3 ms·
I agree it's nonsense. The argument appears to dodge 2FA itself and the benefits to ecosystem by instead focusing on fairness, which is subjective at best. It'
by dlor 4y ago
I agree it's nonsense. The argument appears to dodge 2FA itself and the benefits to ecosystem by instead focusing on fairness, which is subjective at best.
It's not "fair" that the author has to accept the burden of 2FA, because they created a package that turned out to be critical through no fault of their own.
It would seemingly satisfy the author's "fairness" goal if everyone had to use 2FA whether their packages are critical or not.
It's also ironically not "fair" that the volunteer maintainers of PyPI are subjected to complaints like this for their hard and valuable work to improve the security of the entire ecosystem, which has become critical infrastructure itself through no fault of their own.