Hacker News new | ask | show | jobs
by justinwr 4021 days ago
Great news for anyone that doesn't care at all about protecting their SCM with MFA.
4 comments

Not a concern for bitbucket since MFA is not supported, and there is no timeline to support it:

https://bitbucket.org/site/master/issue/5811/support-two-fac...

Couldn't agree more, and came here to say this also. I understand that they are driving forward with new features for developers, but security cannot be taken seriously enough when they are hosting organisation's private code. I cannot take them seriously until they add this feature.
I just don't get the reticence to implement it - I added 2FA to a customer facing app we produce in less than a week - and most of that time was coming up with a nice/pretty setup workflow to enable it on your account.
From what I've read, it seems because of the complications of the global Atlassian accounts across multiple domains.
What's MFA?
it could be multi-factor-authentication/authorization but i don't know for sure