Hacker News
new
past
comments
ask
show
jobs
points
by
erikerikson
8 hours ago
|
comments
by
mayhemducks
6 hours ago
|
next
[-]
Are there downsides to doing this? This was my first thought - though I also recognize that first thoughts are often naive.
reply
by
staticassertion
5 hours ago
|
parent
|
next
[-]
You don't want "project had X users so it's less safe" to suddenly transition into "now this software has X*10 users so it has to change things", it's disruptive.
reply
by
erikerikson
5 hours ago
|
parent
|
prev
|
[-]
TOTP although venerable was better than no second factor at all.
reply
by
moebrowne
5 hours ago
|
prev
|
next
[-]
TOTP isn't phishing resistant
reply
by
erikerikson
5 hours ago
|
parent
|
[-]
No it's not but it's better than nothing. Don't let the perfect be the enemy of the good.
reply
by
staticassertion
5 hours ago
|
prev
|
[-]
TOTP seems effectively useless for npm so that seems fine to me
reply