2 ms·
That's a false dichotomy. The actual options are: 1. Dead project 2. You share access to lots of people and they act responsibly 3. You share access to lots
by RSZC 8y ago
That's a false dichotomy. The actual options are:
1. Dead project
2. You share access to lots of people and they act responsibly
3. You share access to lots of people and they act irresponsibly
#2 is waaaay more likely than #3.
Still seems to me like people are blaming the wrong person here. If you're writing a cryptocurrency-related module (the target of this specific attack) and you're using npm modules written by somebody you don't know, what the hell are you doing?
- bendmorris 8y ago#2 is more likely than #3 because a reasonable person gives access to another contributor or someone they spent a few minutes vetting, not a total stranger with no GitHub history.