https://www.bleepingcomputer.com/news/security/github-makes-2fa-mandatory-next-week-for-active-developers/ BleepingComputer.com logo * * * * [ ] [Login] [Sign up] * * * * [ ] [Login] [Sign up] * News + Featured + Latest + Microsoft OneNote to get enhanced security after recent malware abuse Microsoft OneNote to get enhanced security after recent malware abuse + Blackbaud to pay $3M for misleading ransomware attack disclosure Blackbaud to pay $3M for misleading ransomware attack disclosure + Security researchers targeted with new malware via job offers on LinkedIn Security researchers targeted with new malware via job offers on LinkedIn + Xenomorph Android malware now steals data from 400 banks Xenomorph Android malware now steals data from 400 banks + Clop ransomware gang begins extorting GoAnywhere zero-day victims Clop ransomware gang begins extorting GoAnywhere zero-day victims + CISA warns of actively exploited Plex bug after LastPass breach CISA warns of actively exploited Plex bug after LastPass breach + Brazil seizing Flipper Zero shipments to prevent use in crime Brazil seizing Flipper Zero shipments to prevent use in crime + Overhaul your ethical hacking skills with this training bundle deal Overhaul your ethical hacking skills with this training bundle deal * Downloads + Latest + Most Downloaded + Qualys BrowserCheck Qualys BrowserCheck + STOPDecrypter STOPDecrypter + AuroraDecrypter AuroraDecrypter + FilesLockerDecrypter FilesLockerDecrypter + AdwCleaner AdwCleaner + ComboFix ComboFix + RKill RKill + Junkware Removal Tool Junkware Removal Tool * Virus Removal Guides + Latest + Most Viewed + Ransomware + Remove the Theonlinesearch.com Search Redirect Remove the Theonlinesearch.com Search Redirect + Remove the Smartwebfinder.com Search Redirect Remove the Smartwebfinder.com Search Redirect + How to remove the PBlock+ adware browser extension How to remove the PBlock+ adware browser extension + Remove the Toksearches.xyz Search Redirect Remove the Toksearches.xyz Search Redirect + Remove Security Tool and SecurityTool (Uninstall Guide) Remove Security Tool and SecurityTool (Uninstall Guide) + How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo + How to remove Antivirus 2009 (Uninstall Instructions) How to remove Antivirus 2009 (Uninstall Instructions) + How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller + Locky Ransomware Information, Help Guide, and FAQ Locky Ransomware Information, Help Guide, and FAQ + CryptoLocker Ransomware Information Guide and FAQ CryptoLocker Ransomware Information Guide and FAQ + CryptorBit and HowDecrypt Information Guide and FAQ CryptorBit and HowDecrypt Information Guide and FAQ + CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ * Tutorials + Latest + Popular + How to open a Windows 11 Command Prompt as Administrator How to open a Windows 11 Command Prompt as Administrator + How to make the Start menu full screen in Windows 10 How to make the Start menu full screen in Windows 10 + How to install the Microsoft Visual C++ 2015 Runtime How to install the Microsoft Visual C++ 2015 Runtime + How to open an elevated PowerShell Admin prompt in Windows 10 How to open an elevated PowerShell Admin prompt in Windows 10 + How to start Windows in Safe Mode How to start Windows in Safe Mode + How to remove a Trojan, Virus, Worm, or other Malware How to remove a Trojan, Virus, Worm, or other Malware + How to show hidden files in Windows 7 How to show hidden files in Windows 7 + How to see hidden files in Windows How to see hidden files in Windows * Deals + Categories + eLearning eLearning + IT Certification Courses IT Certification Courses + Gear & Gadgets Gear + Gadgets + Security Security * Forums * More + Startup Database + Uninstall Database + Glossary + Chat on Discord + Send us a Tip! + Welcome Guide * Home * News * Security * GitHub makes 2FA mandatory next week for active developers * * GitHub makes 2FA mandatory next week for active developers By Sergiu Gatlan * March 9, 2023 * 12:00 PM * 0 GitHub GitHub will start requiring active developers to enable two-factor authentication (2FA) on their accounts beginning next week, on March 13. Once expanded to the company's entire user base, the 2FA enrollment requirement will help secure the accounts of more than 100 million users. The gradual rollout will start next week with GitHub reaching out to smaller groups of administrators and developers via email and will speed up as the end of the year approaches to ensure that onboarding is seamless and users have time to sort out any issues. "GitHub has designed a rollout process intended to both minimize unexpected interruptions and productivity loss for users and prevent account lockouts," said Staff Product Manager Hirsch Singhal and Product Marketing Director Laura Paine. "Groups of users will be asked to enable 2FA over time, each group selected based on the actions they've taken or the code they've contributed to." If your account is selected for enrollment, you will receive an email and see a banner on GitHub.com requesting you to enroll in the two-factor authentication (2FA) program. Then, you'll have 45 days to configure 2FA on your account, during which you can keep using your GitHub account as usual, except for occasional reminders. GitHub will keep you updated on your enablement deadline, and once it has passed, you will be prompted to enable 2FA the first time you access GitHub.com and blocked from accessing some features until 2FA is toggled on. GitHub 2FA rolloutGitHub 2FA rollout (GitHub) This follows two previous announcements from May and December that all developers contributing code on the platform will be required to enable 2FA by the end of 2023. GitHub provides detailed instructions on configuring 2FA for your account and recovering accounts when losing 2FA credentials. Developers can use one or more 2FA options, including physical security keys, virtual security keys built into mobile devices like smartphones and laptops, Time-based One-Time Password (TOTP) authenticator apps, or the GitHub Mobile app (after configuring TOTP or SMS 2FA). Although text message-based 2FA is also an option (in some countries ), GitHub is urging users to switch to security keys or TOTP apps because threat actors can bypass SMS 2FA or steal SMS 2FA auth tokens to hijack the developers' accounts. Securing the software supply chain Enabling 2FA on GitHub accounts increases resilience against account takeover by blocking attempts to use reused passwords or stolen credentials in hijacking attacks. This is the company's latest move towards securing the software supply chain by moving away from basic password-based authentication. Previously, the code hosting platform implemented email-based device verification and phased out account passwords for Git operation authentication. Additionally, GitHub disabled password authentication via the REST API back in November 2020 and introduced support for FIDO2 security keys to secure SSH Git operations in May 2021. Over the years, GitHub has enhanced its account security measures by incorporating two-factor authentication, sign-in alerts, blocking the use of compromised passwords, and providing support for WebAuthn. Related Articles: GitHub to require all users to enable 2FA by the end of 2023 Apple iOS 16.3 arrives with support for hardware security keys GitHub's secret scanning alerts now available for all public repos GitHub Copilot update stops AI model from revealing secrets Hackers breach Reddit to steal source code and internal data * 2FA * GitHub * Two-factor Authentication * * * * * Sergiu Gatlan Sergiu Gatlan has covered cybersecurity, technology, and other news beats for more than a decade. Email or Twitter DMs for tips. * Previous Article * Next Article Post a Comment Community Rules You need to login in order to post a comment [Login] Not a member yet? Register Now You may also like: [INS::INS] Popular Stories * AT&T ATT AT&T alerts 9 million customers of data breach after vendor hack * Flipper Zero Brazil seizing Flipper Zero shipments to prevent use in crime Follow us: * * * * * Main Sections * News * Downloads * Virus Removal Guides * Tutorials * Startup Database * Uninstall Database * Glossary Community * Forums * Forum Rules * Chat Useful Resources * Welcome Guide * Sitemap Company * About BleepingComputer * Contact Us * Send us a Tip! * Advertising * Write for BleepingComputer * Social & Feeds * Changelog Terms of Use - Privacy Policy - Ethics Statement Copyright @ 2003 - 2023 Bleeping Computer^(r) LLC - All Rights Reserved Login Username [ ] Password [ ] [*] Remember Me [ ] Sign in anonymously [Login] Sign in with Twitter button Sign in with Twitter --------------------------------------------------------------------- Not a member yet? Register Now Reporter Help us understand the problem. What is going on with this comment? * ( )Spam * ( )Abusive or Harmful * ( )Inappropriate content * ( )Strong language * ( )Other [ ] * [ ] Read our posting guidelinese to learn what content is prohibited. Submitting... SUBMIT