Mandatory two-factor authentication has been enabled in NPM for the 100 most popular packages

GitHub has announced the implementation of mandatory two-factor authentication for 100 NPM packages that are included as dependencies in the most packages. The maintainers of these packages will now be able to perform authentication-required operations with the repository only after enabling two-factor authentication, which requires login confirmation through one-time passwords (TOTP) generated by applications such as Authy, Google Authenticator, and FreeOTP. In the near future, in addition to TOTP, they plan to add support for hardware keys and biometric scanners that support the WebAuth protocol.

As of March 1, all NPM accounts that do not have two-factor authentication enabled will be transitioned to use enhanced account verification, which requires entering a one-time code sent to the email when attempting to log in to npmjs.com or perform authentication-required operations in the npm utility. When two-factor authentication is enabled, email verification will not be applied. On February 16 and 13, there will be a temporary trial run of enhanced verification for all accounts for one day.

It is worth noting that according to a study conducted in 2020, only 9.27% of package maintainers used two-factor authentication to secure access, while in 13.37% of cases, developers tried to reuse compromised passwords found in known password leaks when registering new accounts. During a password strength check, access was gained to 12% of accounts on NPM (13% of packages) due to the use of predictable and trivial passwords like '123456'. Among the problematic accounts were 4 users from the Top 20 most popular packages, 13 accounts whose packages were downloaded more than 50 million times a month, 40 with over 10 million downloads a month, and 282 with more than 1 million downloads a month. Considering the loading of modules through dependency chains, the compromise of insecure accounts could potentially affect up to 52% of all modules in NPM.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster