5 ms·
PyPI has completed its first security audit
- lyu07282 3y agoLink to the report: https://github.com/trailofbits/publications/blob/master/reviews/2023-09-pypi-warehouse-securityreview.pdf https://github.com/trailofbits/publications/blob/master/revi... They seem to not have analysed client-side of PIP itself, but I suppose there isn't anything you could say that isn't already obvious to everyone.
- woodruffw 3y agoPyPI and pip are both under the "umbrella" of PyPA, but they're separate projects with (largely) separate maintainers. The audit was only scoped to the former, not the latter. (FWIW, I don't think the security posture of pip is obvious to everyone[1], and I do think it would benefit from a separate audit!) [1]: https://yossarian.net/res/pub/hushcon-west-2022.pdf https://yossarian.net/res/pub/hushcon-west-2022.pdf
- gnomewascool 3y agoInteresting slides! Thanks! `pip download --no-deps` allowing arbitrary code-execution is non-obvious, and IMO broken.
- aflag 3y agoEven pip install allowing arbitrary code-execution is non-obvious, although perhaps not entirely broken.
- capableweb 3y agoDoes it matter if the code-execution happens at `pip install` or `python myapp.py`? Using 3rd party libraries inevitably means you're allowing code-execution to 3rd parties, that's the point after all.
- dumbo-octopus 3y agoYes, because you could in theory run `pip install`, then manually read through every file you've just downloaded, then run `python myapp.py`. But every package manager seems to grant RCE to every installed package. I agree it's broken.
- bvrmn 3y ago> then manually read through every file you've just downloaded pip download?
- OrderlyTiamat 3y agoWhich can also execute arbitrary code according to the slides above.
- orlp 3y ago> Yes, because you could in theory run `pip install`, then manually read through every file you've just downloaded, then run `python myapp.py`. This security model is utter nonsense because no one does this.
- arrakeenrevived 3y agoReplace "manually read through every file" with "run your security code scanner against every file" and it becomes less nonsense, but just as applicable. In reality this really isn't how code scans are done, so it's still a little silly, but I could theoretically see something like this being a desire.
- MiguelX413 3y agoIt becomes more applicable, not just as applicable.
- hughesjj 3y agoAmazon asked me to and I actually did it for all the Brazil third party imports... granted it wasn't the most thorough of reviews, as is the nature with huge PRs
- the_common_man 3y agoHow much does an audit cost?
- eli 3y agoIt's a bit like asking how much does a vacation cost. It rather depends where you're going and what you're doing. I'd guess high five figures or maybe low six figures?
- Terretta 3y agoFive and six figure vacation costs are why so many security audits are staycations, working from home.
- capableweb 3y agoDepends widely on scope, complexity, client and consultancy. Example from Trail of Bits regarding blockchain audits: +---------+---------------------------+-------------------------+----------------------+ | Size | Small | Medium | Large | +---------+---------------------------+-------------------------+----------------------+ | Project | ERCs (20, 71, 4626, ...) | Standalone arithmetic | AMM or lending | | | | lib | protocol | +---------+---------------------------+-------------------------+----------------------+ | Pricing | $25k | $25-50k | $50-100k | +---------+---------------------------+-------------------------+----------------------+ | Timeline| 1 week | 1-2 weeks | 2-4 weeks | +---------+---------------------------+-------------------------+----------------------+ https://www.trailofbits.com/services/software-assurance/ https://www.trailofbits.com/services/software-assurance/
- trollerator23 3y ago[flagged]
- easylion 3y agoGood to know. But how often are they going to do it ? Is it going to be an annual event from now on ?
- miketheman 3y agoDepends on funding. Ask your employer to pitch in!
- deleted 3y ago[deleted]
- thenerdhead 3y agoCongrats! Thanks for trailblazing and being transparent to help other central registries follow.
- mrbonner 3y agoMy understanding reading the report is that the audit is for PyPI code and infrastructure itself and not the packages it hosts. Am I right?
- woodruffw 3y agoYes, that's correct.