PyPI does not use SMS 2FA. It only supports WebAuthn (which is preferred) and TOTP.
Source: I implemented PyPI’s 2FA.
Source: I implemented PyPI’s 2FA.
Hope these comments don’t make you go crazy. It’s always fun and frustrating to see an area you are extremely familiar with being discussed by those unfamiliar.
fun in this comment thread.
That being said: the PyPI maintainers are also in this community, also doing largely thankless work to keep one of the world’s biggest package indices healthy (and secure). Their motives are good, and (IMO) the rollout here walks the right line between imposition and changes that are necessary to match the prevailing winds in supply chain security.