Dear Eclipse Platform Team,

I am reaching out to request that your project enforces two-factor 
authentication (2FA) for all committers at GitHub. We, at the Eclipse 
Foundation, take the security of your project's code and data very seriously. 
Enforcing 2FA can greatly improve the security of your project and protect it 
from potential security breaches.

As you may know, 2FA adds an extra layer of security to the login process by 
requiring users to provide two forms of authentication: something they know 
(such as a password) and something they have (such as a security key or 
smartphone). This significantly reduces the risk of unauthorized access to 
sensitive information, as it makes it much more difficult for hackers to gain 
access to user accounts. With the increasing number of security breaches and 
cyberattacks, it is crucial for open source projects to take extra precautions 
to secure their code and data. Enforcing 2FA for all committers would be a 
simple yet effective way to enhance the security of your project. See a blog 
post of mine 
<https://mikael.barbero.tech/blog/post/2022-11-22-2fa-for-developers/> for 
additional details.

We understand that implementing 2FA may require some effort, but we are here to 
help. If you want to start enforcing it, just open a ticket on the Eclipse 
Foundation help desk 
<https://gitlab.eclipse.org/eclipsefdn/helpdesk/-/issues/new?issue%5Btitle%5D=Enforce%202FA%20on%20my%20GitHub%20organizations>.
 I can already tell you that less than 70% of committers have 2FA activated in 
your GitHub organization.

Finally, I would like to remind you that GitHub will eventually enforce 2FA for 
all projects by the end of the year 
<https://gitlab.eclipse.org/eclipsefdn/helpdesk/-/issues/new?issue%5Btitle%5D=Enforce%202FA%20on%20jakartaee%20and%20ee4j%20GitHub%20organizations>.
 Be proactive and start right now!

Thank you for your time and consideration. I look forward to your response.

Cheers,


Mikaël Barbero
Head of Security | Eclipse Foundation
🐦 @mikbarbero
📅 Book an appointment <https://calendar.app.google/K1N73kjhE57xHgND9>
Eclipse Foundation <http://www.eclipse.org/>: The Platform for Open Innovation 
and Collaboration



Attachment: signature.asc
Description: Message signed with OpenPGP

_______________________________________________
platform-dev mailing list
platform-dev@eclipse.org
To unsubscribe from this list, visit 
https://www.eclipse.org/mailman/listinfo/platform-dev

Reply via email to