Comment on You too can run malware from NPM (I mean without consequences)parentComments−nodesocket1yOr at a minimum support yubikey for 2fa.−mcintyre19941yThey do, I use a yubikey and it requires me to authenticate with it whenever I publish. They do support weaker 2fa methods as well, but you can choose.−worthless-trash1yOriginal author could be evil. 2fa does nothing.−jamesnorden1yIf my grandma had wheels she'd be a bike. You don't need to attack the problem from only one angle.−worthless-trash1yYour grandma is a bike then. The 2fa is going to solve nothing and any attacker worth their salt knows it.−singulasar1yunphishable 2fa would have prevented this specific case tho... what are you talking about?
Comments
Or at a minimum support yubikey for 2fa.
They do, I use a yubikey and it requires me to authenticate with it whenever I publish. They do support weaker 2fa methods as well, but you can choose.
Original author could be evil. 2fa does nothing.
If my grandma had wheels she'd be a bike. You don't need to attack the problem from only one angle.
Your grandma is a bike then. The 2fa is going to solve nothing and any attacker worth their salt knows it.
unphishable 2fa would have prevented this specific case tho... what are you talking about?