Strengthening GitLab.com security: Mandatory multi-factor authentication
Blog post from GitLab
GitLab is enhancing security on GitLab.com by mandating multi-factor authentication (MFA) for all users and API endpoints that authenticate using a username and password, as part of its Secure by Design commitment to combat credential stuffing and account takeover attacks. This requirement applies to users who sign in with a username and password, but not to those using social sign-on or single sign-on, unless they also have a password for direct login. The MFA rollout will occur gradually over the coming months, with notifications provided via email and in-product reminders, allowing users to prepare and minimize disruptions. Users are advised to set up MFA methods like passkeys, authenticator apps, or WebAuthn devices, and to securely save recovery codes. For API authentication, switching to personal access tokens is recommended. Failure to enable MFA by the deadline will prevent account access, and password-based CI/CD pipelines or automations will require adjustments unless using personal access or deploy tokens.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.