>> high-impact npm accounts are now put into a read-only mode for 72 hours when they change their email or use a 2FA recovery code. This delay allows maintainers time to respond and recover the account before their account can be used to start an attack.
>> high-impact npm accounts are now put into a read-only mode for 72 hours when they change their email or use a 2FA recovery code. This delay allows maintainers time to respond and recover the account before their account can be used to start an attack.
'what time shall we put here?'
'what's the longest hangover you ever had?'
'let's put 72 hours'
Been quietly thinking this for years
[flagged]
the bare minimum award, for the only language and only registry where this regularly happens.