Re: pre-PEP: transition to release-file hosting at pypi site

Donald Stufft <[email protected]> Wed, 13 Mar 2013 13:06:08 -0400
Newsgroups gmane.comp.python.catalog
Message-ID <[email protected]>
On Mar 13, 2013, at 12:54 PM, Tres Seaver <[email protected]> wrote:

> Signed PGP part
> On 03/12/2013 03:57 PM, holger krekel wrote:
> > Nobody should be lead to think that PYPI is a trusted or reviewed
> > source of software even if we got rid of external hosting completely.
> 
> Amen.  I still boggle at the amount of "sky is falling" stuff here over
> MITM / external links / whatever, given the potential damaage from
> explicitly malicious uploads (trojans, viruses, whatever).  Package
> signing might help here, but only for consumers who willing to think hard
> enough about the problem to manage a web of trust (frankly, a vanishingly
> small minority).

Really now? Let's see I can easily protect against malicous uploads by only installing from trusted authors. I cannot easily prevent a MITM or a compromised external host if the tools don't protect me against it. Without the tooling and infrastructure moving to close this gap the only way to do it is to not use that tooling or infrastructure at all. Namely even if the author of the package is myself I cannot be secure installing it using the current toolchain and infrastructure unless I bend over backwards to make sure that no installable link appears anywhere in my long description, and I don't have a homepage, and I don't have a download url.

> 
> And then there are these problems:
> 
> - - Backward-imcompatible releases (even those which make appropriate
>   signals in their version numbers).
> 
> - - Removal of distributions / releases / projects.
> 
> - - Re-upload of new distributions which sliently replace previous
>   distributions *of the same release* ("Yes, Virginia, there are
>   people out there who do this").
> 
> which are deal-killers for the folks who want always-on, reliable,
> repeatable, automatic installation from PyPI (instead of creating their
> own indexes).
> 
> Adding HTTPS or removing external links does nothing to mitigate those
> issues.

Yes there are other problems, so let's just throw our hands in the air and say fuck it instead of iteratively working to secure the system.

> 
> 
> Tres.
> - -- 
> ===================================================================
> Tres Seaver          +1 540-429-0999          [email protected]
> Palladion Software   "Excellence by Design"    http://palladion.com
> 
> 
> _______________________________________________
> Catalog-SIG mailing list
> [email protected]
> http://mail.python.org/mailman/listinfo/catalog-sig

-----------------
Donald Stufft
PGP: 0x6E3CBCE93372DCFA // 7C6B 7C5D 5E2B 6356 A926 F04F 6E3C BCE9 3372 DCFA

_______________________________________________
Catalog-SIG mailing list
[email protected]
http://mail.python.org/mailman/listinfo/catalog-sig
signature.asc (application/pgp-signature, 841 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.19 (Darwin)

iQIcBAEBAgAGBQJRQLIBAAoJEG48vOkzctz69XwQALHx4vOJS+FiFN0gTtiVzS6D
E17LOaU4/iyeCdKVQxFTQGUXKbGtPblo/oqqqbY3HVKVLk1A1D8VZKD9h7r06q2j
AvtZ/KVJ4/QDqw+2k6b7q8Yya6yor/5Uu3Jma1YtbnzTVAre8GLDVaa1iNSSDIdi
CbGWcQeTCrH5fYel9hA909IJhWETthZ1XGMu4qmmuf/r65LDRUY7ToLlK5XUCltO
cIv2AQdNny28JjpQk20MaXuxD03W015l9Qk5tztpF86TOa1J/Ud2N13fWEReAh5N
8awtAlEO7qDGdVwIMXjynj9Ep2goCfDBvOAGuJGO+FuiWxexkrf6tWNXooMzohTL
n+xMJPCUHVQz2gbYZTXdKEpCSA8HDH8WoaleYZNuD6OxoiKsvYObDjqj7797O1Go
XSTrBMWmmJ0BTqIEn/2zPv8i9VB/MLaP/IBS23gm6mj+TRLtOd6w6ipASVhueSmW
tCx2DAgg5HhjS5Vpm3PB1auKmyLFuP/548YtOLrvYbHXEX4TFkaRHt6PB/5oYEru
Y4xlO9j8buF3P0TswM9DF6evw2TP1AMPcBX1JrYACIjLl5yGCaUB0EQSzdfC5Iuw
WQS/XTrOc9CTbSaVAUlGudLABtNqxhidnLkjqLT1nxpaTaC6uqn6taHasjZCieYS
3neK2HeeRTwG6ALOgqnl
=noK5
-----END PGP SIGNATURE-----