4 ms·
Why doesn't the Python package manager (PIP) have package signing feature?
- CogitoCogito 7y agoThat blog post provides nothing of value. It complains that there isn´t package signing and that´s it. It doesn´t propose anything. In the comments the author claims removing the signing is "beyond logic" even while linking to a reddit thread in which the logic is laid out clearly. For example: https://caremad.io/posts/2013/07/packaging-signing-not-holy-grail/ https://caremad.io/posts/2013/07/packaging-signing-not-holy-... https://mail.python.org/pipermail/distutils-sig/2018-March/032066.html https://mail.python.org/pipermail/distutils-sig/2018-March/0... https://old.reddit.com/r/Python/comments/8r9qby/pypi_has_removed_pgp_signatures_of_package/ https://old.reddit.com/r/Python/comments/8r9qby/pypi_has_rem... Read those links if you are curious, but I would recommend skipping the post linked by el_programmador. Read
- new_realist 7y agoYour comment provides nothing of value. It complains that the blog post contains nothing of value and that’s it. It doesn’t propose anything. I would propose abandoning PIP in favor of signed packages from your favorite secure Linux distribution.
- CogitoCogito 7y agoMy post points out the useful links and information found in the comments of that post. It contains _everything_ valuable behind that post. The game you’re playing trying to turn this around me is childish and pointless.
- javagram 7y agoIt would be nice if package managers would not only support 2FA, but make it available via metadata the uploader and whether the uploader used 2FA. If operations are performed over HTTPS, this would probably provide even more security guarantees than the typical use of signatures. Organizations or persons that want increased security could refuse to use packages that weren’t uploaded with 2FA (which, yes, would include packages from automated build servers which are often targets of hacking). I imagine most people would trust-on-first-use signatures and then also accept changes to the signing key, so how much security does it really give?
- payne92 7y ago> It would be nice if package managers would not only support 2FA, but make it available via metadata the uploader and whether the uploader used 2FA. How would this work when the package manager can be run by anyone? 2FA is an authentication method (akin to asking for a password, albeit a special one). It's not a digital signature.
- javagram 7y agoIt would work if you have a centralized registry with a centralized authentication (like npm does, or maven central). You’re correct that it’s not a digital signature. You have to be able to trust the registry (whose communications to you are signed, via HTTPS).
- eru 7y agoThat would be pretty annoying. The signatures are an end-to-end thing. As long as you can trust the signer at time of signing, you can trust the package. No matter what happened to that package in the meantime, or what shady people were in charge of transmitting it to you. Be that five minutes after uploading or fifty years. 2FA and HTTPS only do anything extra on top of that for you, if you trust the whole chain of transmission at all times, and all custodians of the data. Adding 2FA and HTTPS might still be a good idea as a second line of defense. But it's not a replacement for signed packages.
- javagram 7y agoIf the signer puts their key on a build server and that build server is hacked, then the signing is worthless. (Although, having written this, I suppose people would just put their TOTP secret on the build server also) With a centralized registry model I already trust the registry anyway. It’s not like I’m typically going out and verifying people’s keys by emailing them to check what their real key should be or whatever.
- 7y ago
- sametmax 7y agoThe recommanded way to upload a package on pypi is to use twine: Https://pypi.org/project/twine/ Which does the signing as well. But I don't know if pip checks it.
- el_programmador 7y agopip doesn't check anything. As the top reddit comment quotes from the github issue: >> This isn't a bug, we've purposely de-emphasized PGP on Warehouse. While we support uploading them still and they're still a part of the API, we're not exposing them to the user in the UI.