Hi all, > > > > This afternoon I updated invent.kde.org to the latest version of > > Gitlab, > > 15.5. > > Release notes for this can be found at > >

Re: Gitlab update, 2FA now mandatory

2022-10-26 Thread Ahmad Samir
On 25/10/22 15:06, Christoph Cullmann (cullmann.io) wrote: On 2022-10-25 14:55, Ahmad Samir wrote: On 25/10/22 14:31, Christoph Cullmann (cullmann.io) wrote: On 2022-10-25 13:52, Ahmad Samir wrote: On 25/10/22 13:29, Harald Sitter wrote: On Tue, Oct 25, 2022 at 1:22 PM Ahmad Samir wrote:

Re: Gitlab update, 2FA now mandatory

2022-10-26 Thread Ben Cooksley
On Wed, Oct 26, 2022 at 1:32 AM Christoph Cullmann (cullmann.io) < christ...@cullmann.io> wrote: > On 2022-10-25 13:52, Ahmad Samir wrote: > > On 25/10/22 13:29, Harald Sitter wrote: > >> On Tue, Oct 25, 2022 at 1:22 PM Ahmad Samir > >> wrote: > >>> > >>> Can a first time contributor create a

Re: Gitlab update, 2FA now mandatory

2022-10-26 Thread Ben Cooksley
On Wed, Oct 26, 2022 at 12:22 AM Ahmad Samir wrote: > On 25/10/22 12:11, Carl Schwan wrote: > > Le dimanche 23 octobre 2022 à 5:55 PM, Christoph Cullmann (cullmann.io) > a écrit : > > > > > >> On 2022-10-23 08:32, Ben Cooksley wrote: > >> > >>> Hi all, > >>> > >>> This afternoon I updated

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread Christoph Cullmann (cullmann.io)
On 2022-10-25 21:29, Christoph Cullmann (cullmann.io) wrote: On 2022-10-25 20:53, Albert Astals Cid wrote: i concur - after spending so long trying to attract casual contributors, putting up a huge barrier like this is just not helpful. So, 2FA for people who area able to actually mess stuff

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread Christoph Cullmann (cullmann.io)
On 2022-10-25 20:53, Albert Astals Cid wrote: i concur - after spending so long trying to attract casual contributors, putting up a huge barrier like this is just not helpful. So, 2FA for people who area able to actually mess stuff up, absolutely, we have responsibility here and that's fine,

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread Albert Astals Cid
El dimarts, 25 d’octubre de 2022, a les 12:19:36 (CEST), Dan Leinir Turthra Jensen va escriure: > On Tuesday, 25 October 2022 11:11:46 BST Carl Schwan wrote: > > Le dimanche 23 octobre 2022 à 5:55 PM, Christoph Cullmann (cullmann.io) > > a écrit : > > > On 2022-10-23 08:32, Ben Cooksley wrote:

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread Christoph Cullmann (cullmann.io)
On 2022-10-25 14:55, Ahmad Samir wrote: On 25/10/22 14:31, Christoph Cullmann (cullmann.io) wrote: On 2022-10-25 13:52, Ahmad Samir wrote: On 25/10/22 13:29, Harald Sitter wrote: On Tue, Oct 25, 2022 at 1:22 PM Ahmad Samir wrote: Can a first time contributor create a fork, create

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread Ahmad Samir
On 25/10/22 14:31, Christoph Cullmann (cullmann.io) wrote: On 2022-10-25 13:52, Ahmad Samir wrote: On 25/10/22 13:29, Harald Sitter wrote: On Tue, Oct 25, 2022 at 1:22 PM Ahmad Samir wrote: Can a first time contributor create a fork, create multiple/100 MR's and spin up CI jobs? if yes,

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread Harald Sitter
On Tue, Oct 25, 2022 at 1:52 PM Ahmad Samir wrote: > > On 25/10/22 13:29, Harald Sitter wrote: > > On Tue, Oct 25, 2022 at 1:22 PM Ahmad Samir wrote: > >> > >> Can a first time contributor create a fork, create multiple/100 MR's and > >> spin up CI jobs? if yes, > >> then, first time

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread David Jarvie
On 25 October 2022 11:19:36 BST, Dan Leinir Turthra Jensen wrote: > On Tuesday, 25 October 2022 11:11:46 BST Carl Schwan wrote: > > Le dimanche 23 octobre 2022 à 5:55 PM, Christoph Cullmann (cullmann.io) > a écrit : > > > On 2022-10-23 08:32, Ben Cooksley wrote: > > > > Hi all, > > > > > > >

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread Christoph Cullmann (cullmann.io)
On 2022-10-25 13:52, Ahmad Samir wrote: On 25/10/22 13:29, Harald Sitter wrote: On Tue, Oct 25, 2022 at 1:22 PM Ahmad Samir wrote: Can a first time contributor create a fork, create multiple/100 MR's and spin up CI jobs? if yes, then, first time contributors can disrupt the system.

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread Ahmad Samir
On 25/10/22 13:29, Harald Sitter wrote: On Tue, Oct 25, 2022 at 1:22 PM Ahmad Samir wrote: Can a first time contributor create a fork, create multiple/100 MR's and spin up CI jobs? if yes, then, first time contributors can disrupt the system. Weren't there some suspicious accounts that were

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread Harald Sitter
On Tue, Oct 25, 2022 at 1:22 PM Ahmad Samir wrote: > > On 25/10/22 12:11, Carl Schwan wrote: > > Le dimanche 23 octobre 2022 à 5:55 PM, Christoph Cullmann (cullmann.io) > > a écrit : > > > > > >> On 2022-10-23 08:32, Ben Cooksley wrote: > >> > >>> Hi all, > >>> > >>> This afternoon I updated

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread Ahmad Samir
On 25/10/22 12:11, Carl Schwan wrote: Le dimanche 23 octobre 2022 à 5:55 PM, Christoph Cullmann (cullmann.io) a écrit : On 2022-10-23 08:32, Ben Cooksley wrote: Hi all, This afternoon I updated invent.kde.org [1] to the latest version of Gitlab, 15.5. Release notes for this can be found

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread Dan Leinir Turthra Jensen
On Tuesday, 25 October 2022 11:11:46 BST Carl Schwan wrote: > Le dimanche 23 octobre 2022 à 5:55 PM, Christoph Cullmann (cullmann.io) a écrit : > > On 2022-10-23 08:32, Ben Cooksley wrote: > > > Hi all, > > > > > > This afternoon I updated invent.kde.org [1] to the latest version of > > >

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread Carl Schwan
Le dimanche 23 octobre 2022 à 5:55 PM, Christoph Cullmann (cullmann.io) a écrit : > On 2022-10-23 08:32, Ben Cooksley wrote: > > > Hi all, > > > > This afternoon I updated invent.kde.org [1] to the latest version of > > Gitlab, 15.5. > > Release notes for this can be found at > >

Re: Gitlab update, 2FA now mandatory

2022-10-25 Thread Frederik Schwarzer
Hi, making assumptions or generalising a group of people will always "forget" about some people. What about translators? Are they all as "techy" as you imagine all our devs are? (Spoiler: no they aren't) What about older contributors (like me)? Are they all as up-to-date with emerging

Re: Gitlab update, 2FA now mandatory

2022-10-24 Thread Victoria Fierce
I would like to think that anyone who either knows /enough/ about KDE that they want to contribute or has used basically any other internet service before coming to KDE is already familiar with 2FA that it won't be a problem for them. Our users are smart, our devs are also (often) smart,

Re: Gitlab update, 2FA now mandatory

2022-10-24 Thread Andrius Štikonas
2022 m. spalio 24 d., pirmadienis 00:16:30 BST Jack rašė: > On 2022.10.23 02:32, Ben Cooksley wrote: > > Hi all, > > > > This afternoon I updated invent.kde.org to the latest version of > > Gitlab, > > 15.5. > > Release notes for this can be found at > >

Re: Gitlab update, 2FA now mandatory

2022-10-24 Thread Ben Cooksley
On Mon, Oct 24, 2022 at 11:56 PM Raghavendra Kamath wrote: > On Sunday, 23 October, 2022 12:02:23 PM IST Ben Cooksley wrote: > > I > > have also enabled Mandatory 2FA, which Gitlab will ask you to configure > > next time you access it. > > Is the 2FA in KDE identity website same as this. The KDE

Re: Gitlab update, 2FA now mandatory

2022-10-24 Thread Raghavendra Kamath
On Sunday, 23 October, 2022 12:02:23 PM IST Ben Cooksley wrote: > I > have also enabled Mandatory 2FA, which Gitlab will ask you to configure > next time you access it. Is the 2FA in KDE identity website same as this. The KDE identity shows a grid based system where you combine the grid and your

Re: Gitlab update, 2FA now mandatory

2022-10-24 Thread Christoph Cullmann (cullmann.io)
On 2022-10-24 11:23, Ingo Klöcker wrote: On Montag, 24. Oktober 2022 09:19:49 CEST Christoph Cullmann (cullmann.io) wrote: I think it is rather worse that now first time contributors have this requirement. Do you have proof for this, e.g. a study, or is this just your Bauchgefühl (gut

Re: Gitlab update, 2FA now mandatory

2022-10-24 Thread Ingo Klöcker
On Montag, 24. Oktober 2022 09:19:49 CEST Christoph Cullmann (cullmann.io) wrote: > I think it is rather worse that now first time contributors have this > requirement. Do you have proof for this, e.g. a study, or is this just your Bauchgefühl (gut feeling)? There is plenty of proof (e.g. TBs

Re: Gitlab update, 2FA now mandatory

2022-10-24 Thread Timothée Giet
Le 24/10/2022 à 09:24, Ivan Čukić a écrit : Sorry to be dense, but without a webauthn token device, it seems I'm at a total block if I don't have a phone (or don't have it with me.) Is that correct, or is there some fine manual I need to read? You can generate TOTP codes using KeePassXC.

Re: Gitlab update, 2FA now mandatory

2022-10-24 Thread Ivan Čukić
> > Sorry to be dense, but without a webauthn token device, it seems I'm at > > a total block if I don't have a phone (or don't have it with me.) Is > > that correct, or is there some fine manual I need to read? > > You can generate TOTP codes using KeePassXC. There's also Dan Vratil's Plasma

Re: Gitlab update, 2FA now mandatory

2022-10-24 Thread Christoph Cullmann (cullmann.io)
Hi, Could the 2FA stuff perhaps be limited to people with developer role or such? It is technically possible to only apply the mandatory 2FA rules to only certain groups as Developer accounts are simply membership in teams/kde-developers. See

Re: Gitlab update, 2FA now mandatory

2022-10-23 Thread Mathias Homann
Am Montag, 24. Oktober 2022, 01:16:30 CEST schrieb Jack: > On 2022.10.23 02:32, Ben Cooksley wrote: > > Hi all, > > > > This afternoon I updated invent.kde.org to the latest version of > > Gitlab, > > 15.5. > > Release notes for this can be found at > >

Re: Gitlab update, 2FA now mandatory

2022-10-23 Thread Ben Cooksley
On Mon, Oct 24, 2022 at 12:16 PM Jack wrote: > On 2022.10.23 02:32, Ben Cooksley wrote: > > Hi all, > > > > This afternoon I updated invent.kde.org to the latest version of > > Gitlab, > > 15.5. > > Release notes for this can be found at > >

Re: Gitlab update, 2FA now mandatory

2022-10-23 Thread Anna “CyberTailor”
On 2022-10-23 19:16, Jack wrote: > On 2022.10.23 02:32, Ben Cooksley wrote: > > As part of securing Invent against recently detected suspicious > > activity I > > have also enabled Mandatory 2FA, which Gitlab will ask you to > > configure > > next time you access it. This can be done using

Re: Gitlab update, 2FA now mandatory

2022-10-23 Thread Jack
On 2022.10.23 02:32, Ben Cooksley wrote: Hi all, This afternoon I updated invent.kde.org to the latest version of Gitlab, 15.5. Release notes for this can be found at https://about.gitlab.com/releases/2022/10/22/gitlab-15-5-released/ There isn't much notable feature wise in this release,

Re: Gitlab update, 2FA now mandatory

2022-10-23 Thread Ben Cooksley
On Mon, Oct 24, 2022 at 4:55 AM Christoph Cullmann (cullmann.io) < christ...@cullmann.io> wrote: > On 2022-10-23 08:32, Ben Cooksley wrote: > > Hi all, > > > > This afternoon I updated invent.kde.org [1] to the latest version of > > Gitlab, 15.5. > > Release notes for this can be found at > >

Re: Gitlab update, 2FA now mandatory

2022-10-23 Thread Christian
Personally I'd recommend Aegis (https://f-droid.org/packages/com.beemdevelopment.aegis/) over FreeOTP(+) due to the possibility to disable screencaps, the privacy focussed settings such as tap to reveal and encrypted exports (afaik FreeOTP only does unencrypted) and the possibility to import

Re: Gitlab update, 2FA now mandatory

2022-10-23 Thread Mathias Homann
Am Sonntag, 23. Oktober 2022, 21:18:27 CEST schrieb Bernie Innocenti: > I was going to recommend andOTP for Android, but sadly the author no > longer has time to maintain it: > >https://github.com/andOTP/andOTP > > Looks like FreeOTP+ is actively maintained, so I'll look into migrating > to

Re: Gitlab update, 2FA now mandatory

2022-10-23 Thread Akseli Lahtinen
I highly recommend Aegis authenticator, it's on f-droid as well: https://getaegis.app/ - Akseli On Sunday, 23 October 2022 22.18.27 EEST Bernie Innocenti wrote: > I was going to recommend andOTP for Android, but sadly the author no > longer has time to maintain it: > >

Re: Gitlab update, 2FA now mandatory

2022-10-23 Thread Sune Vuorela
On 2022-10-23, Ben Cooksley wrote: > (such as a Yubikey) or TOTP (using the app of choice on your phone) There seems to be some questions about what possible "app of choice" is available. kde has keysmith f-droid have freeotp+ sailfish has sailotp somewhere In the less privacy oriented

Re: Gitlab update, 2FA now mandatory

2022-10-23 Thread Christoph Cullmann (cullmann.io)
On 2022-10-23 08:32, Ben Cooksley wrote: Hi all, This afternoon I updated invent.kde.org [1] to the latest version of Gitlab, 15.5. Release notes for this can be found at https://about.gitlab.com/releases/2022/10/22/gitlab-15-5-released/ There isn't much notable feature wise in this release,

Gitlab update, 2FA now mandatory

2022-10-23 Thread Ben Cooksley
Hi all, This afternoon I updated invent.kde.org to the latest version of Gitlab, 15.5. Release notes for this can be found at https://about.gitlab.com/releases/2022/10/22/gitlab-15-5-released/ There isn't much notable feature wise in this release, however there have been some bug fixes