Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [ee4j-pmc] Request for Enforcing Two-Factor Authentication for All Committers
  • From: "Steve Millidge (Payara)" <steve.millidge@xxxxxxxxxxx>
  • Date: Fri, 3 Mar 2023 11:07:17 +0000
  • Accept-language: en-GB, en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=payara.fish; dmarc=pass action=none header.from=payara.fish; dkim=pass header.d=payara.fish; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=MADX00Jqblqb/EzJ2w44FGvzJV78yyfcTv/Nabr1mpE=; b=lFm5Zwc8pHSqAmNu/lxz9/aKyHazMQZ1Swfe8VJpQCt/RG/eFjp713oTuBsW8JwP+BgJas6ajyiqiwxR3t6qA4csuXxgetIWCYp/3V5eGvr8LM/q9RnoezygtkSP2P3X/fszN4KhO0BoqHuKqHuymOtd6C7TvmyOQrVZbqi8blT2YX0NevKMMXrWQOmMmbxKANb5hV62lT3m9J615jsu/0SoNStwlnhWvkG+Kcu1ZXZHgOmpGS9BBbPZ119w5mQI6KmE+Hh/qjKOTG1e/fs7jFvoMSsOqsO8rmwo1oKIAJm8rwwAfh/KFt90PmIVs+u6JyjmMjV4jqxP6KHq4nXg5w==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=cj71/RieGfjoxL4/Ca5Tx0vDN4QJerhbHJyW32nt0cA0KUrYfw7N/9Fnqogy74b9A6cqoKsHOHJeRwZj0GLViFmGiBAT6zh0ZB+FU2vVhvPeT8G1yY4jgwqv2mu8sI/pCdCAlvDt7VbWgcglTjK/m2k0QmDZj6y7AICrlUPesOZodnRcmT+ux5nfgt39AayrbqMQ7aquAK4ZZhSZBO2NkgKiikEm+VoNyMCra3c+poB6Tpj1k6Un6wc7bjV7VIXVVeBN7RiT764uP6srhUdsN/JuS182hfJqnopG+Z0F8Pj1iIfgj33CXTg5Cltwp2QMdbCROhIM4W9hlcMiUl6lHg==
  • Delivered-to: ee4j-pmc@xxxxxxxxxxx
  • List-archive: <https://www.eclipse.org/mailman/private/ee4j-pmc/>
  • List-help: <mailto:ee4j-pmc-request@eclipse.org?subject=help>
  • List-subscribe: <https://www.eclipse.org/mailman/listinfo/ee4j-pmc>, <mailto:ee4j-pmc-request@eclipse.org?subject=subscribe>
  • List-unsubscribe: <https://www.eclipse.org/mailman/options/ee4j-pmc>, <mailto:ee4j-pmc-request@eclipse.org?subject=unsubscribe>
  • Thread-index: AQHZTSpg9ryGqf9W3UGac5eOsLCLB67oGQoAgADHWNA=
  • Thread-topic: [ee4j-pmc] Request for Enforcing Two-Factor Authentication for All Committers

+1

 

From: ee4j-pmc <ee4j-pmc-bounces@xxxxxxxxxxx> On Behalf Of Ivar Grimstad via ee4j-pmc
Sent: Thursday, March 2, 2023 10:53 PM
To: EE4J PMC Discussions <ee4j-pmc@xxxxxxxxxxx>
Cc: Ivar Grimstad <ivar.grimstad@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: [ee4j-pmc] Request for Enforcing Two-Factor Authentication for All Committers

 

Unless there are objections among the PMC members, I'd say go ahead and activate it for all EE4J repositories. 

 

Ivar 

 

On Thu, Mar 2, 2023, 12:13 Mikael Barbero via ee4j-pmc <ee4j-pmc@xxxxxxxxxxx> wrote:

Dear EE4J/JakartaEE PMC Team,

 

I am reaching out to request that your project enforces two-factor authentication (2FA) for all committers at GitHub. We, at the Eclipse Foundation, take the security of your project's code and data very seriously. Enforcing 2FA can greatly improve the security of your project and protect it from potential security breaches.

 

As you may know, 2FA adds an extra layer of security to the login process by requiring users to provide two forms of authentication: something they know (such as a password) and something they have (such as a security key or smartphone). This significantly reduces the risk of unauthorized access to sensitive information, as it makes it much more difficult for hackers to gain access to user accounts. With the increasing number of security breaches and cyberattacks, it is crucial for open source projects to take extra precautions to secure their code and data. Enforcing 2FA for all committers would be a simple yet effective way to enhance the security of your project. See a blog post of mine for additional details: https://mikael.barbero.tech/blog/post/2022-11-22-2fa-for-developers/

 

We understand that implementing 2FA may require some effort, but we are here to help. If you want to start enforcing it, just open a ticket on the Eclipse Foundation help desk. I can already tell you just above 60% of committers have 2FA activated on both jakartaee and ee4j GitHub organizations.

 

Finally, I would like to remind you that GitHub will eventually enforce 2FA for all projects by the end of the year. Take the lead on that and start right now!

 

Thank you for your time and consideration. I look forward to your response.

 

Cheers,

 


MikaĆ«l Barbero 

Head of Security | Eclipse Foundation

🐦 @mikbarbero

Eclipse Foundation: The Platform for Open Innovation and Collaboration

 

 

 

_______________________________________________
ee4j-pmc mailing list
ee4j-pmc@xxxxxxxxxxx
To unsubscribe from this list, visit https://www.eclipse.org/mailman/listinfo/ee4j-pmc


Back to the top