Episode 332 - PyPI: 2FA or not 2FA, that is the question episode artwork

EPISODE · Jul 18, 2022 · 39 MIN

Episode 332 - PyPI: 2FA or not 2FA, that is the question

from Open Source Security

Josh and Kurt talk about PyPI mandating two factor authentication for the top 1% of projects. It feels like a simple idea, but it's not when you start to think about it. What problems does 2FA solve? How common are these attacks? What are the second and third order effects of mandating 2FA? This episode should have something for everyone on all sides of this discussion to violently disagree with. Show Notes PyPI announcement NPM expired domains Morten Linderud Tweet Congratulations: We Now Have Opinions on Your Open Source Contributions

Episode metadata supplied by the publisher feed · Published Jul 18, 2022

Embed this episode

Ready to play

Episode 332 - PyPI: 2FA or not 2FA, that is the question

0:00 39:01

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Open Source Security?

This episode is 39 minutes long.

When was this Open Source Security episode published?

This episode was published on July 18, 2022.

Can I download this Open Source Security episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!