* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Monday, July 14, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

    Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

    Review: At the Huntington, the New Hollywood String Quartet recalls legendary studio musicians – Los Angeles Times

    Review: At the Huntington, the New Hollywood String Quartet recalls legendary studio musicians – Los Angeles Times

    Kehoe repeals paid sick leave, allows several counties in the Ozarks to have entertainment districts in bill signings – KY3

    Kehoe repeals paid sick leave, allows several counties in the Ozarks to have entertainment districts in bill signings – KY3

    Emily Deschanel was scolded during “Bones” season 1 for being ‘late and unprepared’: ‘I was just beside myself’ – Yahoo

    Emily Deschanel was scolded during “Bones” season 1 for being ‘late and unprepared’: ‘I was just beside myself’ – Yahoo

    How you can see new movies early – Yahoo

    Unlock the Secret to Watching New Movies Before Everyone Else!

    Immersive sports and entertainment venue Cosm set to build its 5th location in Cleveland – WKYC

    Cosm Reveals Exciting Vision for Its 5th Immersive Sports and Entertainment Venue in Cleveland

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Sentrycs’ Cyber Over RF technology integrated into Rafael’s combat-proven Drone Dome system – Defence Industry Europe

    Sentrycs’ Cyber Over RF Technology Boosts Rafael’s Battle-Tested Drone Dome System

    Nordic Air Defence raises $3 million to expand operations and advance drone defence technology – Defence Industry Europe

    Nordic Air Defence Lands $3 Million to Transform Drone Defense and Supercharge Operations

    China’s energy dominance in three charts – MIT Technology Review

    How China Is Powering Its Energy Dominance: A Visual Breakdown

    Meta Acquires AI Startup PlayAI to Enhance Voice Technology Capa – GuruFocus

    Meta Acquires AI Startup PlayAI to Revolutionize Voice Technology Capabilities

    Stallion Uranium Provides Update on Technology Data Acquisition Agreement – GlobeNewswire

    Stallion Uranium Announces Exciting Progress in Technology Data Acquisition Agreement

    2025 WE Local Prague Recap: Inspiring Women in Engineering and Technology – Society of Women Engineers

    2025 WE Local Prague Recap: Inspiring Women in Engineering and Technology – Society of Women Engineers

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

    Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

    Review: At the Huntington, the New Hollywood String Quartet recalls legendary studio musicians – Los Angeles Times

    Review: At the Huntington, the New Hollywood String Quartet recalls legendary studio musicians – Los Angeles Times

    Kehoe repeals paid sick leave, allows several counties in the Ozarks to have entertainment districts in bill signings – KY3

    Kehoe repeals paid sick leave, allows several counties in the Ozarks to have entertainment districts in bill signings – KY3

    Emily Deschanel was scolded during “Bones” season 1 for being ‘late and unprepared’: ‘I was just beside myself’ – Yahoo

    Emily Deschanel was scolded during “Bones” season 1 for being ‘late and unprepared’: ‘I was just beside myself’ – Yahoo

    How you can see new movies early – Yahoo

    Unlock the Secret to Watching New Movies Before Everyone Else!

    Immersive sports and entertainment venue Cosm set to build its 5th location in Cleveland – WKYC

    Cosm Reveals Exciting Vision for Its 5th Immersive Sports and Entertainment Venue in Cleveland

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Sentrycs’ Cyber Over RF technology integrated into Rafael’s combat-proven Drone Dome system – Defence Industry Europe

    Sentrycs’ Cyber Over RF Technology Boosts Rafael’s Battle-Tested Drone Dome System

    Nordic Air Defence raises $3 million to expand operations and advance drone defence technology – Defence Industry Europe

    Nordic Air Defence Lands $3 Million to Transform Drone Defense and Supercharge Operations

    China’s energy dominance in three charts – MIT Technology Review

    How China Is Powering Its Energy Dominance: A Visual Breakdown

    Meta Acquires AI Startup PlayAI to Enhance Voice Technology Capa – GuruFocus

    Meta Acquires AI Startup PlayAI to Revolutionize Voice Technology Capabilities

    Stallion Uranium Provides Update on Technology Data Acquisition Agreement – GlobeNewswire

    Stallion Uranium Announces Exciting Progress in Technology Data Acquisition Agreement

    2025 WE Local Prague Recap: Inspiring Women in Engineering and Technology – Society of Women Engineers

    2025 WE Local Prague Recap: Inspiring Women in Engineering and Technology – Society of Women Engineers

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Mandatory MFA pays off for GitHub and OSS community

April 25, 2024
in Technology
Mandatory MFA pays off for GitHub and OSS community
Share on FacebookShare on Twitter

Mandating multifactor authentication for select developers has been a huge success for GitHub, the platform reports, and now it wants to go further


Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 24 Apr 2024 20:18

Introducing a multifactor authentication (MFA) mandate for users of its platform has paid off for GitHub, which has reported a massive uplift in adoption in the past 12 months, as it continues its drive to improve cyber security standards across the open source software (OSS) community.

Recognising the security impact of software supply chain issues on thousands of organisations worldwide that were compromised through issues arising through insecure OSS code – the Log4Shell incident being arguably the most infamous – GitHub embarked on a drive to raise the bar for supply chain security by addressing developers in May 2022.

It introduced mandatory MFA for selected users in March 2023 as part of that, focusing at first on those considered to have the most critical impact on the software supply chain.

In the past 12 months, the platform said it has seen an opt-in rate of 95% across code contributors who received the MFA requirement, with enrolments still trickling in today. More widely, it added, it has seen a 54% increase in MFA adoption among all active contributors to GitHub-hosted projects.

“Though technology has advanced significantly to combat the proliferation of sophisticated security threats, the reality is that preventing the next cyber attack depends on getting the security basics right, and efforts to secure the software ecosystem must protect the developers who design, build, and maintain the software we all depend on,” wrote Mike Hanley, chief security officer and senior vice president of engineering at GitHub.

“As the home to the world’s largest developer community, GitHub is in a unique position to help improve the security of the software supply chain…strong MFA remains one of the best defences against account takeover and subsequent supply chain compromise.”

In addition to driving developers towards better basic cyber hygiene, GitHub said it has also seen users adopting more secure means of MFA – including passkeys, the introduction of which was a key focus of the initiative; it has registered 1.4 million passkeys on GitHub.com since opening a public beta in July 2023 and the technology has quickly overtaken other forms of Webauthn-backed MFA in day-to-day usage on the platform.

In the interests of flexibility it does continue to offer less secure forms of MFA, such as SMS codes, for the time being, although Hanley said GitHub had tried to make its MFA onboarding workflows nudge people away from SMS as a choice.

GitHub also reported a net reduction in MFA-related support ticket volumes, which it credits to heavy upfront user research and design, as well as some backend support process improvements it has made.

Additionally, said Hanley, other OSS leaders are also getting involved. “Organisations like RubyGems, PyPI, and AWS joined us in raising the bar for the entire software supply chain, proving that large increases in MFA adoption aren’t an insurmountable challenge,” he wrote.

Call to action

Looking ahead, Hanley said that the scope of the project has up to now prioritised specific user groups based on their privileges and actions, but stressed that GitHub is keen to explore how it can require more users to enrol in the next 12 months, and encouraging developers to move up the food chain to more secure factors such as passkeys, while maintaining the user experience.

It is also investigating implementing other account security features such as session and token binding that could enable users to manage the risk of account compromise more effectively regardless of whether or not they have enrolled in MFA. Hanley said there was still much work to be done to support users who may not be able to access a smartphone or who do not have control over the software on the computer they are using to adopt MFA.

“As a global platform, we believe that everyone should have access to tools that make software development easier and more secure, and our efforts to enforce strong authentication for as many developers as possible is ongoing,” said Hanley.

“We’ll continue to find solutions to protect developers, the projects they’re working on, and the communities they participate in, working hard to take a balanced approach that greatly improves the security of the entire software supply chain without restricting those with different setups or environments around the world,” he said.

Marking the one-year anniversary of the start of the MFA mandate, GitHub said it was clear that it was in fact possible to raise the bar for security without negatively affecting user experience, and is encouraging its peers and the wider industry to strongly consider making MFA a compulsory requirement on their platforms.

Read more on Application security and coding requirements


How passwordless helps guard against AI-enhanced attacks


The Security Interviews: Talking identity with Microsoft’s Joy Chik

AlexScroxton

By: Alex Scroxton


5 MFA implementation tips for organizations

KyleJohnson

By: Kyle Johnson


Geek gift guide 2023: Security first, at home and on the go

BethPariseau

By: Beth Pariseau

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366582113/Mandatory-MFA-pays-off-for-GitHub-and-OSS-community

Tags: GitHubmandatorytechnology
Previous Post

Canada’s Felix Auger-Aliassime wins first-round match at Madrid Open

Next Post

Meta chief lays out long-term AI plan

Spatio-Temporal Geographic Networks for Value Co-Creation and Technology Transfer in China with Patent Data – Nature

Unlocking Innovation: How Spatio-Temporal Geographic Networks Drive Value Co-Creation and Technology Transfer in China Using Patent Data

July 14, 2025
2025 MLB Draft tracker, results: Live updates, complete list of every pick, first-round analysis – CBS Sports

2025 MLB Draft tracker, results: Live updates, complete list of every pick, first-round analysis – CBS Sports

July 14, 2025
Canids as pollinators? Nectar foraging by Ethiopian wolves may contribute to the pollination of Kniphofia foliosa – ESA Journals

Could Ethiopian Wolves Be Unexpected Pollinators of Kniphofia foliosa?

July 14, 2025
Guest Opinion: Science is stronger with robust federal funding – Palo Alto Online

Why Strong Federal Funding is Essential for Advancing Science

July 14, 2025
Weight loss may ‘rejuvenate’ fat tissues, clearing away aged cells – Live Science

Weight Loss Could ‘Rejuvenate’ Fat Tissue by Clearing Out Old Cells

July 14, 2025
If your goal is to glow up, say goodbye to these 10 daily decisions – VegOut

10 Daily Habits to Ditch Now for a Stunning Glow-Up

July 14, 2025
‘We’ve never seen a team do this to PSG’ – how Chelsea won Club World Cup – BBC

Unbelievable Comeback: How Chelsea Shocked PSG to Clinch the Club World Cup!

July 14, 2025
India will become $10 trillion economy over next decade, GCCs to contribute $0.5 trillion – The Economic Times

India Poised to Become a $10 Trillion Economy Within a Decade, Powered by GCCs Driving $0.5 Trillion Growth

July 14, 2025
Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

Entertainment Business Master’s Grad Launched Nonprofit to Nurture Emerging Artists – Full Sail University

July 14, 2025
11 lessons for health tech startups from one of UpToDate’s creators – STAT

11 Essential Lessons for Health Tech Startups from a Leading Industry Innovator

July 14, 2025

Categories

Archives

July 2025
MTWTFSS
 123456
78910111213
14151617181920
21222324252627
28293031 
« Jun    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (721)
  • Economy (743)
  • Entertainment (21,631)
  • General (15,893)
  • Health (9,781)
  • Lifestyle (751)
  • News (22,149)
  • People (745)
  • Politics (754)
  • Science (15,962)
  • Sports (21,242)
  • Technology (15,728)
  • World (727)

Recent News

Spatio-Temporal Geographic Networks for Value Co-Creation and Technology Transfer in China with Patent Data – Nature

Unlocking Innovation: How Spatio-Temporal Geographic Networks Drive Value Co-Creation and Technology Transfer in China Using Patent Data

July 14, 2025
2025 MLB Draft tracker, results: Live updates, complete list of every pick, first-round analysis – CBS Sports

2025 MLB Draft tracker, results: Live updates, complete list of every pick, first-round analysis – CBS Sports

July 14, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version