Hacker News new | ask | show | jobs
by jka 1437 days ago
It seemed clearly-written and thought-provoking to me; the author doesn't claim that 2FA is a burden, either.

Writing and distributing software should be straightforward so that everyone can participate. And consuming software should be safe so that people and infrastructure are protected. Finding a security model that achieves both should be the goal.

PyPi appear to have walked a reasonable line on this so far, and it's worth considering and discussing what the future could be like.

1 comments

Another reasonable point here is that pypi is also offering package owners ~$75 (edit: didn't realise they were sold in 1-packs now) in modern usb-c fido2 keys if you have one that is now marked as critical.