Image Credits:Michael Short/Bloomberg via Getty Images / Getty Images

GitHub will require all users who contribute code to enable two-factor authentication by the end of 2023

Here is some news that is both straightforward and still a long time out but nevertheless important: by the end of 2023, GitHub will require all users who contribute code on the platform to enable one or more forms of two-factor authentication (2FA).

And that’s pretty much it for the news. Today, the Microsoft-owned company says, only 16.5% of active GitHub users and 6.44% of npm users use 2FA. That is not a lot, and frankly fewer than I would have expected.

“Compromised accounts can be used to steal private code or push malicious changes to that code. This places not only the individuals and organizations associated with the compromised accounts at risk, but also any users of the affected code. The potential for downstream impact to the broader software ecosystem and supply chain as a result is substantial,” Mike Hanley, GitHub’s chief security officer, writes in today’s announcement.

He also notes that the company is trying to make sure that the extra layer of security doesn’t come at the expense of the user experience. Hence the long time between today’s announcement and when it will enforce this. “Our end of 2023 target gives us the opportunity to optimize for this,” Hanley explains. Switching to 2FA involves some changes to the user experience both on the command line and the GitHub web interface.

It’s worth noting that earlier this year, GitHub also enrolled the maintainers of the top-100 npm packages in mandatory 2FA to prevent software supply chain attacks. It plans to expand to the maintainers of top-500 packages this month and then later expand that to all packages with more than 500 dependents or 1 million weekly downloads.

How two-factor authentication can protect you from account hacks

Techcrunch event

Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

Netflix, Box, a16z, ElevenLabs, Wayve, Hugging Face, Elad Gil, Vinod Khosla — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss the 20th anniversary of TechCrunch, and a chance to learn from the top voices in tech. Grab your ticket before doors open to save up to $444.

Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

Netflix, Box, a16z, ElevenLabs, Wayve, Hugging Face, Elad Gil, Vinod Khosla — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss a chance to learn from the top voices in tech. Grab your ticket before doors open to save up to $444.

San Francisco | October 27-29, 2025

Topics

, , , , , , , , , , ,
Loading the next article
Error loading the next article