Security News > 2021 > August > GitHub deprecates account passwords for authenticating Git operations

GitHub deprecates account passwords for authenticating Git operations
2021-08-12 22:10

GitHub has announced today that account passwords will no longer be accepted for authenticating Git operations starting tomorrow.

"Starting on August 13, 2021, at 09:00 PST, we will no longer accept account passwords when authenticating Git operations on GitHub.com," the company said.

For developers, if you are using a password to authenticate Git operations with GitHub.com today, you must begin using a personal access token over HTTPS or SSH key by August 13, 2021, to avoid disruption.

If you want to ensure that you're no longer using password-based authentication, you can enable two-factor authentication, which requires OAuth or personal access tokens for all authenticated operations via Git and third-party integrations.

The enforced token-based authentication for authenticating Git operations increases GitHub accounts' resilience against takeover attempts by preventing attackers from using stolen credentials or reused passwords to hijack accounts.

In May, GitHub also added support for securing SSH Git operations using FIDO2 security keys for added protection from takeover attempts.


News URL

https://www.bleepingcomputer.com/news/security/github-deprecates-account-passwords-for-authenticating-git-operations/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Github 10 2 30 29 14 75
GIT 2 0 3 4 1 8