3 ms·
Wonderful news. Supply chain security is a disaster because developers won't opt into any kind of security features in the majority. Mandating 2FA is the obviou
by staticassertion 4y ago
Wonderful news. Supply chain security is a disaster because developers won't opt into any kind of security features in the majority. Mandating 2FA is the obvious solution, and we'll all be radically safer for it.
Glad to see Github pushing this, I hope package repositories follow suit!
- dane-pgp 4y agoThis change would certainly have helped against the infamous "Gathering weak npm credentials" research[0] from 2017, but I think that most recent supply chain security issues (in NPM, at least) have been due to: 1) typosquatting, 2) developers deliberately adding malicious (or unwanted) code into their own packages, and 3) deep transitive dependencies on packages that have genuine bugs that lead to vulnerabilities. It's not clear that this 2FA requirement would fix any of those problems, but it could one day allow package management tools to flag up when one developer has given/sold control of their package over to someone else who has less of a reputation and might be malicious, as was the case with the event-stream package.[1] [0] https://github.com/ChALkeR/notes/blob/master/Gathering-weak-npm-credentials.md https://github.com/ChALkeR/notes/blob/master/Gathering-weak-... [1] https://www.eweek.com/security/node.js-event-stream-hack-exposes-supply-chain-security-risks/ https://www.eweek.com/security/node.js-event-stream-hack-exp...
- staticassertion 4y agoYes, it definitely does not solve every problem.
- dane-pgp 4y agoFortunately no one is claiming that it does solve all problems, and I wasn't arguing against that non-claim. My point was, what percentage of supply chain issues (since that 2017 research) would have been mitigated by this policy change? To be extra clear, I'm not saying "This is a bad policy because it only stops some attacks", I'm just trying to get a sense of scale for how much this will help and how much more work needs to be done.
- staticassertion 4y agoI have no idea how many attacks this would stop. I suspect the answer is, roughly, "some".