3 ms·
I find it bizarre that they don't ask for 2FA for all contributions. Possibly a historical inheritance? Edit: I now understand that they require a physical dev
by mtrycz2 4y ago
I find it bizarre that they don't ask for 2FA for all contributions. Possibly a historical inheritance?
Edit: I now understand that they require a physical device instead of a TOTP app. Yeah, that's the line between reasonable and wtf.
- lopuhin 4y ago> they require a physical device instead of a TOTP app. Yeah, that's the line between reasonable and wtf. No, a TOTP app is also allowed.
- mtrycz2 4y agoWell then, that's perfectly reasonable.
- staticassertion 4y agoTo tack on, they're actually giving away those tokens for free for those who request one. https://pypi.org/security-key-giveaway https://pypi.org/security-key-giveaway They're being beyond reasonable. This is outright kind.
- Tainnor 4y ago> Edit: I now understand that they require a physical device instead of a TOTP app. Yeah, that's the line between reasonable and wtf. They don't.
- btown 4y ago2FA, whether TOTP or physical, comes with a per-user support burden for any organization that enforces it, because there must be a human-in-the-loop mechanism to handle "my 2FA devices were all destroyed/stolen, and others depend on me having access to my account." PyPI isn't exempt from this, despite mitigating with multiple 2FA devices, and says as much in the announcement https://pypi.org/security-key-giveaway/ https://pypi.org/security-key-giveaway/ - > Without multiple 2FA options, effect of losing a 2FA method results in the need to fully recover an account, which is burdensome and time-consuming both for maintainers and PyPI administrators. Enabling multiple 2FA methods reduces the potential disruption if one is lost. So there's a huge practical difference to PyPI of enforcing 2FA for all vs. enforcing for <1% of projects. I don't envy their position, and it's a reasonable compromise IMO. That said, it's absurd that PyPI didn't make more clear in the announcement linked above that TOTP apps are allowed. There's literally not an FAQ about the most important FAQ. They very well could have avoided the reaction from OP, and this entire debacle, with more thoughtful messaging.