GitHub has announced that two-factor authentication (2FA) will be mandatory for all code contributors through GitHub.com by the end of 2023, building on a series of recent security developments on the Microsoft.

While sophisticated zero-day attacks are a real threat to companies across the industry spectrum, the fact that most security breaches are due to simple human error or manipulation, whether it’s social engineering or credential theft, shows that the problem starts with account security. And that’s why 2FA can be such a useful mechanism for securing critical business systems, as it means that if a hacker obtains private login credentials, it’s much harder to exploit them.
GitHub's 2FA push
In November, GitHub responded to recent NPM package takeovers resulting from compromised accounts, including one with more than 7 million weekly downloads, by making 2FA mandatory. This process began in February, when GitHub enforced 2FA for all maintainers of the top 100 most popular NPM , and the following month, all NPM accounts were automatically enrolled in GitHub’s improved login verification program. Later this month, GitHub said it would enroll all maintainers of the top 500 NPM packages in 2FA, with those with more than 500 dependencies or 1 million weekly downloads added to the mix in Q3 2022.
And the lessons that GitHub gathers from this gradual rollout for NPM packages will be applied to its broader push to make 2FA mandatory on GitHub.com.
Despite first introducing an optional 2FA mechanism in 2013, it is currently used by just 16.5% of GitHub's active users.
Before today's announcement, GitHub laid the groundwork for implementing 2FA, having added support for physical security keys a while back and then made the GitHub mobile app another way to authenticate logins via 2FA.

The next obvious step is to make 2FA mandatory for all GitHub.com users, which GitHub will do by the end of 2023. In the intervening months, GitHub plans to introduce “more options for authentication and account recovery,” according to GitHub’s chief security officer, Mike Hanley.
It is worth noting that GitHub's mandatory 2FA implementation will also apply to all individual contributors to public open source projects.
Information source: venturebeat.com
