The PyPI catalog has transitioned to mandatory two-factor authentication.

The developers of the Python package repository PyPI (Python Package Index) have announced the implementation of mandatory two-factor authentication for all users. Without enabling two-factor authentication, users will no longer be able to upload files or perform actions related to managing their projects. Previously, two-factor authentication was enforced for user accounts associated with at least one project or those involved in maintaining organization packages.

Implementing two-factor authentication will strengthen the development process's security and protect projects from malicious changes resulting from credential leaks, using the same password on a compromised site, local developer system breaches, or social engineering tactics. Gaining access via account takeover is one of the most significant threats, as a successful attack can lead to injecting malicious changes into other products and libraries that use the compromised package as a dependency.

The preferred method for two-factor authentication is a scheme based on hardware tokens compatible with the FIDO U2F specification and the WebAuthn protocol, which achieves a higher level of security compared to generating one-time passwords. In addition to tokens, applications for authentication based on one-time passwords that support the TOTP protocol can also be used, such as Authy, Google Authenticator, and FreeOTP. When uploading packages, developers are additionally advised to transition to using the 'Trusted Publishers' authentication method based on the OpenID Connect (OIDC) standard or to utilize API tokens.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster