Live data from Hacker News

Compromising Angular via expired NPM publisher email domains

thehackerblog.com

81–82 of 82 posts

Re: Compromising Angular via expired NPM publisher email domains

#81
post #54

Earlier quoted context omitted.

You still can't tell whether a domain was automatically renewed at expiration by the owner or by an attacker. A lot of registrars will auto-renew at the expiration date, or close enough that you can't tell from WHOIS records.

Maybe there should be some metadata that indicates whether a renewal is approved by the previous owner. That might require some extra administration by domain registrars and probably couldn't be applied retrospectively, but it would be useful. The other place where this potentially matters is CAs issuing TLS certificates for domains that expire before the certificate does. If they detect that a domain they have issue…

You might as well use something out-of-band to verify emails, like PGP.

Re: Compromising Angular via expired NPM publisher email domains

#82
post #80
post #78

Earlier quoted context omitted.

That is like a fraction of a fraction of a fraction of people with own domains. I don't think that's relevant, at all.

Could you please clarify your point? I don’t understand the comment as is.

That we don't need to differentiate on that level.

We'd first have to differentiate people that write their password on post-its in an open environment. People that have the same password on all services etc.

Post reply on HN