2
<p>checked the latest numbers and it turns out that software projects i started and maintained were downloaded, at the least, 8.3 billion times. that&#39;s b</p><p>terrifying</p>
<p><span class="h-card" translate="no"><a href="https://mastodon.social/@glyph" class="u-url mention">@<span>glyph</span></a></span> <span class="h-card" translate="no"><a href="https://hachyderm.io/@dalias" class="u-url mention">@<span>dalias</span></a></span> <span class="h-card" translate="no"><a href="https://orbital.horse/@emma" class="u-url mention">@<span>emma</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@mcc" class="u-url mention">@<span>mcc</span></a></span> I believe I have, yes; I&#39;ve been reading them as they came, and I gave them another skim just now (upsettingly, PyPI supports Webauthn but *not* passkeys?.. is that... how does that happen)</p>
<p><span class="h-card" translate="no"><a href="https://mastodon.social/@glyph" class="u-url mention">@<span>glyph</span></a></span> <span class="h-card" translate="no"><a href="https://hachyderm.io/@dalias" class="u-url mention">@<span>dalias</span></a></span> <span class="h-card" translate="no"><a href="https://orbital.horse/@emma" class="u-url mention">@<span>emma</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@mcc" class="u-url mention">@<span>mcc</span></a></span> </p><p>~7.8B for ipaddr.js on npm<br />~0.5B for parser on rubygems<br />probably a few more tens of millions here and there, i stopped counting after these two, it gives me anxiety</p>
<p><span class="h-card" translate="no"><a href="https://mastodon.social/@whitequark" class="u-url mention">@<span>whitequark</span></a></span> <span class="h-card" translate="no"><a href="https://hachyderm.io/@dalias" class="u-url mention">@<span>dalias</span></a></span> <span class="h-card" translate="no"><a href="https://orbital.horse/@emma" class="u-url mention">@<span>emma</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@mcc" class="u-url mention">@<span>mcc</span></a></span> I feel this burden quite heavily already and wow that is a _lot_ more than me :)</p>
<p><span class="h-card" translate="no"><a href="https://mastodon.social/@glyph" class="u-url mention">@<span>glyph</span></a></span> <span class="h-card" translate="no"><a href="https://hachyderm.io/@dalias" class="u-url mention">@<span>dalias</span></a></span> <span class="h-card" translate="no"><a href="https://orbital.horse/@emma" class="u-url mention">@<span>emma</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@mcc" class="u-url mention">@<span>mcc</span></a></span> something I find useful to keep in mind, for myself, is that I&#39;m in technology because it is an almost unbounded force multiplier</p><p>between various packages, software I wrote has been downloaded over _eight billion_ times</p><p>that&#39;s a lot of potential for malice.</p>
<p><span class="h-card" translate="no"><a href="https://mastodon.social/@whitequark" class="u-url mention">@<span>whitequark</span></a></span> I hope it&#39;s something good.</p>
<p><span class="h-card" translate="no"><a href="https://mastodon.social/@whitequark" class="u-url mention">@<span>whitequark</span></a></span> <span class="h-card" translate="no"><a href="https://hachyderm.io/@dalias" class="u-url mention">@<span>dalias</span></a></span> <span class="h-card" translate="no"><a href="https://orbital.horse/@emma" class="u-url mention">@<span>emma</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@mcc" class="u-url mention">@<span>mcc</span></a></span> I only have a small peek behind the curtain here (I am not involved, just friends with many people who are). before I start describing vague background vibes, have you read all the official comms? <a href="https://blog.pypi.org/posts/2024-01-01-2fa-enforced/" target="_blank" rel="nofollow noopener" translate="no"><span class="invisible">https://</span><span class="ellipsis">blog.pypi.org/posts/2024-01-01</span><span class="invisible">-2fa-enforced/</span></a></p>
<p><span class="h-card" translate="no"><a href="https://fosstodon.org/@deshipu" class="u-url mention">@<span>deshipu</span></a></span> reading this made me reach for alcohol</p>
<p><span class="h-card" translate="no"><a href="https://mastodon.social/@whitequark" class="u-url mention">@<span>whitequark</span></a></span> seriously, just stuff it in a single .exe file with py2exe and run it with wine, it&#39;s the only cross platform way</p>