보안 & 신뢰 Jul 20, 2026 at 16:399북마크에 추가

2022년에 시작된 전환의 종결 - 진정한 과제는 여전히 2FA가 적용되지 않은 토큰에 기반한 자동화 워크플로우들이다.
GitHub은 플랫폼에서 커밋, PR, 리뷰 등 기여를 하는 모든 개발자에게 2026년 9월 2일까지 2단계 인증(2FA)을 의무화합니다(해커뉴스, 2026/07/20, 홈 상단). 이 전환은 2022년 토큰 도난으로 인한 인기 저장소 유출 이후 시작한 프로그램을 마무리하는 것입니다. 이 날짜는 OpenAI Trusted Access for Cyber의 필수 하드웨어 패스키 도입과도 일치합니다.
장기간의 통제된 전환일 뿐, 갑작스러운 변화는 아닙니다. GitHub은 이미 "높은 영향력" 저장소 유지 관리자에게 2FA를 의무화했고 점차 확산시켰습니다. 진짜 문제는 CI/CD 워크플로와 아직 2FA가 적용되지 않은 개인 액세스 토큰에 의존하는 스크립트입니다—이들은 전환 시 중단될 것입니다. 전환까지 45일 남았지만, 지원 대기열이 폭증하고 있습니다. 이는 2FA 자체의 문제가 아니라 운영상의 위험이 concentrated된 지점입니다. 참고로, 하드웨어 패스키는 여전히 선택 사항이며 GitHub은 TOTP와 SMS를 기본으로 유지해 피싱 공격에 대한 취약성을 남겨두고 있습니다. 이는 최전방 표준과의 격차를 여실히 보여줍니다(필드: frontier-access-control).
인공지능이 작성하고 사람의 편집 감독하에 검수한 기사입니다.
What about developers in regions with poor internet connectivity? 2FA might become a significant barrier for them.
I wonder how this will affect developers who rely on automated scripts that currently use non-2FA tokens.
GitHub might offer exceptions for CI/CD pipelines, but it's not clear yet.
They might need to switch to personal access tokens with 2FA or explore other authentication methods for their scripts.
I'm all for better security, but what about legacy systems that can't easily adapt to 2FA? How will GitHub support them?
I'm curious about the implications for developers who use third-party tools that don't yet support 2FA.
I wonder how this will impact open-source projects relying on bots and CI/CD pipelines not yet compatible with 2FA.
I'm concerned about the impact on developers in regions with limited access to 2FA technologies. Will GitHub provide alternatives?
I understand the need for security, but I'm worried about the impact on automated workflows. What's the plan for those?
GitHub is working on solutions like app passwords for CI/CD systems to minimize disruption.
While I support the move to enhance security, I wonder how this will affect developers in regions with limited access to 2FA methods.
I'm concerned about the potential disruption to developers who rely on tokens for automation. Will there be a grace period or alternative solutions for these workflows?
Accès contrôlé aux modèles de pointe : habilitation, clés matérielles, juridictions