Tag
A tweet recommends using hardware security keys like Yubikey for SSH keys, referencing an active cross-ecosystem supply chain attack (TrapDoor) on npm, PyPI, and Crates.io involving malicious packages and crypto-stealing malware.
The post argues that static credentials like SSH keys and API tokens are no longer sufficient, and identity-based access is a better alternative.