4 ms·
I'm a top 500 package maintainer apparently (I think for my work on ts-loader but I'm not certain). This is great news. Some years ago an ethical hacker hacked
by johnny_reilly 4y ago
I'm a top 500 package maintainer apparently (I think for my work on ts-loader but I'm not certain).
This is great news. Some years ago an ethical hacker hacked me. I can still remember my shocked reaction upon being contacted by the hacker in question where I learned they now had the ability to publish malicious versions of npm packages on my behalf. This was long before supply chain attacks were well known and commonly discussed. A more innocent time.
The hacker in question gave me a simple piece of advice: turn 2FA on for your packages. Which I subsequently did. It's great that npm are pushing this. Yes it's a faff but the tradeoffs are net good. A little inconvenience is reasonable as compared to the alternative possibility.
I remain very grateful to the person who hacked me. If you should be out there: thanks - you did me a service
- GoblinSlayer 4y agoIf you give your otp to a phishing site, it might not login again, but it can retain this session cookie for as long as it's valid and use it for access all that time.
- Jnr 4y agoOn https://github.com/settings/security https://github.com/settings/security you can revoke other sessions.
- vladvasiliu 4y agoBut you have to specifically go looking for this. GitHub doesn't notify you when you open a new session from an unknown browser.
- totetsu 4y agoI'm always glad when the cookie I hard coded into my bash script curl command still works a year later.
- jimvdv 4y agoDo you use OTP codes? I recently switched to Yubikeys, find them to be much more convenient :)
- junon 4y agoWas the ethical hacker Chalker by any chance? They're wicked sharp and they're known for poking around us top npm-ers.
- johnny_reilly 4y agoI think it was, yes!
- junon 4y agoPwned me once as well. Very polite and professional. Got me to care a bit more about security back when I didn't! Glad to see the name come up :)
- jwilk 4y ago> Some years ago an ethical hacker hacked me. How did they do that?
- johnny_reilly 4y agoYears ago, when I was less security aware, I shared my password across different accounts. Not wise, but I know better now. One site that I used was hacked and my password compromised. The hacker was able to use that password to gain control of my npm account. Lesson learned.