▲ | SchemaLoad 3 days ago | ||||||||||||||||||||||
2FA is a huge benefit over plain passwords. But it wasn't enough here. The package dev had 2FA and it did not help since they got tricked in to logging in to a phishing page which proxied the 2FA code to the real login page. | |||||||||||||||||||||||
▲ | bbarnett 3 days ago | parent [-] | ||||||||||||||||||||||
Yet the parent said for each upload prior to publish. This attack would have 100% been thwarted, when a load of emails appeared saying "publish package you just uploaded?". (if you read the dev's account of this, you'll see this would have worked) | |||||||||||||||||||||||
|