Open Source Security

By Josh Bressers

PyPI: 2FA or not 2FA, that is the question

=> 🔊 Play episode (39 min) | Direct episode link | 💬 Share episode

Published July 17, 2022 7:00pm

Josh and Kurt talk about PyPI mandating two factor authentication for the top 1% of projects. It feels like a simple idea, but it's not when you start to think about it. What problems does 2FA solve? How common are these attacks? What are the second and third order effects of mandating 2FA? This episode should have something for everyone on all sides of this discussion to violently disagree with. Show Notes PyPI announcement NPM expired domains Morten Linderud Tweet Congratulations: We Now Have Opinions on Your Open Source Contributions

=> Return to podcast

Proxy Information
Original URL
gemini://rocketcaster.xyz/episode/9024742347
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
6230.708035 milliseconds
Gemini-to-HTML Time
1.681445 milliseconds

This content has been proxied by September (ba2dc).