Hacker News new | ask | show | jobs
by Dunedan 303 days ago
> If your PyPI account only has a single verified email address from a custom domain name,add a second verified email address from another notable domain (e.g. Gmail) to your account.

Isn't that just increasing the attack surface for all account holders following that suggestion for all cases but domain expiry?