npm: set up 2fa on your account
me: can't be bothered, it's not like I publish packages anyway
npm: 2fa! 2fa! 2fa!
me: FINE
<go to login page, enter username and password>
npm: For your security, we've sent a one-time password to your email address
me: <enter one-time password from email>
npm: 404
genius work, npm people.
What do OTP codes guard against that isn't dealt with by email-you-a-code-to-sign-in anyway? I'm in favour of adding more security than just "do you know a password", but if a site already emails you a code to confirm login, what extra security does an OTP app provide? It's more likely to break -- exporting 2fa OTP codes to new devices is still way too hard.
Is it really only "what if someone compromises your whole email account"? Which would be bad, yes, but for more reasons than npm.
@sil sending otp to the same email that gets password reset tokens gains nothing.
@sil answer: use the back up codes we gave you, or get a new account. Sometimes falling back to physical verification would be acceptable but it depends what were talking about securing. Some random site ? Just get a new account.
@sil you'd have to ask Microsoft they run npm
@falken if it's some random site where you don't care about abandoning the account and getting a new one... why bother having extra-secure 2fa OTP codes for it?