upvote
Instead they took away TOTP as a factor.

Scaling security with the popularity of a repo does seem like a good idea.

reply
Are there downsides to doing this? This was my first thought - though I also recognize that first thoughts are often naive.
reply
You don't want "project had X users so it's less safe" to suddenly transition into "now this software has X*10 users so it has to change things", it's disruptive.
reply
TOTP although venerable was better than no second factor at all.
reply
TOTP isn't phishing resistant
reply
No it's not but it's better than nothing. Don't let the perfect be the enemy of the good.
reply
TOTP seems effectively useless for npm so that seems fine to me
reply