logoalt Hacker News

alpinemantoday at 2:32 PM2 repliesview on HN

>> high-impact npm accounts are now put into a read-only mode for 72 hours when they change their email or use a 2FA recovery code. This delay allows maintainers time to respond and recover the account before their account can be used to start an attack.

'what time shall we put here?'

'what's the longest hangover you ever had?'

'let's put 72 hours'


Replies

lrvicktoday at 8:03 PM

I paid $8 for the recently expired email domain of the sole author of NPM package "foreach", so then control to ship any code I wanted to 70k companies was just a support ticket or password reset away. 72 hours would not make a difference here.

Talked to NPM about this when it went viral, and once again all they could say was enabling package signing, even optionally, would discourage inexperienced people from contributing packages as they would be pressured to learn basic security and key management.

Sorry, if you are unwilling to take 10 minutes to learn how to sign your code, you have no business maintaining software releases millions of people depend on. Full stop.

But NPM will not even make it -optional- and rejects all PRs to implement this going back a decade. So no one feels pressured into basic security. Cool.

Waterluviantoday at 3:10 PM

A weekend plus a day to deal with things seems like a decent minimum duration when it’s somewhat arbitrary what the right number is.

show 1 reply