|
|
|
|
|
by pas
80 days ago
|
|
2FA was mandated by npm they had 2FA, but likely software TOTP (so it was either autofilled via 1password (or similar), or they were able to steal the seed) at this point I think publishing an npm app and asking people to scan a QR with it is the easiest way (so people don't end up with 1 actual factor) |
|
They won't do this, I have talked to them plenty of times about it. But, if they did, the supply chain attacks would almost entirely stop.