https://github.blog/2022-05-04-software-security-starts-with-the-developer-securing-developer-accounts-with-2fa/ * Engineering * Community * Product * Security * Open Source * Enterprise * Education * Company * Changelog Search by Keyword [ ] Search * Product * Security Software security starts with the developer: Securing developer accounts with 2FA GitHub will require all users who contribute code on GitHub.com to enable one or more forms of two-factor authentication (2FA) by the end of 2023. Software security starts with the developer: Securing developer accounts with 2FA Author Mike HanleyMike Hanley May 4, 2022 * * * The software supply chain starts with the developer. Developer accounts are frequent targets for social engineering and account takeover, and protecting developers from these types of attacks is the first and most critical step toward securing the supply chain. GitHub has a long history of protecting developers through efforts including seeking and invalidating known-compromised user passwords, offering robust WebAuthn security key support, and enrolling all npm publishers in enhanced login verification. Today, as part of a platform-wide effort to secure the software ecosystem through improving account security, we're announcing that GitHub will require all users who contribute code on GitHub.com to enable one or more forms of two-factor authentication (2FA) by the end of 2023. GitHub will require all users who contribute code on GitHub.com to enable one or more forms of two-factor authentication (2FA) by the end of 2023. GitHub is committed to making sure that strong account security doesn't come at the expense of a great experience for developers, and our end of 2023 target gives us the opportunity to optimize for this. As standards evolve, we'll continue to actively explore new ways of securely authenticating users, including passwordless authentication. Developers everywhere can expect more options for authentication and account recovery, along with improvements that help prevent and recover from account compromise. Why account security and 2FA matter In November 2021, GitHub committed to new investments in npm account security in the wake of npm package takeovers resulting from the compromise of developer accounts without 2FA enabled. We continue to introduce improvements to npm account security, and are equally committed to securing the accounts of developers using GitHub. Most security breaches are not the product of exotic zero-day attacks, but rather involve lower-cost attacks like social engineering, credential theft or leakage, and other avenues that provide attackers with a broad range of access to victim accounts and the resources they have access to. Compromised accounts can be used to steal private code or push malicious changes to that code. This places not only the individuals and organizations associated with the compromised accounts at risk, but also any users of the affected code. The potential for downstream impact to the broader software ecosystem and supply chain as a result is substantial. [sec-blog-img] The best defense against this is moving beyond basic password-based authentication. We have already taken steps in this direction by deprecating basic authentication for git operations and our API and requiring email based device verification, in addition to a username and password. 2FA is a powerful next line of defense; however, despite demonstrated success, 2FA adoption across the software ecosystem remains low overall. Today, only approximately 16.5% of active GitHub users and 6.44% of npm users use one or more forms of 2FA. npm 2FA updates In February we enrolled all maintainers of the top-100 packages on the npm registry in mandatory 2FA, and in March we enrolled all npm accounts in enhanced login verification. On May 31, we will be enrolling all maintainers of the top-500 packages in mandatory 2FA. Our final cohort will be maintainers of all high-impact packages, those with more than 500 dependents or 1 million weekly downloads, whom we plan to enroll in the third-quarter of this year. We will leverage what we learn from requiring 2FA on npm and apply those lessons to our efforts on GitHub.com. At GitHub, we believe that our unique position as the home for all developers means that we have both an opportunity and a responsibility to raise the bar for security across the software development ecosystem. While we are investing deeply across our platform and the broader industry to improve the overall security of the software supply chain, the value of that investment is fundamentally limited if we do not address the ongoing risk of account compromise. Our response to this challenge continues today with our commitment to drive improved supply chain security through safe practices for individual developers. Get Started Today Individual Users Want to get a head start? We recently launched 2FA for GitHub Mobile on iOS and Android! Click here to learn how to configure GitHub Mobile 2FA today. To configure Mobile 2FA, you'll need to have at least one other form of 2FA enabled. Expand the drop-down below to learn more. Looking for a phishing-resistant WebAuthn security key experience or other options? You can get started here. To support adoption of security keys we've distributed security keys, like YubiKey, to critical open source project maintainers and stocked security keys in the GitHub Shop. SoloKeys or Titan Security Keys are also great options. More documentation on GitHub.com 2FA is available here. To configure 2FA for npm accounts, check this out. Don't forget to save your recovery codes and configure one or more account recovery methods as well! Organizations and Enterprises GitHub.com organization and enterprise owners can also require 2FA for members of their organizations and enterprises. Note that organization and enterprise members and owners who do not use 2FA will be removed from the organization or enterprise when these settings are enabled. Looking forward Over the coming months, we'll share more details and timelines for future 2FA requirements for GitHub.com users. While we strongly believe 2FA for active contributors (for example, those who commit code, open or merge pull requests, use Actions, or publish packages) is the right thing to do, we also want to ensure a smooth and accessible experience, so look out for future improvements and new features designed to help you secure and recover your accounts. Tags: * 2FA, * npm, * Security More on 2FA Top-100 npm package maintainers now require 2FA, and additional security-focused improvements to npm Top-100 npm package maintainers now require 2FA, and additional security-focused improvements to npm Starting today, we are rolling out mandatory 2FA to all maintainers of top-100 npm packages by dependents. Myles Borins Secure your GitHub account with GitHub Mobile 2FA GitHub continues to improve account security and developer experience with a new 2FA mechanism in GitHub Mobile on iOS and Android. Berk Veral Enrolling all npm publishers in enhanced login verification and next steps for two-factor authentication enforcement Today we're introducing enhanced login verification to the npm registry, and we will begin a staged rollout to maintainers beginning Dec 7. Myles Borins More on npm Security alert: Attack campaign involving stolen OAuth user tokens issued to two third-party integrators Security alert: Attack campaign involving stolen OAuth user tokens issued to two third-party integrators On April 12, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm. Read on to learn more about the impact to GitHub, npm, and our users. Mike Hanley Release Radar * March 2022 Edition Each month, we highlight open source projects that have shipped major updates. These include everything from world-changing technology to developer tooling, and weekend projects. Here are our top staff picks... Michelle Mannering Release Radar * February 2022 Edition Our community has shipped lots of open source project updates in the last month. Here's a few of our staff picks. Michelle Mannering Related posts Best practices to keep your projects secure on GitHub Product Best practices to keep your projects secure on GitHub These days software is subject to an ever-changing threat landscape. Check out the many ways you can keep your projects secure on GitHub today. Justin Hutchings GitHub Desktop 3.0 brings better integration for your pull requests Company GitHub Desktop 3.0 brings better integration for your pull requests GitHub Desktop 3.0 brings better integration with your GitHub Pull Requests. You can now receive real time notifications and review the status of your check runs for your pull request. Sergio Padrino Removing the stigma of a CVE Security Removing the stigma of a CVE Do you worry that a CVE will hurt the reputation of your project? In reality, CVEs are a tracking number, and nothing more. Here's how we think of them at GitHub. Madison Oliver Product * Features * Security * Enterprise * Customer Stories * Pricing * Resources Platform * Developer API * Partners * Atom * Electron * GitHub Desktop Support * Docs * Community Forum * Training * Status * Contact Company * About * Blog * Careers * Press * Shop * GitHub on Twitter * GitHub on Facebook * GitHub on YouTube * GitHub on LinkedIn * GitHub's organization on GitHub * (c) 2022 GitHub, Inc. * Terms * Privacy