9 ms·
PyPI will require 2FA by the end of 2023
- 32gbsd 3y agoPretty much this; There are some people who believe that efforts to improve supply chain security benefits only corporate or business users, and that individual developers should not be asked to take on a uncompensated burden for their benefit.
- michaelt 3y agoIs 2FA much of a burden? I use 2FA on many of my accounts, and it's not that bad if you're only being prompted for it once a week or so.
- lhgpr 3y ago[flagged]
- arcanemachiner 3y agoDoes it not raise the threshold required to poison the supply chain? If so, can you inform me as to why this is not a good enough solution, such that you would warrant against the inclusion of 2FA as part of the process? Furthermore, since it's an attempt to solve a known and increasing problem, what do you suggest they do to resolve the issue? This seems some pretty open-and-shut low-hanging fruit to me. "At the expense of uploaders." Arguing against TOTP in 2023 just seems so ridiculous to me, especially for people savvy enough to publish a package on PyPI. I just don't get it.
- arcanemachiner 3y agoThis isn't the first time I've heard such a complaint. So, dumping hours upon hours of work into publishing a project on PyPI is fine, but setting up TOTP is where some people draw the line? To prevent against a commonly-exploited attack vector that is so simple to mitigate? Like... Really?
- teaearlgraycold 3y agoI doubt this person has any public packages on any repository
- arp242 3y agoThe difference is that one type of work is something you do of your own choosing, and the other type of work is enforced and you have no control over it. Not offering an opinion on whether it's good or bad that it's enforced, but that's the difference between the two.
- masklinn 3y agoTOTP is a bit of an annoyance though a pretty rare one all things considered as most sites have reasonable delays before they ask for re-authorising devices. The biggest issue is that as the number of sites in the Authenticator grows finding them becomes more annoying. Keys are a pain in the ass though, as their form factors usually make them impossible to keep attached to a laptop (as they snag and break if you forget to unplug them before putting the laptop in a bag), yet easy to lose if you’re not super careful. There are low-profile keys (yubikey’s nanos) but they’re not exactly cheap, and I’ve never seen one being given out (whereas I have free keys from older programs of github and google both). They’re all minor gripes, but they’re routine annoyances nonetheless, and as the number of sites requiring 2FA grows (rightfully so) the likelihood that you’ll meet a 2FA prompt every day closes in on 1. And there’s a handful of sites which are really shit about it, with way too aggressive requirements and way too short sessions. I’ve got great hopes for TPM WebAuthn.
- aniforprez 3y agoIt is very easy and convenient for your password manager to handle TOTP codes too. I personally have 1Password set up to also generate the codes and they automatically fill up on the websites or copy to the clipboard on mobile devices after filling out the normal passwords
- 32gbsd 3y agoI personally looking forward to 3fa where you need another person to verify that you are not a hacker. Overall it's a sign that these sites have lost the battle.
- arcanemachiner 3y agoJust so I'm understanding correctly, the "uncompensated burden" you're referring to is that someone has to activate 2FA?
- raverbashing 3y agoFor real, if a developer really feels like 2FA is a pain I can only imagine how quirky (in a bad way) their code should be
- trqs 3y ago[flagged]
- itronitron 3y agoMany people associate 2FA with being asked for a phone number, which makes it a burden.
- andybak 3y ago> Many people associate I presume package authors are likely to be rather better informed than this?
- arcanemachiner 3y agoI had to double check to make sure PyPI isn't implementing phone-number based 2FA. I then breathed a sigh of relief. https://nakedsecurity.sophos.com/2017/07/11/two-factor-via-your-mobile-phone-should-you-stop-using-it/ https://nakedsecurity.sophos.com/2017/07/11/two-factor-via-y...
- itronitron 3y agoThat article/advert you cite makes no reference to PyPI, so I'm not sure what your point is.
- deleted 3y ago
- jruohonen 3y agohttps://www.usenix.org/system/files/sec19-zimmermann.pdf https://www.usenix.org/system/files/sec19-zimmermann.pdf
- deleted 3y ago[deleted]
- lhgpr 3y ago[flagged]
- zoobab 3y agoVoila
- timthelion 3y agoWait, what? I'm so confused. How is this security theatre and how is it better to have curated packages than an open ecosystem when it comes to "hostility"?
- claviola 3y agoIt seems to me like your POV is that of an user. They're mandating that for publishers.
- raverbashing 3y ago> Homebrew and BSD solve this with simple checksums and curated packages. This is not what 2FA solve > Someone should offer Homebrew for Python Ah yes the package manager that updates several unrelated packages every time you install anything and doesn't allow rollbacks right? You're not even wrong
- jkukul 3y ago> Ah yes the package manager that updates several unrelated packages every time you install anything It's really annoying that it's doing it by default. To avoid this, add this to your `.bash_profile` / `.zshrc` / etc: export HOMEBREW_NO_AUTO_UPDATE=1
- raverbashing 3y agoThanks for this
- misnome 3y agohow do checksums help prevent people uploading new packages? Are you going to pay for people to manually curate the entire python ecosystem?
- pbhjpbhj 3y agoIs this an extension of the supposed NSL? Demands from USA TLAs to be able to match users to projects would seems to fit with the story as it was presented on HN (PyPI responded to a demand for all data, including use data, related to certain projects; https://news.ycombinator.com/item?id=36061407 https://news.ycombinator.com/item?id=36061407). Could equally come from the project, looking at their past HN stories they've had a lot of problems with malicious users. ID requirements might reduce that.
- eesmith 3y agoNo, it isn't an extension. It's been in the works for a while. PyPI started supporting 2FA 4 years ago (HN at https://news.ycombinator.com/item?id=20055340 https://news.ycombinator.com/item?id=20055340 ) and last year required 2FA for the most widely used accounts (HN at https://news.ycombinator.com/item?id=32058053 https://news.ycombinator.com/item?id=32058053 ). One of the objections about it at the time was on HN at https://news.ycombinator.com/item?id=32037562 https://news.ycombinator.com/item?id=32037562 . I think another Python dev didn't want to deal with 2FA and stopped the project, but I can't find that link. In any case, this multi-year phase-in is the sort of ratcheting steps you do when you want to make a change, and it's a big change, and you don't want a flag-day migration. Or, if you don't like it, you use the boiling frog apologue - https://en.wikipedia.org/wiki/Boiling_frog https://en.wikipedia.org/wiki/Boiling_frog .
- burningion 3y agohey ee just wanted to say thanks for all your work, you're doing so much for the python ecosystem. genuinely appreciate all you're doing, you're a great example for the rest of us.
- eesmith 3y agoI suspect you are confusing me for Ee Durbin, Director of Infrastructure at the PSF. I'm not doing anything for the Python ecosystem. I'm a Python developer, not part of core dev, PyPI, Python packaging, or anything ecosystem related.
- stefantalpalaru 3y agoThere is a command line tool for time-based one-time passwords, if you can get the relevant key from PyPI: https://www.nongnu.org/oath-toolkit/man-oathtool.html https://www.nongnu.org/oath-toolkit/man-oathtool.html This allows you to lose your phone without losing your account.
- badsectoracula 3y ago> What can I do to prepare? > > The most important things you can do to prepare are to enable 2FA for your account as soon as possible, either with a security device (preferred) or an authentication app and to switch to using either Trusted Publishers (preferred) or API tokens to upload to PyPI. So you either need to have a mobile phone (all of the linked applications[0] seem to require an Android or iOS device) or some custom device and they prefer you to rely on some 3rd party they call "Trusted Publisher"? Weren't private+public key signatures invented for solving pretty much this thing? They might be a bit complex for Mere Mortals but programmers should at least be able to figure them out. Am i missing something? EDIT: seems like TOTP is indeed similar to private+public key signatures (in that there is a shared secret to check against), can be done fully locally without requiring a phone or any 3rd party service and it just happened that the applications listed on the site were all for phones. [0] https://pypi.org/help/#totp https://pypi.org/help/#totp
- jjgreen 3y agoBummer, better delete my packages before I get locked out for good then.
- eesmith 3y agoIf you delete your package, can't someone else grab the namespace? I see that as the main issue if you want to migrate away from PyPI's management practices. Similarly, if you don't want to deal with PyPI at all, and host your own packages, then it's all too easy for someone else to register a package of the same name on PyPI. Users aren't used to configuring an alternate server.
- jjgreen 3y agoVery possibly, but I don't have a phone or a hardware key, and I'm certainly not going out and getting one for the benefit of PyPI, so my choices are? Having an outdated version of my packages on a locked-out account on PyPI (with the up-to-date sdists that I distribute on my website) sounds like a nightmare.
- macic 3y agoIs that so they can subpoena your phone number as well?
- di 3y agoPyPI has never supported 2FA via SMS.
- andybak 3y agoTOTP 2FA is fine if you either: a) are the only person who needs to use that login b) you can associate multiple logins with a single account. As far as I can see (b) is not true which means yet another case where a colleague has to phone me every time they need to login.
- e40 3y agoShared 1pw account with the totp from 1pw. Do it all the tine at work. edit: not shared account but a shared vault.
- deleted 3y ago[deleted]
- jadamson 3y agoYou can share the TOTP seed with colleagues (securely), and then enter it manually in your respective authentication apps. Or use an online password manager, as the other comment suggests.
- andybak 3y ago> You can share the TOTP seed with colleagues I hadn't thought of that!
- donaldstufft 3y agoYou can have multiple accounts associated with a single project, so each person can have their own account and you just add them all as owners to the projects. That can be annoying to keep in sync if you have a lot of projects, but we're rolling out organization support to make that easier for people.
- nologic01 3y agoAt some point surely people will realize that forcing the vast majority of people to be either an Apple customer or, worse, a Google product is not a viable design? Current day mobile devices, infested as they are with the dubious morality and regulatory malpractices that engineered the duopoly are horrible as digital identity providers and 2FA. 2FA is a function that is becoming essential for anybody that wants to participate in a digital life. A widely available and easy to use alternative is not a good to have it is absolutely essential. The implications of how 2FA is implemented go far beyond lovely PyPI. Entities like banks are deprecating specialized hardware in favor of the mobile. This is insane and odious.
- supriyo-biswas 3y agoYou can add TOTPs to a password manager like Keepass.
- arp242 3y agoTOTP is not tied to Google, Apple, or mobile phones in any way. It's an open specification and easy to understand and implement by anyone with even fairly junior skills. Some 2FA systems do require some specialized mobile app, but this is not one of them.
- nologic01 3y agoNot recognising slippery slopes early on is what leads to large scale social regression. As night follows day the next stage of 2FA will be biometrically based and there will be no escape route for "junior developers".
- donaldstufft 3y agoThere is zero chance we require biometrics on PyPI.
- BoppreH 3y agoI, for one, really appreciate this move. Supply chain attacks are huge problem, and package repositories are especially at risk. The options provided are very reasonable, and supporting TOTP ensures that even the most hardcore privacy and free-software enthusiasts are included. As a consumer and maintainer myself, PyPI has had a fair share of issues, but this is definitely not one of them.
- anthk 3y agopkgsrc, ports.tar.gz, guix... Seriously, stop reinveting the wheel.
- tomjen3 3y agoShould have focused on GPG signatures of packages instead. It doesn't matter who uploads, it matters what is uploaded.