Hacker News new | ask | show | jobs
by robbie-c 1581 days ago
> I don't like GitHub's security screener dismissing this report because of the "social engineering" aspect.

Agreed.

I get where it comes from, npm isn't responsible for individual contributors getting social-engineered, but this is much deeper than that, and part of the flaw is with npm's support allowing the password reset to go through.

1 comments

What do you suggest as an alternative to password reset based on the account email?
If you retired the email because the domain expired, maybe don't let it reset existing accounts. It's dead.