4 ms·
Glad they were able to automatically detect/catch this. There seems to be so much bloat when dependencies get pulled in. Wonder if something like pledge and u
by anonymousnotme 4y ago
Glad they were able to automatically detect/catch this. There seems to be so much bloat when dependencies get pulled in.
Wonder if something like pledge and unveil around library code could be helpful; perhaps library code needs to be separated out into a separate process that would not have reason to access AWS keys.
Also, looking at the screenshot, could a simple programming searching for URLs in the library code help in this case?
Looks like they removed the modules, so one can't examine them any more.
- Pv9KKy3 4y agoYeah, I'd love to have a decorator at the top of a file - @env to provide access to env variables or @secrets for some kind of secrets access, nothing else gets this. Python is tough though, a very dynamic language so probably kind of hard to lock it down.
- Beltiras 4y agoYou would normally be able to solve things like this via file permissions in the OS but currently we are running everything as root inside a container.
- Pv9KKy3 4y agoNot really, because the dependencies to your python code often have access to all global variables and/or run at same permission level as all your code etc.
- grepfru_it 4y agoIs it really automated? The infographic glosses over the how with a “security research team” in the flowchart. Maybe the automation catches suspicious code/activity (like the urls or accessing sensitive files) and the research team just verifies