You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: Gathering-weak-npm-credentials.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -20,7 +20,7 @@ If your token/password was revoked, it means that at least one of these cases ha
20
20
21
21
And once again: **npm wasn't breached — your credentials came up from somewhere else**. You could check [haveibeenpwned.com](https://haveibeenpwned.com/) to get a hint on that.
22
22
23
-
Note that apart a few accounts that asked for that, I did not point npm to the specific leaks through other services — some of those are sensitive, and because of that I didn't want to include specific sources for everyone. That said, I included the links to specific files on GitHub for npm credentials leaks through GitHub, and I labeled the weak/dictionary passwords as being weak — so npm support should have that data.
23
+
Note that apart from a few accounts that asked for that, I did not point npm to the specific leaks through other services — some of those are sensitive, and because of that I didn't want to include specific sources for everyone. That said, I included the links to specific files on GitHub for npm credentials leaks through GitHub, and I labeled the weak/dictionary passwords as being weak — so npm support should have that data.
24
24
25
25
If you still have questions that you _really_ want to be answered after checking with [haveibeenpwned.com](https://haveibeenpwned.com/) — contact me in Gitter, either in the [public room](https://gitter.im/chalker-notes) for common questions or [privately](https://gitter.im/ChALkeR). I will not be able to respond by email on this, and it will be harder for me to respond in IRC (Gitter accounts are linked to GitHub, so I can be reasonably sure to whom I am speaking).
0 commit comments