top | item 46647033

Why is NPM getting rid of TOTP as 2FA authentication method?

3 points| whicks | 1 month ago |github.com

1 comment

order

entuno|1 month ago

Does NPM require MFA to be used?

If so I could understand this (although there are certainly arguments to have had about it). But if they allow accounts without MFA then this would seem counterproductive, because while TOTP has issues it's a lot better than nothing.