3 ms·
Its still not a great measure. A project with three downloads that are all from the credit rating agencies, or a project with 100 downloads from all banks woul
by protomyth 4y ago
Its still not a great measure. A project with three downloads that are all from the credit rating agencies, or a project with 100 downloads from all banks would be considered 'critical' by most folks.
- giaour 4y agoBut not by PyPI! Whoever is in charge of supply chain security at those credit rating agencies and banks should think long and hard about what they've gotten themselves into, though.
- protomyth 4y agoI'm a bit unclear about your response. My contention is that the method of determination of critical is based on something that really doesn't tell you how critical it is. I do believe the customer has a responsibility but I am not seeing any of that in PyPI's actions. Do I blame or think PyPI did anything wrong? No. I think everyone has the best intentions. I just think arbitrarily declaring someone work 'critical' without some involvement from the users of that developer's work is going to cause problems and not actually solve the issue. PyPI doesn't really have access to the information needed to declare something critical.
- giaour 4y agoWhat I meant by my reply is that PyPI is using "critical" as a label for packages that meet a specific criterion. I agree that "critical" as an English word can be rather vague, but it is not in this case. PyPI's interest here is in the integrity of accounts that can publish PyPI's most widely downloaded packages. If you believe based on the chosen label that in the future, PyPI will come in and expand the criteria for criticality, then I guess that's possible? But it's not what's happening now.
- samastur 4y agoIt's not arbitrarily because you've been told the criteria already. The problem you have is that you disagree with criteria which, well, not sure what to tell you except that there are no universal conditions everyone would agree to as clearly just demonstrated. PyPI maintainers selected their own, as they have every right to and they are not obviously stupid as they seem to be a reasonably good proxy for which packages would afflict most developers. Personally, as a developer who both publishes and uses packages from PyPI, I'd love to know who finds 2 minute 2FA set-up too burdensome (and if you save it in your password manager, that's all you'll every have to do) so I can avoid their packages. I have little faith in maintenance of packages for which a minimal one-time effort (per account, not even per package) is too big.
- protomyth 4y agoIt's not arbitrarily because you've been told the criteria already It's arbitrary because it doesn't seem to correspond to what is 'critical'. It might be an ok proxy, but I'm not really convinced of that either. I once again say I think everyone is being well intentioned, but I do not think they actually have enough information to build out a less than arbitrary criteria. Personally, as a developer who both publishes and uses packages from PyPI, I'd love to know who finds 2 minute 2FA set-up too burdensome (and if you save it in your password manager, that's all you'll every have to do) so I can avoid their packages. I have little faith in maintenance of packages for which a minimal one-time effort (per account, not even per package) is too big. If it is not burdensome, then they probably should of just required it from everyone going forward. It would have saved any debate as to singling out individuals for a higher maintenance demand.
- samastur 4y agoAs a non-native English speaker I will not argue about proper use of arbitrary. I will reiterate though that there is no universal criteria for what critical means and plausibly theirs (in sense that I am speculating) is not an unreasonable one: packages when compromised would affect the most and enough developers directly as they are the primary users of the packages and everyone else is downstream. Downloads admittedly are not a perfect measure as it is not a fixed ratio between number of developers and downloads, but it is again a reasonable one as it is highly unlikely that with expected power law distribution of popularity the top 1% would not be also widely used. The remaining quibble could be the cut off at 1% which I assume was derived from data and not an infatuation with 1. I doubt mandating 2FA for all would save any debate at all as it seems mainly to be centered on "why are they doing this to me" and not "why am I being singled out", but personally I certainly wouldn't have a problem if they did. I certainly would prefer to know which packages are better protected than others. There's also a reason why one wouldn't mandate it which is to make first steps in publishing easier for beginners with expected audience of only them. I also share James' perspective that our obligations change with other people relying on us. However even if you don't, you are not forced to accept it. You only won't be able to publish new versions of the package, but you can always rename it and publish that if 2FA is really such a burden.