Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
smw
31 days ago
|
parent
|
context
|
favorite
| on:
DuckDB NPM packages 1.3.3 and 1.29.2 compromised w...
Parent is exactly right! For critical infrastructure an un-phishable 2fa mechanism like passkeys or hardware token (FIDO2/yubikey) should be required! It would remove this category of attack completely.
Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: