6 ms·
The index thinks that a widely- adopted package looks like a tempting target for hackers to inject malware. They need to help avoid that, for ethical, legal, an
by crumpled 4y ago
The index thinks that a widely- adopted package looks like a tempting target for hackers to inject malware. They need to help avoid that, for ethical, legal, and business reasons. Signing the release sounds perfectly reasonable too.
HOWEVER
I do think that a lot of the committing here is focused too much on the thing that got the author thinking (2FA), and focused too little on what the author was thinking about.
It is worth noticing that there's a potential for a package index to leverage your user base against you and start making demands. Of course you could walk away from pypy, or npm, but that's almost like suggesting you walk away from the Google Play store if you developed android apps. I like this article as something to keep in the back of your mind when you look at the future of package publishing.
How likely will this repo/index be to demand money from me some day when my user base gets large enough? Can I be delisted because of a new content policy?
- __alexs 4y agoI think it would be perfectly reasonable for these platforms to start demanding money. As a consumer and a producer of packages they provide a huge amount of value. Yes I could run my own but it's deeply inconvenient in many ways, that's part of where that value comes from.
- nmstoker 4y agoWhilst not impossible, as soon as that's done, it adds all sorts of unintended consequences
- pishpash 4y agoThen make sure the index is owned by a cooperative of all the developers (with appropriate ground rights), not by some arbitrary third party?
- staticassertion 4y agoPyPI is so easy to self host it's almost a joke. You can run a single python simple http server (one command) and use specific file system layout and you have a compatible pypi. If there is such a significant mismatch in what pypi is going for vs contributors, people will migrate to another solution.
- pas 4y agothere's a big gap between "meh it's okay" and "pypi really goes above and beyond to serve the package developers and the users too". it's strange (unexpected? totally expected? sad?) that the for profit npm (which started out as the butt of every supply chain joke) seems the most dev friendly. eg. npm has namespaces (and neither pypi nor rust's crates.io does. and the Rust dev experience is usually considered sublime, and the whole decision making in Rust land is [was?] very dev-driven)
- staticassertion 4y ago> which started out as the butt of every supply chain joke Mostly because 99% of developers knows nothing about supply chain attacks and leftpad blew up. Both npm and rust should force 2FA. Thankfully, crates.io forces github SSO, and github will eventually force 2FA.
- jlokier 4y ago> Thankfully, crates.io forces github SSO. Ouch. That must be difficult for any Rust package maintainers whose GitHub accounts were deleted a few months ago due to the Russian war sanctions.
- staticassertion 4y agoYes, Putin is a piece of shit, unfortunately.
- franciscop 4y agoExactly, I'm in the same boat as the author and you, where the 2FA is just a mild inconvenience (I travel a lot, no fixed sms, have lost too many yubikeys). However indexes forcing authors to use 2FA has open my eyes to how much control they have; if they required tomorrow to identify with a national ID, or pay $10/year for the top 1% of authors they could easily do so (e.g. any action not "too" drastic to have a massive backlash, meaning it's draconian but only for very few). This could go virtually in any direction and they have a massive amount power, and that feels very scary indeed. I've invested 10s of thousands of hours in writing open source, which I'm very happy to share with the world, and while I have multiple backups being banned or unable to use npm would def be a tragedy for me.
- massysett 4y agoThe index didn’t force the devs to do anything. The developer can just stop uploading packages. Years ago software was just distributed by the developers themselves on their own websites, or by Usenet, or even by floppy disks. It may well be that the developer wants to be on the index and is willing to pay. In that case, OK. Maintaining an index is not free, so if the indexer needs to charge somebody, it could be users, or it could be developers.
- franciscop 4y ago> Years ago software was just distributed... Well it's not years ago, in general most languages have been centralized around a single large index, which gives many advantages but also some disadvantages like seen here. This has been great so far since they've been benevolent, but in cases like npm (which I'm most familiar with) the non-profit Node Foundation joined the private company npm inc. giving it basically exclusive rights. Previous node and npm inc developers have tried to make alternatives, but unfortunately the reality is if you want to publish a JS package today and want anyone to use it, you should use npm. > Maintaining an index is not free No, it's indeed probably very profitable when npm was sold to Microsoft, since the npm owners fought tooth and nail before to keep it private and not part of the Node Foundation.