Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
downrightmike
6mo ago
0 comments
Share
The NPM breach was an email that stated the dev needed to update their MFA by the next day in order to keep their access.
If you're arguing that is what ruby central should have done, that's a social engineering attack.
0 comments
default
newest
oldest
mrinterweb
6mo ago
How would a heads up email look like a phishing email? Blindsiding the maintainers like this is just cruel.
loloquwowndueo
6mo ago
It’s entirely possible to distinguish between legit internal communication and a phishing email. (It gets harder and harder every day but ultimately still possible)
j
/
k
navigate · click thread line to collapse