24 ms·
Just want to agree with everyone who is thanking you for owning up (and so quickly). Got phished once while drunk in college (a long time ago), could have been
by winwang 1y ago
Just want to agree with everyone who is thanking you for owning up (and so quickly). Got phished once while drunk in college (a long time ago), could have been anyone. NPM being slowish to get back to you is a bit surprising, though. Seems like that would only make attacks more lucrative.
- internetter 1y agoin general npm does a not-too-great job with these things
- tripplyons 1y agoRemember, NPM stands for Now Part of Microsoft! (Microsoft owns GitHub, which owns NPM.)
- thayne 1y agoWhich means they don't have the excuse of being a volunteer effort to not be on top of this. MS has plenty of resources.
- dabockster 1y agoIf you're running this kind of infrastructure online these days, you have every right to require payment somehow. Don't work for free.
- wer232essf 1y ago[dead]
- deleted 1y ago[deleted]
- sneak 1y agoCan happen to anyone… who doesn’t use password manager autofill and unphishable 2FA like passkeys. Most people who get phished aren’t using password managers, or they would notice that the autofill doesn’t work because the domain is wrong. Additionally, TOTP 2FA (numeric codes) are phishable; stop using them when U2F/WebAuthn/passkeys are available. I have never been phished because I follow best practices. Most people don’t.
- junon 1y agoI use a password manager. I was mobile, the autofill stuff isn't installed as I don't use it often on my phone. In 15 years of maintaining OSS, I've never been pwned, phished, or anything of the sort. Thank you for your input :)
- ants_everywhere 1y agosounds like you should use it on your phone then
- bingabingabinga 1y ago> In 15 years of maintaining OSS, I've never been pwned, phished, or anything of the sort. Well, until now.
- typpilol 1y agoI just don't get how you didn't look for an announcement about npm resetting 2fa. Especially when you get a random reset
- acdha 1y agoBecause you’re one person with a job which isn’t security, and the world is full of legitimate warnings from companies telling you that you must do something by an arbitrary deadline? They screwed up, but we have thousands of years of evidence that people make mistakes even when they really know better and the best way to prevent that is to remove places where a single person making a mistake causes a disaster. On that note, how many of the organizations at risk do you think have contributed a single dollar or developer-hour supporting the projects they trust? Maybe that’s where we should start looking for changes.