4 ms·
This isn't, in any way, a new problem. I did a presentation on this topic for OWASP AppSecEU 2015 (https://www.youtube.com/watch?v=Wn190b4EJWk&list=PLpr-xdpM8w
by raesene6 9y ago
This isn't, in any way, a new problem. I did a presentation on this topic for OWASP AppSecEU 2015 (https://www.youtube.com/watch?v=Wn190b4EJWk&list=PLpr-xdpM8wG-ZTcHhFfAeBthNVZVEtkg9&index=10 https://www.youtube.com/watch?v=Wn190b4EJWk&list=PLpr-xdpM8w...) and when doing the research for that I encountered cases of repo. attacks and compromise.
IME the problem will continue unless the customers (e.g. companies making use of the libraries hosted) are willing to pay more for a service with higher levels of assurance.
The budget required to implement additional security at scale is quite high, and probably not a good match with a free (at point of use) service.
- cdnsteve 9y agoI'm sure companies would pay for it. The service needs to be part of the main package service, not some third party.
- raesene6 9y agoInteresting if you think that npm/Rubygems/PyPI are leaving a load of money on the table, why do you think they haven't introduced those services so far...
- cdnsteve 9y agoBecause their mission isn't to generate income like a traditional business. But if the income went back to the foundations, like Python Foundation, I think that would make sense.
- raesene6 9y agonpm is a commercial organisation, they offer paid subscriptions but don't offer a curated package signed option...
- cdnsteve 9y agoSort of a critical feature they are missing
- wongarsu 9y agoBut income can be also used to help finance their main mission. Obviously they seem to operate fine without strong reasons to expand revenue streams, but I feel like they ignore an opportunity to create improvements for just about everyone.
- xapata 9y agoAnaconda gives a healthy amount to open source, either by donations to foundations like NumFOCUS or paying salaries of contributors. Is that what you're looking for?
- jessaustin 9y agoISTM we're just talking about running an alternate, more restrictive registry? npm etc. don't have to play any part in that. This service could be offered by anyone: IBM could do it.
- raesene9 9y agoIndeed IBM or anyone else could do this, but they're not, which implies a lack of demand.
- fovc 9y agoIf someone here wants to build a business around this, count me in for NPM (high willingness to pay) or PyPi (lower WTP). Here's an idea: make it similar to Kickstarter, where customers can commit a certain amount of funds towards a specific package. If the package doesn't "tilt" in a certain amount of time money goes back. Otherwise you vet a point release and add it to your repo. you could offer subscriptions to keep packages updated or handle each update as its own project (with presumably lower costs if a recent release has been audited). Handling dependencies is key as an exercise for the reader
- pmoriarty 9y agoOne thing to consider if you're going to provide a service like this: What happens if a vulnerability nevertheless sneaks through? The whoever did the vetting could conceivably get sued. So then they might want to take out insurance or try to protect themselves from lawsuits in some other way -- all of which is likely to make such a service even more expensive.
- cookiecaper 9y agoIt has to be constrained to something reasonable. You can't guarantee the software is safe, but you can guarantee it is published by someone who is who they say they are, similar to EV certificates for domains. You can also refuse to publish packages with intentionally-confusing names.
- pmoriarty 9y ago"you can guarantee it is published by someone who is who they say they are" Can you? Positively identifying people seems a pretty tricky and easily screwed up business. ID's can be forged, and a web of trust requires, well, trust. I guess such a service could say something like "we got this person's ID (and/or address)" or "here's this key's web of trust", and that would probably be a bit better than what we have today (which is virtually nothing), but it would still be a far cry from "guaranteeing it is published by someone who is who they say they are".