Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Journalist Application
    • Contact Us
Reading: GitHub to Enforce Two-Factor Authentication By The End Of 2023
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > IT Security > GitHub to Enforce Two-Factor Authentication By The End Of 2023
IT Security

GitHub to Enforce Two-Factor Authentication By The End Of 2023

Editorial Desk
Last updated: June 1, 2022 9:34 pm
Editorial Desk
Share
SHARE

Users who upload code to the site will need to enable one or more forms of 2FA by the end of 2023 to continue using the platform.

GitHub will require all users who contribute code to the platform to enable one or more forms of two-factor authentication (2FA).

The Microsoft-owned company says, only 16.5% of active GitHub users and 6.44% of npm users use 2FA and fewer that many would have expected.

The platform said the move was “part of a platform-wide effort to secure the software ecosystem through improving account security.”

GitHub has already taken a few steps beyond basic password-based authentication, including withdrawing basic authentication for git and its API operations, and requiring device verification with email in addition to a username and password.

The platform said: “2FA is a powerful next line of defense.”Compromised accounts can be used to steal private code or push malicious changes to that code

Mike Hanley, GitHub’s chief security officer wrote in an announcement compromised accounts can be used to steal private code or push malicious changes to that code.

“This places not only the individuals and organizations associated with the compromised accounts at risk, but also any users of the affected code. The potential for downstream impact to the broader software ecosystem and supply chain as a result is substantial,” said Hanley

Andrew Hay, COO at LARES Consulting, branded GitHub’s decision “a great move towards increasing the complexity of account takeovers.”

However, Hay expressed concern about what could happen if some GitHub contributors do not implement 2FA. 

“One design decision, that may cause some issues, is that GitHub stated that it will remove enterprise members and owners who do not use 2FA from the organisation or enterprise once these settings are enabled,” said Hay. 

“We don’t expect this to cause many issues, but it may lead to some calls to the support desk if a user finds that they can no longer access the code repositories they once had access to.” he said.

GitHub has also enrolled maintainers of the first 100 npm packages in mandatory 2FA to prevent attacks on the software supply chain. It plans to expand to maintainers of the first 500 packages this month and then expand it to all packages with more than 500 employees or 1 million downloads per week.

Related :See Githubs new enterprise 3.5 server advanced security features

By Editorial Desk
The TBN team is a well establish group of technology industry professionals with backgrounds in IT Systems, Business Communications and Journalism.
Previous Article Tech Giants Team Up Microsoft, Apple and Google Team Up on Passwordless Standard
Next Article Facebook Ban Facebook accused of deliberately disrupting emergency services in Australia
Leave a comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

GITHUB 2FA

Tech Articles

VPN Service Providers Cyber Attacks

Should VPN Service Providers Be Held Accountable For Cyber Attacks?

Should VPN service providers be held accountable for cyber attacks…

November 3, 2024
Content creation platforms leveraged for phishing attacks

Phishing Attacks Exploit Content Creation Platforms

Content creation platforms are being leveraged for phishing attacks. Its…

September 17, 2024
Healthcare AI

AI Is Transforming Healthcare By Improving Workflows And Resource Management

Artificial Intelligence (AI) is transforming every industry. In healthcare, there…

October 12, 2024

Recent News

IT Security

Group-IB Opens Latest Digital Crime Resistance Center in Thailand

6 Min Read
Avanan shares Microsoft’s Dynamics 365 exploit
IT Security

Microsoft’s Dynamics 365 the latest program used by hackers to exploit customer data

4 Min Read
IT Security

Australian Businesses Face Increasing Annual Losses Linked To API Insecurity

6 Min Read
Barracuda Zero Trust
IT Security

Barracuda CloudGen Access adds web security in Zero Trust Access solution

3 Min Read
Tech News

Tech Business News

Stay up to date with the latest technology & business news trends from Australia and the around the world.

Technology News reports and whitepaper publishing services are available along with media and advertising options

Our Australian technology news includes People, Business, Science, World News, Local News, Guest publishers, IT News & Tech News Australia | Tech News was established in 2019

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

December, 10, 2024

Contact

Contact Information.
Melbourne, Australia

Werribee 3030

Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.


Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2024

Welcome Back!

Sign in to your account