Instead they took away TOTP as a factor.
Scaling security with the popularity of a repo does seem like a good idea.
Are there downsides to doing this? This was my first thought - though I also recognize that first thoughts are often naive.
TOTP isn't phishing resistant
TOTP seems effectively useless for npm so that seems fine to me
Are there downsides to doing this? This was my first thought - though I also recognize that first thoughts are often naive.