Back to News
Advertisement

GitHub's 2FA is to become mandatory on September 2, 2026

iitvision about 17 hours ago 7 comments

FR version is available. Content is displayed in original English for accuracy.

Hey birdie-github!

We're reaching out to let you know that as announced last year, we will officially ([begin][1]) requiring two-factor authentication (2FA) for certain contributors on GitHub.com. You are receiving this notification because your account meets the criteria for the current enrollment group, and you have 2FA enabled already.

You don't need to do anything in response to this email. After September 2nd, 2026 at 00:00 (UTC), you will no longer be able to disable 2FA. If you disable 2FA before then, your access to GitHub.com will be restricted on this date until you re-enable 2FA. This email, and a dismissible banner on GitHub.com, will be the only notifications about this change.

For more information about this program, please take a look at ([our documentation][2]).

Making the software supply chain more secure is a team effort, and we couldn't do it without you. Your enrollment in 2FA is an impactful step in keeping the world's software secure.

To see this and other security events for your account, visit your account ([security audit log][3]).

If you run into problems, please contact support by visiting the GitHub ([support page][4]).

Thanks, The GitHub Team

[1]: https://github.blog/2023-03-09-raising-the-bar-for-software-security-github-2fa-begins-march-13 [2]: https://docs.github.com/authentication/securing-your-account-with-two-factor-authentication-2fa [3]: https://github.com/settings/security-log [4]: https://github.com/contact

Advertisement

⚡ Community Insights

Discussion Sentiment

100% Positive

Analyzed from 106 words in the discussion.

Trending Topics

#phone#authenticator#https#fact#orgs#member#flipping#switch#newsworthy#yep

Discussion (7 Comments)Read Original on HackerNews

majewsky•about 16 hours ago
The fact that one of the orgs that you're a member of is flipping the switch is not newsworthy.
gus_massa•about 9 hours ago
Yep, it has been happening since a long time.
lioeters•about 16 hours ago
If anyone prefers not to use a mobile phone for this purpose, it is possible to use an application such as Authenticator (fox Linux).

https://gitlab.gnome.org/World/Authenticator

There are disadvantages to this, but for some people the requirement of a phone for 2FA is inconvenient or unacceptable.

VCFundedGenYer•about 6 hours ago
I have used 2FAuth for years and it is rock solid. You can self-host it on a NAS or a pi or local computer via Docker. https://github.com/Bubka/2FAuth
magackame•about 15 hours ago
I just store them in bitwarden. Wonder what 2FA actually protects against, when any malware will just steal your session tokens anyway.
pdpi•about 15 hours ago
Or you can use a hardware U2F key.
m0llusk•about 12 hours ago
I'm an uncertain contributor so this shouldn't apply to me.