Feeds

Linux kernel devs made to finger their dongles before contributing code

Two-factor auth enabled for Kernel.org repositories

Beginner's guide to SSL certificates

Beginning on Monday, the security of the Linux kernel source code has become a little bit tighter with the addition of two-factor authentication for the kernel's Git code repositories.

Contributing code changes to the Linux kernel sources at Kernel.org already required more than just a password, even before the change. Developers must use their own unique SSH public keys to login to the Git repositories. But not even this added security layer was truly failsafe – as the software's maintainers found out in 2011 when their servers were rooted.

"While using ssh keys is much more secure than just passwords," Linux Foundation IT director Konstantin Ryabitsev explained in a blog post on Monday, "there are still a number of ways for ssh private keys to fall into malicious hands – for example if the developer's workstation is compromised or if someone manages to access some poorly secured backups."

To lock down access even further, the Linux Foundation has now added a true two-factor authentication step – in this case, by requiring each kernel contributor to provide a one-time code obtained from a hardware token.

The specific tokens used are Yubikeys, tiny dongles produced by Swedish startup Yubico that act like keyboards when you plug them into a USB port. Press the single button on the Yubikey and it "types" the one-time code for you.

The tag in question

Linux kernel developers will need one of these to contribute from now on

According to Ryabitsev, Yubico donated 100 Yubikeys for the effort – enough for all of the Linux kernel developers who currently have accounts at Kernel.org.

This doesn't mean kernel development is strictly tied to Yubico. Rather than using the company's own two-factor implementation, the Linux Foundation has opted to use a system based on the open HMAC-based One-Time Password (HOTP) algorithm, meaning developers can also opt to use a "soft token" if they prefer, such as a smartphone app that implements the same algorithm.

Developer who do a lot of work from the same place can also choose to whitelist their IP addresses for up to 30 days so that they don't need to enter new one-time passwords as often.

What they can't do anymore, however, is access the kernel repositories without providing a one-time code at all. Ryabitsev says mandatory two-factor authentication was enabled for the mainline and stable Linux kernel repositories on Monday, to coincide with the opening of this year's Linux Kernel Summit, taking place this week in Chicago.

"As kernel developers congregate in Chicago ... we are hoping that many more of them will choose to turn on 2-factor authentication on their own repositories hosted at kernel.org, to make it that much more difficult for an attacker to sneak in a malicious commit," Ryabitsev said. ®

Beginner's guide to SSL certificates

More from The Register

next story
Preview redux: Microsoft ships new Windows 10 build with 7,000 changes
Latest bleeding-edge bits borrow Action Center from Windows Phone
Google opens Inbox – email for people too thick to handle email
Print this article out and give it to someone tech-y if you get stuck
Microsoft promises Windows 10 will mean two-factor auth for all
Sneak peek at security features Redmond's baking into new OS
UNIX greybeards threaten Debian fork over systemd plan
'Veteran Unix Admins' fear desktop emphasis is betraying open source
Entity Framework goes 'code first' as Microsoft pulls visual design tool
Visual Studio database diagramming's out the window
Google+ goes TITSUP. But WHO knew? How long? Anyone ... Hello ...
Wobbly Gmail, Contacts, Calendar on the other hand ...
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.