
Software development tool GitHub requires more accounts to enable two-factor authentication (2FA) starting March 13th. This obligation extends to all developers contributing code on GitHub.com by the end of 2023.
GitHub announced plans to roll out the 2FA requirement in a blog post last May. At the time, the company’s chief security officer said the move was made because GitHub (used by millions of software developers worldwide in countless industries) is a vital part of the software supply chain. This supply chain has come under multiple attacks over the last few years and months, making 2FA a strong defense against social engineering and other particularly common attack methods.
At the time that blog post was written, GitHub revealed that only about 16.5% of active GitHub users are using 2FA.
In December, GitHub announced details of plans that will roll out to more people in the next few days. The company identifies specific subsets of users who need to jump on the bandwagon first, such as members of companies and organizations, and users who have contributed code to critical repositories.
These users will receive periodic reminders in-product and via email 45 days before the requirement goes into effect. Starting with your first login after 2FA expires, you will receive daily reminders to enable 2FA. If you haven’t accessed it after 7 days, you won’t be able to access most of GitHub’s features until you do. 28 days after that, GitHub will initiate a “2FA checkup” to ensure it’s working properly and that users can still access their accounts.
According to GitHub, more and more accounts will participate in this process during 2023 and will include all contributing developer accounts by the end of the year.
This is not an implementation of 2FA for GitHub accounts. A user has long been able to opt-in to his 2FA on his personal account, and corporate organizations have been able to require his 2FA for all members for some time.
Over the past few months, GitHub has also gradually rolled out requirements for certain types of users. For example, in December, he announced that “maintainers of packages with more than 1 million weekly downloads or more than 500 dependencies” should have 2FA enabled. Prior to that, he required 2FA for contributors to JavaScript libraries distributed via NPM.
If you’re a GitHub user, you should monitor your email or in-app notification that your ticket has been validated.