3 ms·
But if ABD and ABC are both package names in the system, then in order to present that warning we have to do some sort of resolution process to determine whethe
by sheac 10y ago
But if ABD and ABC are both package names in the system, then in order to present that warning we have to do some sort of resolution process to determine whether one is typosquatting.
Now that there's a strategy for finding fakers:
1) You have an attacker-defender arms race. The attacker will always be one step ahead of the defender.
2) You have the extra burden of keeping up in this race, otherwise your security feature is a facade. At best, this is useless. At worst, it lulls your users into a false sense of security.
- zardeh 10y agoI feel like "pick the more popular package" is a good enough solution in this case.
- sheac 10y agoCool. Attacker-defender race is on! As attacker, my next strategy is create a bunch of agents (<10K should be enough) to download my typo packages. Your move, defender ;) But seriously, my point has less to do with the particular tactics of the adversaries and more to do with how the proposed strategy of automatically detecting potential typos invites gaming.
- zardeh 10y agoPerfect, if each of those 10K hosts downloads the library 100 times you can now typo-attack the zope.event (working in python) library, which gets ~100 downloads per day, many of which are automated and so invulnerable to your attack. Your attack vector gets you, we'll say 1 new hit every 2 days at most, and likely only one a week or so (according to some math, on `requst` vs. requests)