Re: Question from a Beginner
Sonic Emitter3000 <[email protected]> Thu, 23 Sep 2021 19:53:40 -0400
| Newsgroups | gmane.comp.python.distutils.devel |
|---|---|
| Message-ID | <CAODXCBzroBFxpwO48meOK=tk+WBMk-A8d1=S7yKW8_mWpa8APw@mail.gmail.com> |
--===============6699797128018038512== Content-Type: multipart/alternative; boundary="000000000000bb23ae05ccb25740" --000000000000bb23ae05ccb25740 Content-Type: text/plain; charset="UTF-8" Awesome, thanks for the information. On Thu, Sep 23, 2021, 2:11 PM Steve Dower <[email protected]> wrote: > The main thing for you to do is to double-check all the names you type > in *before* you install anything. Most of the "security" issues come > down to people trying to catch misspellings ("typo-squatting"), so if > you've spelled everything correctly, you'll get the packages you expected. > > If you don't even trust *those* packages, or their dependencies, you're > signing up for a whole lot more work (reviewing code, manually creating > a private mirror, curation, etc.). Ultimately it will be up to you to > decide who you trust and how much you trust them. > > I believe the infrastructure itself to be trustworthy, and most of the > people publishing popular packages are trustworthy. But ultimately > you're on your own right now for detecting impersonation. > > Cheers, > Steve > > On 9/17/2021 5:13 PM, Sonic Emitter3000 wrote: > > Hello, hope you're doing well. I greatly appreciate the effort of you > > people to make open source projects like you do, but I must ask. > > > > I have heard that security is quite lax when installing modules using > > the most popular sites for Python modules. Would you know of how I would > > protect myself more from potentially malicious fakes of popular Python > > modules? > > > --000000000000bb23ae05ccb25740 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto">Awesome, thanks for the information.=C2=A0</div><br><div = class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, Sep 23,= 2021, 2:11 PM Steve Dower <<a href=3D"mailto:[email protected]">st= [email protected]</a>> wrote:<br></div><blockquote class=3D"gmail_quo= te" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"= >The main thing for you to do is to double-check all the names you type <br= > in *before* you install anything. Most of the "security" issues c= ome <br> down to people trying to catch misspellings ("typo-squatting"), s= o if <br> you've spelled everything correctly, you'll get the packages you ex= pected.<br> <br> If you don't even trust *those* packages, or their dependencies, you= 9;re <br> signing up for a whole lot more work (reviewing code, manually creating <br= > a private mirror, curation, etc.). Ultimately it will be up to you to <br> decide who you trust and how much you trust them.<br> <br> I believe the infrastructure itself to be trustworthy, and most of the <br> people publishing popular packages are trustworthy. But ultimately <br> you're on your own right now for detecting impersonation.<br> <br> Cheers,<br> Steve<br> <br> On 9/17/2021 5:13 PM, Sonic Emitter3000 wrote:<br> > Hello, hope you're doing well. I greatly appreciate the effort of = you <br> > people to make open source projects like you do, but I must ask.<br> > <br> > I have heard that security is quite lax when installing modules using = <br> > the most popular sites for Python modules. Would you know of how I wou= ld <br> > protect myself more from potentially malicious fakes of popular Python= <br> > modules?<br> > <br> </blockquote></div> --000000000000bb23ae05ccb25740-- --===============6699797128018038512== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- Distutils-SIG mailing list -- [email protected] To unsubscribe send an email to [email protected] https://mail.python.org/mailman3/lists/distutils-sig.python.org/ Message archived at https://mail.python.org/archives/list/[email protected]/message/S3NQFRSRAMIKF6FWBLALPBQ4GBSM4HI5/ --===============6699797128018038512==--