|
|
|
|
|
by usr1106
1944 days ago
|
|
All code you install to your machine. System packages, Python packages in virtualenvs, scripts. I don't keep important private keys in my .ssh folder. Well, it's just security by obscurity. An educated, determined attacker would find them. But
some random malicious code would not immediately find them. I run the Web browser in firejail (Linux). |
|
If there is a bad actor that releases a widely using dependency, for sure it's going to be gone from npm quite fast most of the time! However, it'll take some time for it to get noticed, and people will invariably get affected.
You shouldn't bring an open honeypot to a place where bears can attack you easily, right?