4 ms·
I think 2FA, if it mandates SMS use, is a burden for certain package types. Imagine a package that helps you write software that bypasses the Great Firewall. Th
by dataangel 4y ago
I think 2FA, if it mandates SMS use, is a burden for certain package types. Imagine a package that helps you write software that bypasses the Great Firewall. There is occasionally value in anonymously authored software, and cell phones to degrees that vary by country reveal your identity and at the very least give a central authority knowledge about your location.
- ev1 4y agoPyPI is correct 2FA: TOTP, WebAuthn etc
- adamius 4y agoSeems sane. Its not like its a SMS / phone required situation is it? Unlike some others...
- radus 4y agoIn that scenario though I think there are reasons why one might avoid package repositories such as pypi. For instance, say a censorship avoidance package is popular on pypi - what happens when whatever authority comes knocking? I would think that it would be more secure to provide anonymized distribution as well. Of course, that means that you lose some convenience and reach, but that’s a common trade off in scenarios that have elevated security needs.
- woodruffw 4y agoPyPI does not use SMS 2FA. It only supports WebAuthn (which is preferred) and TOTP. Source: I implemented PyPI’s 2FA.
- DiggyJohnson 4y agoCheers. I love when this happens on HN. Hope these comments don’t make you go crazy. It’s always fun and frustrating to see an area you are extremely familiar with being discussed by those unfamiliar. fun in this comment thread.
- woodruffw 4y agoI have a lot of sympathy for some of the frustration being expressed here: I do a lot of open source maintenance, and any amount of change to my workflows drives me up the wall! That being said: the PyPI maintainers are also in this community, also doing largely thankless work to keep one of the world’s biggest package indices healthy (and secure). Their motives are good, and (IMO) the rollout here walks the right line between imposition and changes that are necessary to match the prevailing winds in supply chain security.
- staticassertion 4y agoPlease keep up the excellent work, I'm very encouraged by what I'm seeing from PyPI.
- woodruffw 4y agoThanks for the kind words. Just to clarify (and avoid stolen valor): I worked on the 2FA implementation, but not the current critical project scheme or free key giveaway. That was all done by PyPI’s maintainers (I’m just a contributor), and they’re absolutely incredible and tireless in their commitment.
- nocturnial 4y agoMaybe also mention eligible maintainers can also get free titan security keys (with free shipping). This should reduce the burden even further. https://pypi.org/security-key-giveaway/ https://pypi.org/security-key-giveaway/