Skip to content

[Security todo] Enforce 2FA for the maintainer account and any future collaborators #229

Description

@superagent-security

Security todo

2FA enforcement is org/account-level and could not be verified here, but panbanda is the sole admin with full push/admin/maintain rights and owns the crates.io publish path. A phished password on that one account is the whole ballgame. Enable 2FA (prefer passkey/WebAuthn over SMS) on the maintainer account, and require 2FA for any future collaborators or the owning org.

Context

  • Severity: High
  • Category: account_access_control
  • Confidence: Unverified
  • Threat: Compromised contributor — account takeover via credential theft is the cheapest path to repo + publish control.

Evidence

collaborators list only panbanda with admin=true; 2FA status is not readable from the API.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions