The Fedora project introduces mandatory two-factor authentication for privileged maintainers.

The FESCo (Fedora Engineering Steering Committee), responsible for the technical aspects of Fedora Linux development, has decided to implement mandatory two-factor authentication for all members of the provenpackager group who have commit rights in the repositories involved in the maintenance and development of packages. Unlike members who have access to the development of specific packages, provenpackager group members can make changes to any packages without being their maintainers or owners. The stance on two-factor authentication, which had previously been advisory, was reconsidered after an incident involving the hijacking of one developer's account and actions taken in their name.

Registered members of the provenpackager group have three months to enable two-factor authentication. If this requirement is not met, access rights will be restricted on September 25. For new registrations, the requirement for enabling two-factor authentication is effective immediately. For developers and maintainers not in the provenpackager group, enabling two-factor authentication is currently not mandatory, but strongly recommended.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster