Developers rejoice: WordPress.org will be beefing up default security practices by requiring accounts to enable two-factor authentication if they have direct access to the codebases that power  plugins and themes.Â

The move, which will take effect Oct. 1, is aimed at preventing hijacked developer accounts from spreading malicious code to the likely hundreds of millions of sites using the free blogging software, the organization announced.

WordPress.org — which is the open source, self-hosted version of the blogging platform — is also introducing specific passwords for Apache Subversion, a popular, open-source version control system. The Subversion-specific passwords separate commit access from main account credentials, giving developers an additional layer of protection.Â

WordPress.org noted the current code base doesn’t allow for two-factor authentication on existing code repositories.

Making two-factor authentication a default option has been a major talking point for the Biden administration. The Cybersecurity and Infrastructure Security Agency went so far as to embark on a public campaign dubbed “More Than a Password” to tout 2FA as a basic cyber hygiene step that could dramatically reduce security incidents.Â

Supply chain hacks through abandoned WordPress themes or hacked plugin accounts is a common tactic among cybercriminals.

Users can configure 2FA on existing accounts here.

The post WordPress.org to require two-factor authentication for plugin developers appeared first on CyberScoop.

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

House Republicans propose eliminating funding for election security

June 5, 2024 0 Comments 0 tags

A key House panel has zeroed out funding for federal grants that would send tens of millions of dollars to state and local governments to improve the security of their

OpenAI Leadership Split Over In-House AI Watermarking Technology

August 9, 2024 0 Comments 0 tags

One primary concern is that the tool might turn ChatGPT users away from the product

Criminal Gang Physically Assaulting People for Their Cryptocurrency

July 18, 2024 0 Comments 0 tags

This is pretty horrific: …a group of men behind a violent crime spree designed to compel victims to hand over access to their cryptocurrency savings. That announcement and the criminal