How we boosted WebAuthn adoption from 20 percent to 93 percent in two days
Blog post from GitLab
GitLab accelerated the adoption of phishing-resistant authentication methods following significant phishing campaigns that breached various tech companies, opting for WebAuthn devices as the sole method for logging into Okta, their main SaaS application platform. This shift was necessary due to the vulnerabilities associated with other multi-factor authentication (MFA) methods, such as SMS, TOTP codes, and push notifications, which are susceptible to various types of attacks. The company communicated this transition through a series of initiatives, including a Slack announcement from the CEO, a dedicated FAQ document, and virtual office hours for support. Despite the challenge of transitioning over 1,700 remote team members across more than 65 countries within a tight 48-hour deadline, GitLab successfully enrolled 93% of its employees in the new system by leveraging existing technologies like Touch ID and YubiKeys, along with a significant communication strategy. The implementation was further facilitated by the discovery of a QR code scanning method for enrolling new devices, reducing the need for direct IT support and reinforcing the company's security posture efficiently.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Real-time | 1 | 1,351 | 420 | 143 | -5% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.