Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Should/will 2FA (2 factor authentication) be required for making GitHub contributions #19

Open
nschonni opened this issue Sep 28, 2018 · 8 comments
Labels
guidance security Security related issue

Comments

@nschonni
Copy link
Member

nschonni commented Sep 28, 2018

https://help.github.com/articles/about-two-factor-authentication/

@obrien-j
Copy link

Where possible, 2FA should be mandatory for all systems GC uses, along with enforced (by system) code reviews.

@CalvinRodo
Copy link

I'd like to also see promotion of hardware 2FA whenever possible such as https://www.yubico.com/ or similar tools.

@gcharest
Copy link
Member

gcharest commented Nov 8, 2018

I would personnally be in favour.

@gcharest
Copy link
Member

gcharest commented Nov 8, 2018

Looping @ptd-tbs in for this.

@ptd-tbs
Copy link

ptd-tbs commented Nov 9, 2018

I am also in favour of implementing multi-factor authentication. We made it mandatory for privileged access to cloud-based services in the Direction on the Secure Use of Commercial Cloud, Section 6.2.3.

@LaurentGoderre
Copy link

I think requiring 2FA for making contribution is too much of an overreach but it should be mandatory for people maintaining GC repositories

@gcharest
Copy link
Member

gcharest commented Nov 13, 2018 via email

@ptd-tbs
Copy link

ptd-tbs commented Nov 14, 2018

In general, I think we should be developing a checklist for securing GitHub.This includes enabling 2FA in general for those with accounts. If this is a key component of the CI/CD pipeline, it should be assessed and approved once, then reused by other projects. Checklist is on our to do list.

@gcharest gcharest added security Security related issue guidance labels Nov 17, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
guidance security Security related issue
Projects
None yet
Development

No branches or pull requests

6 participants