4 ms·
Pretty much this; There are some people who believe that efforts to improve supply chain security benefits only corporate or business users, and that individual
by 32gbsd 3y ago
Pretty much this; There are some people who believe that efforts to improve supply chain security benefits only corporate or business users, and that individual developers should not be asked to take on a uncompensated burden for their benefit.
- michaelt 3y agoIs 2FA much of a burden? I use 2FA on many of my accounts, and it's not that bad if you're only being prompted for it once a week or so.
- lhgpr 3y ago[flagged]
- arcanemachiner 3y agoDoes it not raise the threshold required to poison the supply chain? If so, can you inform me as to why this is not a good enough solution, such that you would warrant against the inclusion of 2FA as part of the process? Furthermore, since it's an attempt to solve a known and increasing problem, what do you suggest they do to resolve the issue? This seems some pretty open-and-shut low-hanging fruit to me. "At the expense of uploaders." Arguing against TOTP in 2023 just seems so ridiculous to me, especially for people savvy enough to publish a package on PyPI. I just don't get it.
- arcanemachiner 3y agoThis isn't the first time I've heard such a complaint. So, dumping hours upon hours of work into publishing a project on PyPI is fine, but setting up TOTP is where some people draw the line? To prevent against a commonly-exploited attack vector that is so simple to mitigate? Like... Really?
- teaearlgraycold 3y agoI doubt this person has any public packages on any repository
- arp242 3y agoThe difference is that one type of work is something you do of your own choosing, and the other type of work is enforced and you have no control over it. Not offering an opinion on whether it's good or bad that it's enforced, but that's the difference between the two.
- masklinn 3y agoTOTP is a bit of an annoyance though a pretty rare one all things considered as most sites have reasonable delays before they ask for re-authorising devices. The biggest issue is that as the number of sites in the Authenticator grows finding them becomes more annoying. Keys are a pain in the ass though, as their form factors usually make them impossible to keep attached to a laptop (as they snag and break if you forget to unplug them before putting the laptop in a bag), yet easy to lose if you’re not super careful. There are low-profile keys (yubikey’s nanos) but they’re not exactly cheap, and I’ve never seen one being given out (whereas I have free keys from older programs of github and google both). They’re all minor gripes, but they’re routine annoyances nonetheless, and as the number of sites requiring 2FA grows (rightfully so) the likelihood that you’ll meet a 2FA prompt every day closes in on 1. And there’s a handful of sites which are really shit about it, with way too aggressive requirements and way too short sessions. I’ve got great hopes for TPM WebAuthn.
- aniforprez 3y agoIt is very easy and convenient for your password manager to handle TOTP codes too. I personally have 1Password set up to also generate the codes and they automatically fill up on the websites or copy to the clipboard on mobile devices after filling out the normal passwords
- 32gbsd 3y agoI personally looking forward to 3fa where you need another person to verify that you are not a hacker. Overall it's a sign that these sites have lost the battle.
- arcanemachiner 3y agoJust so I'm understanding correctly, the "uncompensated burden" you're referring to is that someone has to activate 2FA?
- raverbashing 3y agoFor real, if a developer really feels like 2FA is a pain I can only imagine how quirky (in a bad way) their code should be
- trqs 3y ago[flagged]
- itronitron 3y agoMany people associate 2FA with being asked for a phone number, which makes it a burden.
- andybak 3y ago> Many people associate I presume package authors are likely to be rather better informed than this?
- arcanemachiner 3y agoI had to double check to make sure PyPI isn't implementing phone-number based 2FA. I then breathed a sigh of relief. https://nakedsecurity.sophos.com/2017/07/11/two-factor-via-your-mobile-phone-should-you-stop-using-it/ https://nakedsecurity.sophos.com/2017/07/11/two-factor-via-y...
- itronitron 3y agoThat article/advert you cite makes no reference to PyPI, so I'm not sure what your point is.
- deleted 3y ago