5 ms·
With the belief that everyone is well intentioned and wants whats best for everyone, I think the thing that freaks me out about this whole thing is that through
by protomyth 4y ago
With the belief that everyone is well intentioned and wants whats best for everyone, I think the thing that freaks me out about this whole thing is that through some process a developer has had their work declared 'critical'. If PyPI said this was a new requirement for everyone, then it would be make more sense, but the sudden declaration just seems problematic. I get there is a resource issue, but no one likes getting an e-mail that they're now subject to new rules not applied to others.
So you maintain a package 'X', that has been determined to be 'critical'. It just seems like some user of package 'X' needs to perform some action to insure the group safety. It just seems like the one party that benefits the most isn't doing anything to help the situation. Thinking about it, what if the three users of your package are the credit agencies? The whole criteria seems a bit arbitrary.
But there’s a reason why the slippery slope is a fallacy
Yeah, if anything, its a certainty not a fallacy.
- giaour 4y agoThe "critical" designation is not arbitrary. It's based on download statistics. From https://pypi.org/security-key-giveaway/ https://pypi.org/security-key-giveaway/: > What determines if a project is a critical project? > PyPI determines eligibility based on download counts derived from PyPI's public dataset of download statistics. Any project in the top 1% of downloads over the prior 6 months is designated as critical.
- protomyth 4y agoIts still not a great measure. A project with three downloads that are all from the credit rating agencies, or a project with 100 downloads from all banks would be considered 'critical' by most folks.
- giaour 4y agoBut not by PyPI! Whoever is in charge of supply chain security at those credit rating agencies and banks should think long and hard about what they've gotten themselves into, though.
- protomyth 4y agoI'm a bit unclear about your response. My contention is that the method of determination of critical is based on something that really doesn't tell you how critical it is. I do believe the customer has a responsibility but I am not seeing any of that in PyPI's actions. Do I blame or think PyPI did anything wrong? No. I think everyone has the best intentions. I just think arbitrarily declaring someone work 'critical' without some involvement from the users of that developer's work is going to cause problems and not actually solve the issue. PyPI doesn't really have access to the information needed to declare something critical.
- giaour 4y agoWhat I meant by my reply is that PyPI is using "critical" as a label for packages that meet a specific criterion. I agree that "critical" as an English word can be rather vague, but it is not in this case. PyPI's interest here is in the integrity of accounts that can publish PyPI's most widely downloaded packages. If you believe based on the chosen label that in the future, PyPI will come in and expand the criteria for criticality, then I guess that's possible? But it's not what's happening now.
- samastur 4y agoIt's not arbitrarily because you've been told the criteria already. The problem you have is that you disagree with criteria which, well, not sure what to tell you except that there are no universal conditions everyone would agree to as clearly just demonstrated. PyPI maintainers selected their own, as they have every right to and they are not obviously stupid as they seem to be a reasonably good proxy for which packages would afflict most developers. Personally, as a developer who both publishes and uses packages from PyPI, I'd love to know who finds 2 minute 2FA set-up too burdensome (and if you save it in your password manager, that's all you'll every have to do) so I can avoid their packages. I have little faith in maintenance of packages for which a minimal one-time effort (per account, not even per package) is too big.
- protomyth 4y agoIt's not arbitrarily because you've been told the criteria already It's arbitrary because it doesn't seem to correspond to what is 'critical'. It might be an ok proxy, but I'm not really convinced of that either. I once again say I think everyone is being well intentioned, but I do not think they actually have enough information to build out a less than arbitrary criteria. Personally, as a developer who both publishes and uses packages from PyPI, I'd love to know who finds 2 minute 2FA set-up too burdensome (and if you save it in your password manager, that's all you'll every have to do) so I can avoid their packages. I have little faith in maintenance of packages for which a minimal one-time effort (per account, not even per package) is too big. If it is not burdensome, then they probably should of just required it from everyone going forward. It would have saved any debate as to singling out individuals for a higher maintenance demand.