logoalt Hacker News

erikeriksonyesterday at 2:12 PM3 repliesview on HN

Instead they took away TOTP as a factor.

Scaling security with the popularity of a repo does seem like a good idea.


Replies

mayhemducksyesterday at 4:01 PM

Are there downsides to doing this? This was my first thought - though I also recognize that first thoughts are often naive.

show 2 replies
moebrowneyesterday at 4:20 PM

TOTP isn't phishing resistant

show 1 reply
staticassertionyesterday at 4:54 PM

TOTP seems effectively useless for npm so that seems fine to me