


















I think it's extremely funny that instead of forcing people to use 2FA to do uploads, they forced 2FA to login, and then you create a long lived all-powerful token and forget about 2FA.
I was doing uploads by typing in my password (not stored in any password manager), and now the only way I can do uploads (without moving my projects on a corporate-owned forge) is via a token which sits on my disk, ready to be stolen.
Google gave me an hardware token for free, but it only works for web login.
All of this effort and I'm now less secure than I was a few years ago. Which makes me strongly suspect that ballombe's take is the right one. USA is adding constraints to foreign companies forcing them to avoid any chinese software to be able to sell anything in USA…
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。