GitHub will begin its official rollout of two-factor authentication for developers who contribute code on the platform, starting March 13. GitHub added that it will support SMS text messages as a second factor, while testing FIDO Alliance passkeys internally to improve the security posture. “It is true that SMS 2FA can be easily phished by hackers as it relies on knowledge-based credentials. But GitHub recognizes these risks and strongly recommends using security keys and TOTPS wherever possible for greater security – [and] will continue to offer SMS for 2FA – which is better than removing the option entirely,” said Andrew Shikiar, executive director of the FIDO Alliance.


More

The Register: Microsoft, Google do a victory lap around passkeys

Passkeys are based on a FIDO alliance standard that’s supported by Apple, Microsoft and Google. Think of…

Read More →

Silicon Republic: Microsoft and Google are pushing harder for passkeys

Passkeys have been growing rapidly in popularity. In the UK, for instance, more than half…

Read More →

TechCrunch: Google expands passkey support to its Advanced Protection Program ahead of the US presidential election

Google is introducing passkey support to its Advanced Protection Program (APP), designed for individuals facing…

Read More →


123242 Next