Hacker News new | ask | show | jobs
by chmod775 10 days ago
Also ignores the common vector of the maintainer getting compromised and their credentials immediately being used to push malware.

Most maintainer are going to notice that themselves.

1 comments

Exactly, and the vast majority of the attack success is in a very short period of time.

It will make credential attacks much harder to pull off successfully and the returns from using them will drop pretty dramatically.