https://www.facebook.com/itzonepakistan
×

Archives

  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2021
  • February 2021
  • December 2020
  • November 2020
  • April 2019

Categories

  • Business
  • DMS
  • Networking
  • Technology
  • Tips
  • Uncategorized

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

HOW TO SHOP

1 Login or create new account.
2 Review your order.
3 Payment & FREE shipment

If you still have problems, please let us know, by sending an email to support@website.com . Thank you!

SHOWROOM HOURS

Mon-Fri 9:00AM - 6:00AM
Sat - 9:00AM-5:00PM
Sundays by appointment only!
social sharing

SIGN IN YOUR ACCOUNT TO HAVE ACCESS TO DIFFERENT FEATURES

FORGOT YOUR PASSWORD?

FORGOT YOUR DETAILS?

AAH, WAIT, I REMEMBER NOW!
QUESTIONS? CALL: 03144 166 777
  • LOGIN
  • SUPPORT

IT Zone Pakistan

IT Zone Pakistan

IT Zone Pakistan | Graphics, Web Design, ERP, Document Scanning Services, 3d interior design

T (31) 44 166 777
Email: sales@itzonepakistan.com

IT Zone Pakistan
II Chundriger Road Uni Plaza Karachi-Pakistan

Open in Google Maps
  • Home – IT Zone
  • About Us
  • Our Services
    • Office Paper Shredding Service – Free of Charge!
    • Document Scanning Services
    • Document Management Software
    • Office Computer Scrap Buying
  • Shop
  • BLOG & STORIES
    • EVENTS
  • Contact Us
  • MY CART
    No products in cart.
FREEQUOTE
  • Home
  • BLOG & STORIES
  • Uncategorized
  • Free Scanning and 2FA Enhance GitHub Software Ecosystem – TechGenix
July 1, 2025

Free Scanning and 2FA Enhance GitHub Software Ecosystem – TechGenix

Free Scanning and 2FA Enhance GitHub Software Ecosystem – TechGenix

by admin / Friday, 30 December 2022 / Published in Uncategorized

Microsoft subsidiary, GitHub, rolled out its secret scanning service to all users on Dec. 15. This service was previously available only to GitHub Enterprise Cloud users with a GitHub Advanced Security license. GitHub’s secret scanning looks through public repositories for over 200 token formats. In 2022, GitHub alerted its partners to over 1.7 million security exploits. 
“Secret scanning alerts notify you directly about leaked secrets in your code. We’ll still notify our partners for your fastest protection, but now you can own the holistic security of your repositories,” read the GitHub blog.
Users will also get two-factor authentication (2FA) security feature in March 2023. GitHub had previously announced that it’d implement 2FA for high-impact package maintainers in Nov. 2022. However, it recently outlined 2FA’s wide-scale implementation across its 94-million user base. 
The rationale behind GitHub’s free scanning tool is to prevent secrets and credentials compromises. A “secret” is a token or an authentication tool. Developers rely on them for communication with external services. Secret scanning takes place in Git history and all its branches. 
As per the GitHub document, the secret scanning tool looks for known security vulnerabilities. This is something to keep in mind as a caveat, given that vulnerabilities can also be unknown (found only months after they occur). 
That said, users can implement secret scanning alerts through “Code security and analysis” settings. Already exposed secrets are present under the “Vulnerability alerts” section. When you select any of the exposed secrets, you can view the exposure type and the remedial action you need to take. 
Users and partners get different forms of secret scanning on GitHub. Users constitute:
On the other hand, partners get an alert when the same file has two keys. GitHub works with a number of partners to find exposed secrets. GitHub automatically alerts its partners when secret scanning detects a secret in a GitHub commit. The platform currently works with over 100 partners, including Adobe, Azure, Atlassian, Dropbox, Discord, Hubspot, Meta, Shopify, Stripe, etc. 
According to IBM, leaked credentials are the most common type of data breach. These data breaches cost more than $150,000 than the average data breach and take 327 days to identify. The IBM report, cited by GitHub, highlighted that 83% of companies could suffer from one or more of these data breaches. The report further recommends using automation tools, which can cut threat identification times by 74 days. 
Leaked secrets are especially worrying in the context of the software supply chain. Google recently released a report concerning the software supply chain and open-source dependencies. With open-source software in wide circulation, a compromised commit can affect all developer dependencies. Moreover, the line between commercial and public software is growing thinner as commercial entities begin relying on open-source code. 
Companies using open-source code allow cybercriminals an increasing number of attack vectors. Sadly, organizations cannot reduce these dependencies without also reducing operational efficiencies. Enforcing 2FA can be the best bet for companies in such a situation. And that’s what GitHub is working on implementing in the next phase to reduce the damage from attacks that target related software systems. 
In addition to free secret scanning, GitHub is also rolling out 2FA from March 2023 to all code contributors. 2FA increases network security by asking users for an additional passcode before logging them into an application. This stops cybercriminals from compromising a network unless they gain access to either the physical device or application. 
The following user classes will be able to use 2FA:
By the end of 2023, 2FA will be mandatory for all users, including people who publish code on the platform — everyone will have to fulfill a 2FA login. Users who fail to enable 2FA will have 45 days before they’re blocked from using GitHub features. Overall, 2FA will make the software ecosystem safer for all parties. As a bonus to this, GitHub, like Google, is also adding passkey support, which is an alternative to passwords. 
Alex Weinert, Microsoft’s Director of Identity Security, said that an account using 2FA is 99.99% less likely to be compromised, whereas cybercriminals always compromise passwords. Microsoft research further stated that using powerful passwords doesn’t prevent compromises, but it’s still better than weaker passwords.
Google research also indicated that “adding a recovery phone number to your Google Account can block up to 100% of automated bots, 99% of bulk phishing attacks, and 66% of targeted attacks that occurred during our investigation.”
Identity management is a significant issue. The debate around it will get even more heated as we increase the adoption of online authentication. GitHub has committed itself to protect its users’ and partners’ identities by rolling out 2FA and secret scanning, laying down an example for us all to follow. 
The CEO of Zurich Insurance, one of Europe’s largest insurance companies, has said that cybercrime could soon become uninsurable, warning that the risks surpassed climate…
Read More »
Facebook owner, Meta, has agreed to a $725 million settlement in relation to the longstanding Cambridge Analytica scandal that first emerged in 2018. Facebook allowed…
Read More »
Ireland’s Data Protection Commission (DPC) has launched a Twitter inquiry after a breach affected over 5.4 million users through an API vulnerability. DPC launched the…
Read More »
A recent report from Prodaft has unveiled FIN7 as one of the deadliest cybercrime groups on the planet, with a particular emphasis on breaching corporate…
Read More »
Your email address will not be published. Required fields are marked *


This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

document.getElementById( “ak_js_1” ).setAttribute( “value”, ( new Date() ).getTime() );
Join Our Newsletters
Learn about the latest security threats, system optimization tricks, and the hottest new technologies in the industry.
TechGenix reaches millions of IT Professionals every month, empowering them with the answers and tools they need to set up, configure, maintain and enhance their networks.
Copyright © 2022 TechGenix

source

  • Tweet

About admin

What you can read next

‘Couture for data’: capturing organisational know-how for good – Raconteur
Document Scanning Services Market Size Is Booming Worldwide with Share, Top Key Players (2024-2034) – Third Eye News
Scan Document from Notes App Icon on iPhone or iPad – OSXDaily

Recent Posts

  • WhatsApp is adding document scanning feature on Android: Here’s how to use – financialexpress.com

    source...
  • EU Settlement Scheme: information for local authorities – GOV.UK

    source...
  • WhatsApp Tests New In-App Document Scanner for Android Beta Users – StartupNews.fyi

    source...
  • Samsung phones get one more way to scan documents – SamMobile

    source...
  • Geopro Consultants, LLC brings unique business and technology jobs to Lancaster – Lancaster Eagle-Gazette

    source...

Recent Comments

    Featured Posts

    • WhatsApp is adding document scanning feature on Android: Here’s how to use – financialexpress.com

      0 comments
    • EU Settlement Scheme: information for local authorities – GOV.UK

      0 comments
    • WhatsApp Tests New In-App Document Scanner for Android Beta Users – StartupNews.fyi

      0 comments
    • Samsung phones get one more way to scan documents – SamMobile

      0 comments
    • Geopro Consultants, LLC brings unique business and technology jobs to Lancaster – Lancaster Eagle-Gazette

      0 comments

    Archives

    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2021
    • February 2021
    • December 2020
    • November 2020
    • April 2019

    Categories

    • Business
    • DMS
    • Networking
    • Technology
    • Tips
    • Uncategorized

    Meta

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    GET A FREE QUOTE

    Please fill this for and we'll get back to you as soon as possible!

    FACEBOOK

    2,175
    LIKES

    TWITTER

    1,050
    Followers

    PINTEREST

    101
    follower

    FOOTER MENU

    • Terms and Conditions
    • F.A.Q.
    • Our Services
    • BLOG & STORIES

    NEWSLETTER SIGNUP

    By subscribing to our mailing list you will always be update with the latest news from us.

    We never spam!

    GET IN TOUCH

    II Chundriger Road Uni Plaza Karachi-Pakistan
    Email: Info@Itzonepakistan.com
    Phone:
    Direct+92-314-4166-777
    Sales+92-313-8854-133

    Social Platform

    • Tweet
    • Pin It

    RSS ARY NEWS

    • Pakistan and India exchange lists of prisoners July 1, 2025
    • GET SOCIAL
    IT Zone Pakistan

    Copyright @2024-25. All rights reserved | Design & Develop IT Zone Pakistan.

    TOP