|
|
|
|
|
by psychoslave
275 days ago
|
|
How will multi-factor-authentication prevent such a supply chain issue? That is, if some attacker create some dummy trivial but convenient package and 2 years latter half the package hub depends on it somehow, the attacker will just use its legit credential to pown everyone and its dog. This is not even about stilling credentials. It’s a cultural issue with bare blind trust to use blank check without even any expiry date. https://en.wikipedia.org/wiki/Trust,_but_verify |
|