Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

PyPI brings in mandatory 2FA for all software publishers following recent security issues

  • May 30, 2023
Total
0
Shares
0
0
0


PyPI has announced that all users who maintain a project or organization on the platform must now set up two-factor authentication in an effort to increase security.

This follows previous measures set out by PyPI, including optional 2FA, blocking compromised passwords, support for API tokens, and mandatory 2FA for certain projects.

This comes just days after some new registrations were suspended on the platform following an excess of malicious code, impersonation, and other security concerns.

2FA for PyPI

Many users are likely to have a six-month window to apply the additional authentication measure to their account, with plans drawn up to make 2FA mandatory by the end of this year. The Python repository’s official blog post explains more:

“Between now and the end of the year, PyPI will begin gating access to certain site functionality based on 2FA usage. In addition, we may begin selecting certain users or projects for early enforcement.”

The post continues to detail the preferred method of authentication – physical devices – though authenticator apps and other services remain supported. Uploads should be done via trusted publishers or API tokens to ensure optimal security, too.

When posing itself the question of why not all users should be forced to use 2FA, PyPI says: “an account without access to any project cannot be used to attack anyone 2 so it is a very low value target.”

Among the numerous reasons given for employing mandatory 2FA, PyPI calls out GitHub for taking similar steps, as well as funding that enabled the hiring of a PyPI Safety and Security Engineer.

As two- and multi-factor authentication become increasingly important for securing accounts, many have slated SMS-based authentication for its inferior security and reliance on cellular service. Then, there is the gradual rollout of passwordless passkeys, which is slowly building traction after a delayed start.


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

Arcimoto’s latest teeny-tiny EV is all work and no play

  • May 30, 2023
View Post
Next Article
  • Technology

Sorry, but Alexa can no longer talk like Samuel L Jackson

  • May 30, 2023
View Post
You May Also Like
View Post
  • News

Quordle today – hints and answers for Sunday, October 1 (game #615)

  • September 30, 2023
View Post
  • News

Mortal Kombat 1 creator teases that a host of terrifyingly familiar faces may be on the way

  • September 30, 2023
View Post
  • News

Google Pixel Buds Pro leak gives us an early look at some new colors

  • September 30, 2023
View Post
  • News

The Pokémon Company apologizes and blames “overwhelming demand” for its Van Gogh collab stock issues

  • September 30, 2023
View Post
  • News

Your next laptop could run faster, last longer and pack more memory thanks to Samsung’s revolutionary new technology — but it won’t be cheap

  • September 30, 2023
View Post
  • News

Early iPhone 16 leak hints at larger screens for the Pro and Pro Max models

  • September 30, 2023
View Post
  • News

Bad news – turns out even long passwords can be cracked easily

  • September 30, 2023
View Post
  • News

AMD has a new trick to make games run smoother – but only for RX 7000 GPUs

  • September 30, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.