3 ms·
PyPI supports TOTP 2FA: https://pypi.org/help/#totp https://pypi.org/help/#totp TOTP is defined in a freely available RFC (https://www.rfc-editor.org/rfc/rfc62
by giaour 4y ago
PyPI supports TOTP 2FA: https://pypi.org/help/#totp https://pypi.org/help/#totp
TOTP is defined in a freely available RFC (https://www.rfc-editor.org/rfc/rfc6238 https://www.rfc-editor.org/rfc/rfc6238) and is implemented by a wide variety of applications and libraries, both proprietary and open source.
- paganel 4y agoYes, I know, I've implemented it on the server side once, but I was curious why did Google (the company) feel the need to get involved with those thousands of physical dongles as long as almost any Android or iPhone can handle this, hence my question. Because I suppose there aren't thousands of contributors who don't have an iPhone nor an Android phone. Or maybe it's just a marketing ploy? I still don't get it.
- giaour 4y agoDongles are generally understood to be more secure than TOTP because they have to be physically stolen (unlike TOTP seeds, which are just information). Google is giving away thousands of physical keys maybe to drum up goodwill among the python community, maybe because it's a trivial expense for them and they have an institutional interest is seeing PyPI succeed. I dunno, but it doesn't really seem all that sinister. Just FYI, you don't need a smartphone to use TOTP. You can download 'pyotp' from PyPI and use it with any python interpreter. Anybody publishing packages to PyPI would have access to that.