6 ms·
Why is the 2fa rollout going at such a glacial pace ? In July last year it was announced that the top 1% projects contributors had to use 2fa. It it because of
by nightshift1 3y ago
Why is the 2fa rollout going at such a glacial pace ?
In July last year it was announced that the top 1% projects contributors had to use 2fa.
It it because of pushback from the developpers, or maybe because it is not as easy it it seems ?
I'm just curious, I am in now way involved in this.
- woodruffw 3y ago2FA itself has been deployed and available on PyPI for years, and has seen a decent amount of adoption. That part hasn't been glacial :-) Mandatory 2FA, on the other hand, is a little thorny: the Python packaging ecosystem has a lot of very popular, very stable packages that receive relatively few updates, meaning that it takes a long time to onboard those maintainers (without risking locking them out of their accounts or their abilities to do rapid security releases). Now that GitHub is mandating 2FA, however, the argument for slow-walking it becomes much weaker: the overwhelming majority of maintainers will need to enable 2FA anyways to make changes to their codebases, so PyPI can effectively "hitch" onto that wave and do a mandate at the same time. TL;DR: Moving hundreds of thousands of users to a mandatory 2FA scheme is relatively disruptive; the circumstances have aligned such that doing so now is minimally disruptive.
- nightshift1 3y agoInteresting, I kinda understand since I work for a big org where everything is very slow because of bureaucracy and fear of changes but here the big projects were already forced to use 2fa. It would seem logical to force the contributors to use good security practices right from the start. I would have probably started with those. Anyway, I don't want to complain. I believe its a good step towards securing the software supply chain. Keep up the good work.
- woodruffw 3y ago> It would seem logical to force the contributors to use good security practices right from the start. I would have probably started with those. I agree, but that's the benefit of hindsight :-) PyPI is simultaneously one of the oldest and most active language packaging ecosystems out there; a lot of of the things we treat as "table stakes" in terms of good security practices weren't even invented when it was first released. The consequence of all of this is that there's a lot of ossification, and things can't be changed suddenly without (reasonably!) upsetting a lot of people who are invaluable to the community. It'd be great in terms of security if we could just force it, but that wouldn't be fair to them, to their historical expectations, etc. Edit: I should say: I'm not a maintainer of PyPI, just someone who has contributed to it. My opinions aren't representative.
- predictabl3 3y ago> The consequence of all of this is that there's a lot of ossification, and things can't be changed suddenly without (reasonably!) upsetting a lot of people who are invaluable to the community. It'd be great in terms of security if we could just force it, but that wouldn't be fair to them, to their historical expectations, etc. I can't tell if you're being very overly generous to folks, or if there's something I'm really not considering. Given that I've been using a Yubikey, password manager, ssh-only auth, etc for ... idk, nearly a decade? Did it take a whole hour to learn + setup? Yes. Do I think that over time I've been more secure, and had to deal with less headaches from the repeated LastPass breaches, password leaks, compromises, etc? Oooh absolutely. --- Sorry Python ecosystem! Sorry a package was compromised by a careless dev. Pypi? Oh what about it? Why didn't it require basic security mechanisms to upload packages downloaded by literally tens of millions of users? Oh, we couldn't inconvenience lazy devs, come on now. I just can't with people. These things matter. Taking hard stances and making people uncomfortable sometimes IS NECESSARY. And to be clear, I'm not trying to come for your woodruffw (or the pypi team, god knows I've seen how HN acts with forced 2FA), I'm expressing a generous frustration that there doesn't seem to be a firewall where "general dev laziness" is overridden by idk, any sense of the commons, or any basic understanding that valuable assets WILL be attacked, passwords WILL be compromised and that some "root of trust" with something I physically can hold is pretty much required these days. LOL HN really does not like hearing inconvenient truths or truths that point out their blind/lazy spots.
- eesmith 3y ago> "general dev laziness" is overridden by idk ... Have you considered that perhaps you are the lazy one? You don't want to inspect the source code yourself for security holes, you don't want to pay someone to do it, and you don't want to establish a direct trust relationship (personal or legal) with the original developers. Instead, you want to trust automation and externalize blame. And you call others lazy? > ... any sense of the commons If you have any sense of the commons beyond past Hardin's simplistic and historically flawed argument advocating mandatory population control, then surely you can understand how PyPI admins are trying to balance the traditional commons use rights based on cooperation and responsibility with the needs of lazy people like you, while hopefully avoiding any devastating effects akin to how English land enclosure deprived commoners of their rights of access and privilege.