| ▲ | Tharre an hour ago | ||||||||||||||||
"Hey, let's take down all of npm, because there's a package that installs something malicious, and some people may install it without reviewing it first. The thousands of other people relying on this service can wait." Do you not realize how crazy of an request that is? | |||||||||||||||||
| ▲ | hypfer an hour ago | parent [-] | ||||||||||||||||
You do realize that the people relying on the service also get served wormable malware, right? The service is already disrupted. It is not that a disruption could be _avoided_. The discussion makes no sense. ___ Hell, even if I would be completely wrong in that assessment (not sure how, but let's assume that's the case) You can still put up a banner. "Hey, FYI: We're under attack". If not right away, then at the very least the moment media reports on it. And if media reported wrong, the banner says "Don't worry people. Media got it wrong." | |||||||||||||||||
| |||||||||||||||||