Hacker News new | ask | show | jobs
by staticassertion 1438 days ago
I assume/ hope that this is PyPI's first step in rolling out mandatory 2FA? Otherwise the whole "you're critical so you have to enable it" seems a bit silly in that you're going to have developers who get critical decide they don't want to do this, and at that point pull packages/ stop maintaining.

Just having a 2FA requirement from the start (or some grace period like 7 days) seems like the way to do it.