← Back to context

Comment by NooneAtAll3

3 months ago

is there an actual habituation?

that message feels like it could work as a first-time as well

We should be immediately suspicious when we get any solicitation to "renew" something "expired" in a security domain. Swapping un-compromised secrets is essentially always more risky than leaving them be.

Regardless of whether the real NPM had done this in the past, decades of dumb password expiration policies have trained us that requests like this are to be expected rather than suspected.