4 ms·
Interesting, I kinda understand since I work for a big org where everything is very slow because of bureaucracy and fear of changes but here the big projects w
by nightshift1 3y ago
Interesting,
I kinda understand since I work for a big org where everything is very slow because of bureaucracy and fear of changes but here the big projects were already forced to use 2fa.
It would seem logical to force the contributors to use good security practices right from the start. I would have probably started with those.
Anyway, I don't want to complain. I believe its a good step towards securing the software supply chain.
Keep up the good work.
- woodruffw 3y ago> It would seem logical to force the contributors to use good security practices right from the start. I would have probably started with those. I agree, but that's the benefit of hindsight :-) PyPI is simultaneously one of the oldest and most active language packaging ecosystems out there; a lot of of the things we treat as "table stakes" in terms of good security practices weren't even invented when it was first released. The consequence of all of this is that there's a lot of ossification, and things can't be changed suddenly without (reasonably!) upsetting a lot of people who are invaluable to the community. It'd be great in terms of security if we could just force it, but that wouldn't be fair to them, to their historical expectations, etc. Edit: I should say: I'm not a maintainer of PyPI, just someone who has contributed to it. My opinions aren't representative.
- predictabl3 3y ago> The consequence of all of this is that there's a lot of ossification, and things can't be changed suddenly without (reasonably!) upsetting a lot of people who are invaluable to the community. It'd be great in terms of security if we could just force it, but that wouldn't be fair to them, to their historical expectations, etc. I can't tell if you're being very overly generous to folks, or if there's something I'm really not considering. Given that I've been using a Yubikey, password manager, ssh-only auth, etc for ... idk, nearly a decade? Did it take a whole hour to learn + setup? Yes. Do I think that over time I've been more secure, and had to deal with less headaches from the repeated LastPass breaches, password leaks, compromises, etc? Oooh absolutely. --- Sorry Python ecosystem! Sorry a package was compromised by a careless dev. Pypi? Oh what about it? Why didn't it require basic security mechanisms to upload packages downloaded by literally tens of millions of users? Oh, we couldn't inconvenience lazy devs, come on now. I just can't with people. These things matter. Taking hard stances and making people uncomfortable sometimes IS NECESSARY. And to be clear, I'm not trying to come for your woodruffw (or the pypi team, god knows I've seen how HN acts with forced 2FA), I'm expressing a generous frustration that there doesn't seem to be a firewall where "general dev laziness" is overridden by idk, any sense of the commons, or any basic understanding that valuable assets WILL be attacked, passwords WILL be compromised and that some "root of trust" with something I physically can hold is pretty much required these days. LOL HN really does not like hearing inconvenient truths or truths that point out their blind/lazy spots.
- eesmith 3y ago> "general dev laziness" is overridden by idk ... Have you considered that perhaps you are the lazy one? You don't want to inspect the source code yourself for security holes, you don't want to pay someone to do it, and you don't want to establish a direct trust relationship (personal or legal) with the original developers. Instead, you want to trust automation and externalize blame. And you call others lazy? > ... any sense of the commons If you have any sense of the commons beyond past Hardin's simplistic and historically flawed argument advocating mandatory population control, then surely you can understand how PyPI admins are trying to balance the traditional commons use rights based on cooperation and responsibility with the needs of lazy people like you, while hopefully avoiding any devastating effects akin to how English land enclosure deprived commoners of their rights of access and privilege.
- predictabl3 3y agoNo, I'm talking about the complete shit show that is python packaging and the fact that there is any hand wringing over this (2FA) being "hard" to force on devs. There's nothing hard about it. This doesn't have anything to do with auditing source, that's such a creative cop out, subject change, whataboutism. No, actually, I'm not a giant corp, I can't afford to hire teams to review every commit. Especially across the python ecosystem, it being what it is. And that's assuming it's even easy to find the damn source, or go from papi back to the actual source commit. Which, it often isn't! Oh and supposedly I have to do this because devs that publish packages with millions of users are too lazy to have some actual security around their release process? No. Sorry, it's not unreasonable to review a project, skim the source, and determine there's software engineering going on. However, without 2FA, none of that really matters, does it? Oh! And, this whole scenario is moot given that most people aren't pinning with hashes anyway, so your little made-up scenario and words you've effectively put in my mouth really doesn't make the point you think it does, anyway! In fact, thanks for another great point to add to my initial list! > you don't want to establish a direct trust relationship (personal or legal) with the original developers. Do you actually understand what this thread is even about? What in the hell good does that do me when their laptop gets swiped at a conference and their latest package gets replaced? > while hopefully avoiding any devastating effects akin to how English land enclosure deprived commoners of their rights of access and privilege. Wow, I can't believe I wasted my time reading you post, let alone replying to any of it. I love a dramatic flair but that's in poor taste.