10 ms·
PyPI Requires 2FA for New User Registrations
- toomuchtodo 3y agoHey Mike, can you support renaming secure authenticators (Two factor methods)? Github is a great example wrt UX around this specific experience: https://github.blog/wp-content/uploads/2023/07/key_list.png?w=768 https://github.blog/wp-content/uploads/2023/07/key_list.png?... (from https://github.blog/2023-07-12-introducing-passwordless-authentication-on-github-com/ https://github.blog/2023-07-12-introducing-passwordless-auth...). Appreciate the efforts to secure the software supply chain!
- miketheman 3y agoThanks for the suggestion! The image you showed is in regards to Passkeys, which PyPI doesn't support yet. For TOTP, we support a single entry, and can't set a custom name. For WebAuthn, we allow a custom label value, is that what you're looking for?
- toomuchtodo 3y ago> For WebAuthn, we allow a custom label value, is that what you're looking for? Yep! I don't see that option, but I'm probably just missing it. Thank you for the reply!
- tialaramex 3y agoCan you change it though? When I first added my tokens I wrote their brand name to identify them, but then I realised I might buy more from that brand, so, I changed to writing a colour, reasoning that when I buy new ones even if they've got an identical colour I can add a blob of nail polish or something, so "The Red One" is clearly this one, not that one. I don't use PyPI but I found it convenient to go back and fix places where I'd written like "Yubico". It's not a big thing, but it's also hopefully not difficult to implement.
- samcat116 3y agoHopefully they support Passkeys sometime soon.
- deleted 3y ago[deleted]
- miketheman 3y agoTurns out we already do! When setting up 2FA, select WebAuthN and create a label for your device. When prompted, follow directions on your device.
- woodruffw 3y agoThis has been a long time coming, and will keep PyPI closely aligned with improving practices on the source host side as well[1]. [1]: https://github.blog/2023-03-09-raising-the-bar-for-software-security-github-2fa-begins-march-13/ https://github.blog/2023-03-09-raising-the-bar-for-software-...
- jjgreen 3y agoI see the list of "management actions" does not explicitly include project or account deletion (after 2FA imposed), anyone know if those will be included?
- miketheman 3y agoProject deletion would fall under "management". Account deletion is excluded so you can elect to remove your account at any time.
- jjgreen 3y agoThanks -- but if you are the sole owner of project, what happens to those projects after account deletion? Some kind of orphan status?
- miketheman 3y agoIf you are the sole owner of a project, you can still delete the project. That's not great right now. There's a conversation topic that you might find interesting: https://discuss.python.org/t/stop-allowing-deleting-things-from-pypi/17227/71?u=dstufft https://discuss.python.org/t/stop-allowing-deleting-things-f...
- jjgreen 3y agoSorry, now I'm confused. Suppose it is 2nd Jan 2024, 2FA is now required, I have an account and a sole-owned project, I don't have 2FA. From above, I cannot delete the project because "Project deletion would fall under 'management'" and management requires 2FA, Or from above "you can still delete the project" so I can delete the project without 2FA? From reading around, one cannot delete an account if it has sole-owner projects (right?), so in the former case, one could not delete one's account without setting up 2FA to delete the project first, contrary to "you can elect to remove your account at any time"?
- thewataccount 3y agoAny chance of signed builds returning? It's bizarre to me that we would move _away_ from signed builds. 2FA means we can trust the person that logged in - but we still don't trust that PyPI is being honest (no offense).
- miketheman 3y agoNone taken :) PEP 458 describes the path forward for PyPI. https://peps.python.org/pep-0458/ https://peps.python.org/pep-0458/ Here's the in-progress roadmap: https://github.com/pypi/warehouse/issues/10672 https://github.com/pypi/warehouse/issues/10672 If there's particular issues you believe you could pick off to help achieve the goal, much appreciated!
- zimmerfrei 3y agoThat is not really a big improvement, as it just covers the threat of compromise for the CDN and any of proxies, but not of the PiPI infra itself. That is covered by PEP 480, which is already 9 years old: https://peps.python.org/pep-0480/ https://peps.python.org/pep-0480/ Too bad that PyPI (and pip) effectively killed PGP signatures under control of the developers (therefore truly end to end) even with the simple TOFU model, and without providing an alternative.
- woodruffw 3y ago> Any chance of signed builds returning? It's bizarre to me that we would move _away_ from signed builds. PyPI never supported "signed builds" in the first place. What it had was vestigial support for attaching PGP signatures to distributions; without a key or identity distribution mechanism, these signatures were virtually useless (and all public evidence indicates that they were, consequently, virtually unused). Note that attached signatures alone don't prevent dishonesty on PyPI's part: without identity pinning, a dishonest PyPI could replace a correctly signed distribution Foo with a correctly signed (and easily exploitable) distribution Bar during a user's retrieval. Every signature needs to be bound to both the distribution's content and its distribution name by some stable discoverable identity.
- arnon 3y agoPyPi let an old employer take over my account and hasn't been responding for nearly two years. They told me they'd investigate but have been ghosting me since. I sent several requests to have my account restored but they just won't answer.
- miketheman 3y agoSo sorry to hear that. I looked at our account recovery requests repo and didn't see anything from `arnon` or similar usernames. We have the published account recovery process here: https://pypi.org/help/#account-recovery https://pypi.org/help/#account-recovery Is that the process you've followed?
- arnon 3y agoThey reset my password and then changed the e-mail. The username remains the same and it is "arnon". I tried re-registering now to check your claim but it says the username is under use and I can't restore the password for it since they changed the e-mail to one of theirs. The last communication I got from PyPi was from Ee Durbin in 2022 saying: > Given this, it appears that someone from <redacted> utilized the @<redacted>.com email address associated with the account to take it over and obtain access to the <redacted> libraries that the arnon User owned. > We are discussing next steps internally. > -Ee Durbin > Director of Infrastructure > Python Software Foundation I've asked a couple of times for status updates as recently as this July and haven't heard back.
- nightshift1 3y agoWhy is the 2fa rollout going at such a glacial pace ? In July last year it was announced that the top 1% projects contributors had to use 2fa. It it because of pushback from the developpers, or maybe because it is not as easy it it seems ? I'm just curious, I am in now way involved in this.
- woodruffw 3y ago2FA itself has been deployed and available on PyPI for years, and has seen a decent amount of adoption. That part hasn't been glacial :-) Mandatory 2FA, on the other hand, is a little thorny: the Python packaging ecosystem has a lot of very popular, very stable packages that receive relatively few updates, meaning that it takes a long time to onboard those maintainers (without risking locking them out of their accounts or their abilities to do rapid security releases). Now that GitHub is mandating 2FA, however, the argument for slow-walking it becomes much weaker: the overwhelming majority of maintainers will need to enable 2FA anyways to make changes to their codebases, so PyPI can effectively "hitch" onto that wave and do a mandate at the same time. TL;DR: Moving hundreds of thousands of users to a mandatory 2FA scheme is relatively disruptive; the circumstances have aligned such that doing so now is minimally disruptive.
- nightshift1 3y agoInteresting, I kinda understand since I work for a big org where everything is very slow because of bureaucracy and fear of changes but here the big projects were already forced to use 2fa. It would seem logical to force the contributors to use good security practices right from the start. I would have probably started with those. Anyway, I don't want to complain. I believe its a good step towards securing the software supply chain. Keep up the good work.
- woodruffw 3y ago> It would seem logical to force the contributors to use good security practices right from the start. I would have probably started with those. I agree, but that's the benefit of hindsight :-) PyPI is simultaneously one of the oldest and most active language packaging ecosystems out there; a lot of of the things we treat as "table stakes" in terms of good security practices weren't even invented when it was first released. The consequence of all of this is that there's a lot of ossification, and things can't be changed suddenly without (reasonably!) upsetting a lot of people who are invaluable to the community. It'd be great in terms of security if we could just force it, but that wouldn't be fair to them, to their historical expectations, etc. Edit: I should say: I'm not a maintainer of PyPI, just someone who has contributed to it. My opinions aren't representative.
- superq 3y agounpopular thought perhaps, but with this many companies/teams mandating MFA (especially to technical people, who should already know how to create secure passwords, not use them on more than one site, not spread them around, etc): The pressure of all of these MFA inputs, especially for products that expire them even on a trusted device/browser, is eventually going to push people into the arms of convenient "password managers". This will effectively nullify the 'something you have' in MFA because it'll all be available on your one single device again. Even worse, it'll present multiple high-value targets now, from the centralized server/sync side (ie lastpass) down to individual devices. Put another way: if you're storing the passwords in the same place as the MFA secrets, then it's not actually MFA anymore. It's not that PyPI is wrong to do this, it's that the weight of everyone mandating MFA will eventually either push people away or force them to work around draconian or onerous security requirements.
- mplewis 3y agoWhen someone stores their MFA credential in a password manager, that only means that in the worst case, they are as insecure as someone with no MFA – right? This doesn't seem like a big problem to me for two reasons: 1. if they're using a password manager, they are likely to be using a better password 2. it's much more likely that someone has intercepted a single static password for a single website than, say, your 1Password vault password AND username AND secret key
- saithound 3y ago> When someone stores their MFA credential in a password manager, that only means that in the worst case, they are as insecure as someone with no MFA – right? Even if this was right (which I don't think it is under the threat model described by the OP: they claim, rightpy or wrongly, that the attack surface somehow increases when everybody adopts MFA), consider the protocol where you have to enter your password and cut off a lock of hair to authenticate. In the worst case, this is as insecure as someone who just enters their password without any hair cutting, but doesn't mean that adopting it would not be a big problem, or even a good thing overall (at the very least it would massively inconvenience bald people; there are parallels, it's not like MFA does not inconvenience certain people).
- insanitybit 3y agoAwesome stuff, I really hope others follow suit.
- angry_octet 3y agoWill there be a way to determine is a package has all owners 2FA enrolled? Maybe even a public key that is linked to the account? It would be good to have an API queryable mechanism linking identity with signing.
- woodruffw 3y agoBy the end of 2023, all users on PyPI will be required to enable some form of 2FA to perform packaging operations. So the distinction between has 2FA and not will become moot.
- TheBrokenRail 3y agoI hate these 2FA mandates. I don't use PyPI, but I do use GitHub, which has also announced a 2FA mandate. I use my GitHub account to make bug reports, small pull requests, and silly personal projects. It is not that important. I want to sacrifice security for convenience on it, and that should be my choice. I also do not agree with the argument this secures the supply chain because: 1. It ignores supply-chain attacks from people who already have repository access. 2. Most big companies (ie. Google) are probably already using 2FA. 3. And if people are automatically pulling code from random people/groups without checking it... maybe that's what actually needs to be banned.
- d4mi3n 3y agoI don’t really agree with your sentiment, but the points you make aren’t wrong. The big issue I see is with your last point: > 3. And if people are automatically pulling code from random people/groups without checking it... maybe that's what actually needs to be banned. Github does not have control over this but would largely be blamed for the fallout, regardless of how reckless some individuals may be. The best most orgs can do to avoid liability/risk is usually to make changes to things they control, even if it isn’t the best option. You see this sort of coping mechanism in all sorts of situations if you start looking for it.
- fsociety 3y agoUnfortunately even if you did not pull code from random groups, and instead curated your GitHub dependencies, you can still be caught by surprise when one person has a re-used password and no 2FA because “ugh it’s so inconvenient”. Nothing will fully secure the supply chain, but this certainly reduces risk and given the impact software has in today’s world it’s important.
- CatWChainsaw 3y agoI hate 2FA where it's not needed because it removes the last vestige of anonymous accounts.
- dankle 3y agoGood
- bombolo 3y agoI'm personally annoyed by 2FA. Most importantly, as a normal person, I'm more inclined to go through security hoops with internet banking and payments, and much less so for every single website that exists.
- Grimburger 3y agoHard disagree here, supply chain attacks are big business, it matters a lot more than a few thousand bucks in a savings account which can be easily reversed if stolen by crooks. PyPi isn't "every single website", it's full of modules powering a lot of the internet and other critical infrastructure. I have a hardware key for the 2FA on my meagre open source libraries, it takes 10 seconds to pull it out of my pocket and use it. Why is that a bad thing if it's enforced? It seems more like you have a UX problem here, there's solid open source TOTP software that come with browser extensions and are one click to use. SMS only can be a pain but many companies are moving away from that, albeit slowly.
- j16sdiz 3y ago(not OP) I understand why they are needed. I still dislike them. It’s like washing dishes. I understand why they need to be washed, how good a modern disk-washer can be ...and I still hate them.
- bombolo 3y agoI also ave a hardware key, I got it for free last year. It doesn't take 10 seconds. It takes remembering to keep it with me when I travel. Also with 2FA the risk of being permanently locked out of my account increases A LOT. With a bank or similar I can show up to their office, show my id and reset all access. With websites there is NOBODY responding. I've tried taking over an abandoned project on pypi for which I've done several contributions before the owner disappeared. Never got any response. So losing the keys means that I have to fork my own project :D
- CatWChainsaw 3y agoThis is KYC on steroids.
- pabs3 3y agoWonder if PyPI will ever get reproducible builds. https://reproducible-builds.org/ https://reproducible-builds.org/