|
|
|
|
|
by pixl97
11 days ago
|
|
>think this is eventually becoming some type of pointless arms race, as cooldown does not act actively towards reducing ecosystem attacks. The nature of some of these attacks, it does. If your developers machine with publishing rights gets rooted a cool down makes credential gathering attacks via script in npm so very much harder it's not even funny. In some of the recent supply chain attacks the entire fiasco was only a few hours long, but in that time tens of hundreds of thousands of credentials may have been stolen. One day timers have the weakness of weekends and holidays reducing the number of eyes/systems seeing the issue. |
|
- Independent security companies are scanning the packages (be careful if the project is depending on some no-so-popular packages)
- Maintainers react promptly (it would be nonsense if people need to cooldown for 21 days because people may have 21-day vacations)