@dalias @GossiTheDog Security Keys aren't draconian, they're easy to use and there's plenty of open source implementations (both software and hardware). Since LPMs aren't going to disappear overnight, they're really the only practical solution to such targeted phishing attacks.
Notices by Leo@ALLES (leoluk@chaos.social)
-
Embed this notice
Leo@ALLES (leoluk@chaos.social)'s status on Tuesday, 09-Sep-2025 05:49:51 JST
Leo@ALLES
-
Embed this notice
Leo@ALLES (leoluk@chaos.social)'s status on Tuesday, 09-Sep-2025 02:06:24 JST
Leo@ALLES
@GossiTheDog It's incredible that high profile targets like npm or GitHub STILL aren't enforcing Security Keys...