3 ms·
probably the most reasonable stopgap to this class of attacks is for npm to do more to encourage 2FA, with badges, etc, and introduce a warning on non-2FA insta
by micimize 8y ago
probably the most reasonable stopgap to this class of attacks is for npm to do more to encourage 2FA, with badges, etc, and introduce a warning on non-2FA installs.
- thephyber 8y agoOne of the notes on the ESLint postmortem[1] was that developers shouldn't reuse passwords and should use a password manager to facilitate making this easier. While I ack that 2FA would have prevented this incident, so would have using unique credentials. Note that using unique credentials is available at every SaaS service, not just the ones that support 2FA. [1] https://eslint.org/blog/2018/07/postmortem-for-malicious-package-publishes https://eslint.org/blog/2018/07/postmortem-for-malicious-pac...
- micimize 8y agoright, but 2FA usage is something npm can actually verify, so that we as package consumers can ask/receive some security guarantees from publishers.