Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

two-factor authentication #358

Closed
sserrano44 opened this issue Sep 18, 2015 · 117 comments
Closed

two-factor authentication #358

sserrano44 opened this issue Sep 18, 2015 · 117 comments

Comments

@sserrano44
Copy link

Please add two-factor authentication people is using your service for deploying to production in continuos integration scenarios like Amazon EC2 Container Service.

@scottampush
Copy link

Bump ⬆️

1 similar comment
@sankethkatta
Copy link

Bump ⬆️

@Manouchehri
Copy link

TOTP or U2F would be great to have.

@joeldrapper
Copy link

👍

1 similar comment
@jpettersson
Copy link

👍

@pieterdd
Copy link

Bump ⬆️

@let4be
Copy link

let4be commented Feb 2, 2016

Any update?
Currently using docker hub private repos in production is questionable as tampering account password effectively means serious business problems

@cihanucar
Copy link

Any update?

@frekele
Copy link

frekele commented Jul 12, 2016

+1, two-factor authentication and/or oauth 2.0

This is regrettable, Portal Docker Hub, seems built by a child, it seems thing beginner, very amateur.

How can I trust my private repositories to docker Hub of security does not seem to be important for them.

We are seriously thinking to migrate to another provider.

Safety first!!!!

@frekele
Copy link

frekele commented Jul 12, 2016

@joeldrapper
I know him, including i already made some PR there. But the question here is another.

Security Docker Hub is the question here and not rancher server.

@joeldrapper
Copy link

joeldrapper commented Jul 13, 2016

@frekele sorry mate, I thought this might help if you were concerned about Docker Hub’s authentication for Docker Cloud. I don’t work for Docker, was just recommending Rancher as it’s more secure than Docker Cloud.

I totally agree with you. Docker Hub needs to take security seriously. 2FA, oauth, enforcing long passwords, etc. is really important for this. How can we know that even the official Docker Hub images, that we rely on, are safe from attack?

Personally, I'm making the best of the situation by using a ~50 character password that was generated by 1Password. That stops the brute-force threat, but can’t protect you from MITM or other possible attacks.

@frekele
Copy link

frekele commented Jul 13, 2016

@joeldrapper Exactly.

@munhitsu
Copy link

2FA is a need

@BAlmeidaS
Copy link

Bump ⬆️

@unresolv
Copy link

👍

3 similar comments
@revett
Copy link

revett commented Nov 7, 2016

+1

@egut
Copy link

egut commented Nov 14, 2016

+1

@gregholland
Copy link

+1

@kolobus
Copy link

kolobus commented Dec 11, 2016

Bump

@koekiebox
Copy link

+1

@mrafayaleem
Copy link

Bump ⬆️

@mzac
Copy link

mzac commented Jan 18, 2017

+1

@tjwebb
Copy link

tjwebb commented Feb 3, 2017

security plz

@rhuddleston
Copy link

+1

3 similar comments
@roman-vynar
Copy link

+1

@samsheff
Copy link

samsheff commented Aug 3, 2017

+1

@basgys
Copy link

basgys commented Aug 11, 2017

+1

@rhuddleston
Copy link

Seems we need a community driven, security focused public docker repo (with notary and 2-factor). Do any good alternative public container repos exists?

@nijave
Copy link

nijave commented Aug 22, 2019

Seems we need a community driven, security focused public docker repo (with notary and 2-factor). Do any good alternative public container repos exists?

Github's is in beta right now https://help.github.com/en/articles/configuring-docker-for-use-with-github-package-registry

@pbostrom
Copy link

@nijave The github package registry looks nice, thanks. Now if only my beta invite will come through...

@jaywink
Copy link

jaywink commented Aug 22, 2019

GitLab has a really well working registry - and it has 2fa! :)

It's also available for gitlab.com accounts as per:

If you are using GitLab.com, this is enabled by default so you can start using the Registry immediately. Currently there is a soft (10GB) size restriction for registry on GitLab.com, as part of the repository size limit.

https://docs.gitlab.com/ee/user/project/container_registry.html

@rhuddleston
Copy link

@nijave, any idea if github supports notary?

@payamazadi-natgeo
Copy link

how is this still a thing? please add 2fa it's not that hard there are plenty of OAuth and SAML plugins

@philCryoport
Copy link

there are alternative container runtimes

There sure are, I recommend rkt: https://coreos.com/rkt/

Here's a list I found by googling: https://www.g2.com/products/docker-hub/competitors/alternatives

@DrSensor
Copy link

DrSensor commented Sep 7, 2019

@meticulous-dft is everything okay?

@comunitius
Copy link

Hello from September 😃 https://twitter.com/comunitius/status/1170450304849965056

@jakejarvis
Copy link

Hello? Anyone? Bueller....?

This is looooong overdue and a pretty insane lack of communication.... SO many scary potental problems that should be keeping you up at night! I'm guessing this would be a few days' work with the amount of plug-and-play solutions out there.

Moving to GitLab in the meantime, which is unfortunate. :( Just got the GitHub Package beta this week so looking into that too. Please, at the very least, give us an update!!!!

@comunitius
Copy link

FYI #1879

@dgw
Copy link

dgw commented Sep 25, 2019

My uptime monitoring service now supports 2FA, and Docker Hub still does not.

A breach of my Uptime Robot account can't affect anything except my potential response delay when stuff goes down. It's nice to have, but I'd notice on my own a few minutes later in most cases. A breach of my Docker Hub account could theoretically poison half an ecosystem (or worse) in a few minutes, before anyone has a chance to react.

Please, please give us some transparency on what's holding this up. The continued silence should embarrass everyone at Docker, Inc.

@meticulous-dft
Copy link

Quick update: we released personal access token last week https://docs.docker.com/docker-hub/access-tokens/, now we are wrapping up and internal testing 2FA. It will be released in October.

@deekej
Copy link

deekej commented Sep 30, 2019

<sarcasm>
After reading this issues comments you no longer have to rush - I've already lost trust in your company. And I think many others did as well... :) Now you also need to fix your reputation as well, so GL with that.
</sarcasm>

@sweepies
Copy link

Sarcasm not needed - letting this security issue go on for 4 years with no comment until now is absolutely not okay.

@dm17
Copy link

dm17 commented Oct 19, 2019

I'm also trying to get clarity on how secure having our own private registry is...
Is TOTP something devs outside of Docker can add, or do we need their help?

@joshatintegris
Copy link

joshatintegris commented Oct 19, 2019

@dm17 - we have opted to use Harbor for our private registry and have integrated it with Okta using OIDC for auth. That gives us enforced MFA for access to the UI at least. Pulling images still requires the use of an auth code without MFA but that’s not a requirement for us. Okta has a free developer account for up to 1000 monthly active users and Harbor is not super hard to deploy. It also comes with a Notary for signing and verifying images, which is pretty useful.

@shaneakr
Copy link

shaneakr commented Oct 22, 2019

2FA on Docker Hub was launched today.

@dylmye
Copy link

dylmye commented Oct 22, 2019

4 years, 4 days and 1 breach later, with little communication, we're here. Hope this can be avoided in similar occasions in the future. Again an explanation for how we got to this state would be good. :)

@shaneakr
Copy link

4 years, 4 days and 1 breach later, with little communication, we're here. Hope this can be avoided in similar occasions in the future. Again an explanation for how we got to this state would be good. :)

I don't know all of the history as I'm new-ish to Docker but what I do know is that our team has worked and will continue to work to ensure that our platform is secure.

@payamazadi-natgeo
Copy link

thanks @shaneakr, we all appreciate your hard work! this was great news!

@fgervais
Copy link

https://www.docker.com/blog/designing-docker-hub-2fa/

Thank you for targeting webauthn. Hoping my bank would do the same ;)

@manishtomar
Copy link
Contributor

Closing now that it is finally launched :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests