Earlier quoted context omitted.
TOTP is a minuscule security win in exchange for a significant amount of inconvenience, versus using a good password manager. If you want to prevent password reuse, add an option to use a pre-generated password as an alternative to 2FA. I think the statement "these weaknesses are implementation specific", while true, is irrelevant when 99% of people affected by this mandate (and 99.9% of 2FA users in general) are goi…
The difference between a password manager and TOTP is that TOTP is something PyPI can enforce and a password manager is not. Yes, TOTP adds very little advantage when you have an already safe password. But there is no way for PyPI to know if you're doing that or not , and they can know if you're using 2FA. > 99% of people affected by this mandate (and 99.9% of 2FA users in general) are going to use an implementation…
But there is! Pre-generate a password for the user, instead of letting them supply one. This adds no extra inconvenience if you're already using a password manager, but it makes password reuse impossible.