Security quotes of the week
— Lance R. Vick (Thanks to Paul Wise.)
- Buy expired NPM maintainer email domains.
- Re-create maintainer emails
- Take over packages
- Submit legitimate security patches that include package.json version bumps to malicious dependency you pushed
- Enjoy world domination.
Nuclear disarmament is “real geopolitics,” while the Internet is still, even now, seen as vaguely magical, and something that can be “fixed” by having the nerds yank plugs out of a wall.— Bruce Schneier and Tarah Wheeler
