Live data from Hacker News

We all dodged a bullet

xeiaso.net

1–10 of 498 posts

Re: We all dodged a bullet

#4
post #2

Is it possible to do the thing proposed in the email without clicking the link? I just try to avoid clicking links in emails generally...

Should be - open another browser window and manually log into npm whatever, and update your 2fa there.

Definitely good practice .

Re: We all dodged a bullet

#5
> These kinds of dependencies are everywhere and nobody would even think that they could be harmful.

Tons of people think these kind of micro dependencies are harmful and many of them have been saying it for years.

Re: We all dodged a bullet

#6
Dat domain name.

Yeah, stop those cute domain names. I never got the memo on Youtu.be, I just had “learn” it was okay. Of course people started to let their guard down because dumbasses started to get cute.

We all did dodge a bullet because we’ve been installing stuff from NPM with reckless abandon for awhile.

Can anyone give me a reason why this wouldn’t happen in other ecosystems like Python, because I really don’t feel comfortable if I’m scared to download the most basic of packages. Everything is trust.

Re: We all dodged a bullet

#7
post #2

Is it possible to do the thing proposed in the email without clicking the link? I just try to avoid clicking links in emails generally...

Should be - open another browser window and manually log into npm whatever, and update your 2fa there. Definitely good practice .

This is the Way. To minimize attack surface, the senders of authentic messages should straight-up avoid putting links to "do the thing" in the message. Just tell the user to update their credentials via the website.

Re: We all dodged a bullet

#8
post #2

Is it possible to do the thing proposed in the email without clicking the link? I just try to avoid clicking links in emails generally...

Should be - open another browser window and manually log into npm whatever, and update your 2fa there. Definitely good practice .

That's what I always do. Never click these kinds of links in e-mail.

Always manually open the website.

This week Oracle Cloud started enforcing 2FA. And surely I didn't click their e-mail link to do that.

Re: We all dodged a bullet

#9
Always use password manager to automatically fill in your credentials. If password manager doesn't find your credentials, check the domain. On top of that, you can always go directly to the website, to make any needed changes there, without following the link.

Re: We all dodged a bullet

#10

Always use password manager to automatically fill in your credentials. If password manager doesn't find your credentials, check the domain. On top of that, you can always go directly to the website, to make any needed changes there, without following the link.

what do you mean bankofamericaabuse.com isn't a real website!? It's in the email and everything! The nice guy on the phone said it was legit...
Post reply on HN