4 ms·
There are many other problems beyond what 2fa can solve, so this discussion focused solely on 2fa is missing the forest for the trees. Specifically, one can get
by zbird 4y ago
There are many other problems beyond what 2fa can solve, so this discussion focused solely on 2fa is missing the forest for the trees. Specifically, one can get malware into a package via (a) publishing a malicious version of the package using stolen credentials, or (b) having the malware merged in a PR. 2fa only protects against the first case. Also, pulling in third-party dependencies into a software project without reviewing them is a terrible way to develop software, so the responsibility does not fully lie on the provider of the package (and, as I mentioned earlier, there is legally no responsibility on them anyway as per many of these free licenses.) So there are many more ways we can kill a distribution channel that 2fa cannot solve. Forcing 2fa on a select number of packages to suit the whims of corporations is still a shitty move. Though I still agree with you that, in general, more guarantees on the origin of a package is for the best.