Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

How we boosted WebAuthn adoption from 20 percent to 93 percent in two days

Blog post from GitLab

Post Details
Company
Date Published
Author
Eric Rubin
Word Count
1,028
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab accelerated the adoption of phishing-resistant authentication methods following significant phishing campaigns that breached various tech companies, opting for WebAuthn devices as the sole method for logging into Okta, their main SaaS application platform. This shift was necessary due to the vulnerabilities associated with other multi-factor authentication (MFA) methods, such as SMS, TOTP codes, and push notifications, which are susceptible to various types of attacks. The company communicated this transition through a series of initiatives, including a Slack announcement from the CEO, a dedicated FAQ document, and virtual office hours for support. Despite the challenge of transitioning over 1,700 remote team members across more than 65 countries within a tight 48-hour deadline, GitLab successfully enrolled 93% of its employees in the new system by leveraging existing technologies like Touch ID and YubiKeys, along with a significant communication strategy. The implementation was further facilitated by the discovery of a QR code scanning method for enrolling new devices, reducing the need for direct IT support and reinforcing the company's security posture efficiently.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 1 1,351 420 143 -5%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.