▲ | rtpg 4 days ago | |||||||||||||||||||||||||||||||
I have a hard time arguing that 2FA isn't a massive win in almost every circumstance. Having a "confirm that you have uploaded a new package" thing as the default seems good! Someone like npm mandating that a human being presses a button with a recaptcha for any package downloaded by more than X times per week just feels almost mandatory at this point. The attacks are still possible, but they're not going to be nearly as easy here. | ||||||||||||||||||||||||||||||||
▲ | SchemaLoad 3 days ago | parent [-] | |||||||||||||||||||||||||||||||
2FA is a huge benefit over plain passwords. But it wasn't enough here. The package dev had 2FA and it did not help since they got tricked in to logging in to a phishing page which proxied the 2FA code to the real login page. | ||||||||||||||||||||||||||||||||
|