We all dodged a bullet
xeiaso.net
We all dodged a bullet
1–10 of 498 posts
Re: We all dodged a bullet
#2I just try to avoid clicking links in emails generally...
Re: We all dodged a bullet
#3NPM debug and chalk packages compromised
Re: We all dodged a bullet
#4Is it possible to do the thing proposed in the email without clicking the link? I just try to avoid clicking links in emails generally...
Definitely good practice .
Re: We all dodged a bullet
#5Tons of people think these kind of micro dependencies are harmful and many of them have been saying it for years.
Re: We all dodged a bullet
#6Yeah, stop those cute domain names. I never got the memo on Youtu.be, I just had “learn” it was okay. Of course people started to let their guard down because dumbasses started to get cute.
We all did dodge a bullet because we’ve been installing stuff from NPM with reckless abandon for awhile.
Can anyone give me a reason why this wouldn’t happen in other ecosystems like Python, because I really don’t feel comfortable if I’m scared to download the most basic of packages. Everything is trust.
Re: We all dodged a bullet
#7Is it possible to do the thing proposed in the email without clicking the link? I just try to avoid clicking links in emails generally...
Should be - open another browser window and manually log into npm whatever, and update your 2fa there. Definitely good practice .
Re: We all dodged a bullet
#8Is it possible to do the thing proposed in the email without clicking the link? I just try to avoid clicking links in emails generally...
Should be - open another browser window and manually log into npm whatever, and update your 2fa there. Definitely good practice .
Always manually open the website.
This week Oracle Cloud started enforcing 2FA. And surely I didn't click their e-mail link to do that.
Re: We all dodged a bullet
#9Re: We all dodged a bullet
#10Always use password manager to automatically fill in your credentials. If password manager doesn't find your credentials, check the domain. On top of that, you can always go directly to the website, to make any needed changes there, without following the link.