two-factor-authentication

3 posts

gitlab

Passkeys now available for passwordless sign-in and 2FA on GitLab (opens in new tab)

GitLab now supports passkeys for passwordless sign-in and phishing-resistant two-factor authentication. Built on WebAuthn and public-key cryptography, passkeys let users authenticate with a fingerprint, face recognition, or device PIN while keeping the private key on their device. Users can register multiple passkeys across browsers, mobile devices, and FIDO2 security keys, improving both security and convenience. ## Passkeys for Sign-In and 2FA - Passkeys can be used: - As a passwordless login method. - As a phishing-resistant 2FA method. - For accounts with 2FA enabled, passkeys automatically become the default 2FA option. - Authentication uses a device fingerprint, facial recognition, or PIN. ## Registration and Compatibility - Users can register passkeys under **Profile settings > Account > Manage authentication**. - Supported platforms include: - Chrome, Firefox, Safari, and Edge. - iOS 16 and later. - Android 9 and later. - FIDO2 hardware security keys. - Multiple passkeys can be registered for access across different devices. ## WebAuthn Security Model - Passkeys rely on WebAuthn and public-key cryptography. - The private key remains securely stored on the user’s device and is never sent to GitLab. - GitLab stores only the public key. - A breach of GitLab’s stored credentials would not give attackers usable private keys for account access. ## GitLab’s Security Goals - Passkeys support GitLab’s commitment under the CISA Secure by Design Pledge. - They help increase MFA adoption while providing a smoother, phishing-resistant authentication experience. - GitLab invites users to provide feedback through its community and feedback channels. Users should register passkeys in their GitLab authentication settings, ideally across multiple trusted devices or security keys for both stronger protection and account recovery.

figma

Figma Expands Support for India with Local Data Hosting and New Governance Tools | Figma Blog (opens in new tab)

Figma is expanding its support for India with local hosting for Figma file data and stronger enterprise governance tools. Local data residency is planned for Q1 2026, helping regulated organizations meet security and compliance requirements while maintaining Figma’s performance. Governance+ is already available to Enterprise customers in India. ## Local Data Hosting for Indian Customers - Figma file data will be hosted within India, including content from FigJam, Make, Sites, Buzz, and Slides. - The option is intended for regulated sectors such as public services, healthcare, and finance. - Indian users created more than 35 million files between October 2024 and September 2025. - India is Figma’s second-largest active user base globally. - The offering builds on existing data residency options in Australia, Europe, and the United States. - Figma has expanded its local presence through a new Bengaluru hub and serves companies including Airtel, Flipkart, Swiggy, TCS, and Zomato. ## Governance+ for Enterprise Teams Governance+ gives organizations more control over how employees access and use Figma: - **Centralized control:** IP Allowlisting and Network Access Restrictions help ensure work occurs in approved Figma instances and networks. - **Account security:** Enforced two-factor authentication, extended idle session timeouts, and support for multiple identity providers reduce account-compromise risks. - **Data governance:** The Discovery Pipeline provides visibility into activity to support retention policies and legal discovery. - Governance+ complements existing tools such as activity logs, SSO, SCIM-based seat management, and restrictions on external collaborators. - The feature is available now to all Enterprise-plan customers. Figma’s India strategy combines regional data residency with tighter administrative controls, making the platform more suitable for organizations with strict privacy, security, and regulatory obligations. Enterprises interested in local hosting can register their interest ahead of its planned Q1 2026 launch.

figma

Figma's two-factor authentication | Figma Blog (opens in new tab)

Figma introduced two-factor authentication (2FA) to give users additional protection if their passwords are compromised. Users can receive codes by SMS or an authenticator app, with recovery codes available if they lose access to their phone. After verification, 2FA remains valid for 21 days unless the user logs in from a new device or signs back in after logging out. ## Enabling Two-Factor Authentication - Users can activate 2FA from the account settings menu in Figma. - Supported verification methods include: - SMS login codes - Authenticator apps such as Google Authenticator - The feature works with all mobile phones. ## Recovery and Login Behavior - Figma provides recovery codes in the account settings. - Users are encouraged to record these codes in case they lose their phone. - 2FA is required when: - Logging in on a new device - Signing back in after logging out - Once authenticated, the verification remains valid for 21 days. Figma recommended enabling 2FA as an additional account-security measure and indicated that more security features were planned for the future.