You know what would be nice? Having to opt into downloading a pypi package from any account that is less than 12 months old. This would kill typosquatting & give malicious package detectors enough time to find the bad before people install by accident.