Web: https://malware.news/t/github-enforces-2fa-it-s-about-time-given-the-state-of-supply-chain-security/67912

March 15, 2023, 4:40 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news


GitHub is a weak link in the software supply chain. Finally, Microsoft is doing something about it — by forcing users into two-factor authentication (2FA).


Unfortunately, SMS is still an option, but at least you don’t have to use it. WebAuthn keys and TOTP are where you should be looking, plus there’s a dedicated GitHub app. Passkeys support isn’t there yet, but it’s “coming soon.”


No need to wait until you’re forced. In this week’s Secure Software Blogwatch, we …

2fa github security state supply supply chain supply chain security

OCIO-0020 Expert on Enterprise Cyber-related Exercises Support (NS) - MON 3 Apr

@ EMW, Inc. | Brussels, Brussels, Belgium

Senior Consultant (m/w/d) IT Security Management - remote/ onsite

@ MVI Group GmbH | München, Germany

Cyber Security Analyst II - Remote Contract (3913-W)

@ Stout Systems | New York City, United States - Remote

Sr Cyber Security Advisor - S Atlantic Enterprise

@ Optiv | Atlanta, GA

Director, Information Security Operations (Ottawa, ON)

@ SSENSE | Ottawa, ON, Canada

Senior Security Engineer - Threat Detection

@ Samsara | San Francisco, CA

Information Security Engineer

@ NMI | Bristol, England, United Kingdom - Remote

Co-op Student - IT Compliance

@ BusPatrol | Remote

Incident Response Manager

@ matchpoint solutions | Houston, Tx, Houston, Tx, United States

Consultant(e) réseau / sécurité H/F - Innovative Tech

@ Devoteam | Nantes, France

DevSecOps Security Consultant 2023 ECL

@ Bosch Group | Bengaluru, India

Staff Back-end Engineer [Security Architecture & Engineering]

@ Coupang | Seoul, South Korea