Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
zokier
60 days ago
|
parent
|
context
|
favorite
| on:
DuckDB NPM packages 1.3.3 and 1.29.2 compromised w...
But in the same vein the phishing email can easily be gpg signed too. The problem is to check if the gpg key used to sign the email is legitimate, but that is exactly the same problem as checking if the from address is legitimate.
Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: