npm: set up 2fa on your account
me: can't be bothered, it's not like I publish packages anyway
npm: 2fa! 2fa! 2fa!
me: FINE
<go to login page, enter username and password>
npm: For your security, we've sent a one-time password to your email address
me: <enter one-time password from email>
npm: 404
genius work, npm people.
What do OTP codes guard against that isn't dealt with by email-you-a-code-to-sign-in anyway? I'm in favour of adding more security than just "do you know a password", but if a site already emails you a code to confirm login, what extra security does an OTP app provide? It's more likely to break -- exporting 2fa OTP codes to new devices is still way too hard.
Is it really only "what if someone compromises your whole email account"? Which would be bad, yes, but for more reasons than npm.
@sil sending otp to the same email that gets password reset tokens gains nothing.
@falken what happens if you lose your phone? Answer: you have to email everyone to get the codes reset. Your email account is the ultimate fallback.
@sil answer: use the back up codes we gave you, or get a new account. Sometimes falling back to physical verification would be acceptable but it depends what were talking about securing. Some random site ? Just get a new account.
@sil you'd have to ask Microsoft they run npm