GitHub has begun implementing mandatory two-factor authentication.

GitHub announced the phased rollout of mandatory two-factor authentication for all users who publish code. Starting March 13, mandatory two-factor authentication will apply to specific groups of users, gradually expanding to cover more categories. Initially, two-factor authentication will be mandatory for developers who publish packages, OAuth applications, and GitHub actions that create releases, as well as for those involved in the development of projects critical to the npm, OpenSSF, PyPI, and RubyGems ecosystems, including those working on four million of the most popular repositories.

By the end of 2023, GitHub will prohibit the ability to submit changes without using two-factor authentication for all users. As the transition to two-factor authentication approaches, users will receive email notifications and see warnings in the interface. After the first warning is issued, developers will have 45 days to set up two-factor authentication.

For two-factor authentication, you can use a mobile app, SMS confirmation, or a hardware key. It is recommended to use applications that generate time-based one-time passwords (TOTP) as the preferred option for two-factor authentication, such as Authy, Google Authenticator, and FreeOTP.

Implementing two-factor authentication will enhance the security of the development process and protect repositories from malicious changes resulting from credential leaks, the use of the same password on compromised sites, local system breaches, or social engineering attacks. According to GitHub, gaining access to repositories through account takeover is one of the most dangerous threats, as a successful attack can lead to the injection of malicious changes into popular products and libraries used as dependencies.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster