Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Maybe even send a user an email notification with a link...


lol granted! But notice how in that universe since npm has to send the link, then access to the link is coupled to access to the email address, serving as an auth factor.

In the attack described above, the attacker did not have access to the victim's email address.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: