Two-Factor Authentication Across Package Registries
- ID: 967aa06f
- 原文链接: https://nesbitt.io/2026/08/18/two-factor-authentication-across-package-registries.html
- Added: 2026-08-18
- Source: blog / Andrew Nesbitt
- Original Date: 2026-08-18
- AAIF Category: infra
- Quality Score: 5
- Status: active
- Source Type: article
- Language: en
- Tags: supply-chain, 2fa, package-registries, security, trusted-publishing
中文摘要
Nesbitt 按「账户身份来自哪里」把 ecosyste.ms 上包数过万的 registry 切成四档横向对比 2FA 进度:PyPI 是唯一全员强制(2024-01 起 TOTP/WebAuthn 都收,2022 年还发过 4000 把硬件 key);npm 走 cohort 强制、2026-08 关掉账户治理类操作的 2FA bypass;RubyGems 对累计下载 1.8 亿次以上 gem 强制;NuGet 2022 年起依托 MSA/AAD 最早一刀切;Maven Central 至今无 2FA,靠 PGP 签名管 artifact。CI 发包被 2FA 逼出 trusted publishing(PyPI 2023-04 落地,npm/crates.io 2025 跟进),npm 2026-05 GA 的 staged publishing 还要求版本经独立 2FA challenge 批准。这是 2026 供应链安全现状最实的一张表。
English Summary
Nesbitt slices the 2FA status of every package registry with >10k packages tracked by ecosyste.ms along "where does account identity come from": PyPI is the only fully mandatory one (and shipped 4000 hardware keys to top maintainers in 2022); npm enforces by cohort, closed the account-governance 2FA bypass in Aug 2026 per GitHub's supply-chain plan; RubyGems mandates 2FA for gems over 180M cumulative downloads; NuGet leaned on MSA/AAD earliest (new accounts forced since 2022-03); Maven Central still has no 2FA and relies on PGP signatures. 2FA at the publish stage squeezes CI into trusted publishing (PyPI 2023-04, RubyGems 2023-12, npm/crates.io 2025), and npm's staged publishing (GA 2026-05) adds a separate 2FA challenge before a version becomes installable.
原文要点(证据摘录)
- npm 2026-08: stopped accepting bypass-2FA tokens for account-governance actions, closing reusable-credential bypass routes (github.blog plan set out 2025-09).
- PyPI: mandatory for all since 2024-01 (TOTP/WebAuthn), 4000 hardware keys shipped 2022; trusted publishing since 2023-04.
- NuGet: 2FA verification tied to MSA/AAD, new accounts forced since 2022-03 — the earliest platform-wide cutover.
- Maven Central: still no client-side 2FA, PGP-signed artifacts; CocoaPods trunk email-token model, stops accepting new podspecs 2026-12-02.
- Evidence snapshot:
~/.hermes/evidence/ak-rss-digest/2026-08-18/01-nesbitt-2fa-registries.txt
来源 / Obsidian 引用
- 本机 Obsidian 同日材料:OpenClaw定时任务/AK-RSS-Digest(89源精选)/2026-08-18(评分 8.5/10)
- 评分依据:原文正文/官方 release body(不靠标题或源声誉)