logoalt Hacker News

dec0dedab0deyesterday at 1:50 PM1 replyview on HN

github, pypi, npm, homebrew, cpan, etc etc. should adopt a multi-multi-factor authentication approach for releases. Maybe have it kick in as a requirement after X amount of monthly downloads.

Basically, have all releases require multi-factor auth from more than one person before they go live.

A single person being compromised either technically, or by being hit on the head with a wrench, should not be able to release something malicious that effects so many people.


Replies

worksonmineyesterday at 2:01 PM

And how would that work for single maintainer projects?

show 1 reply