3 ms·
Supply chain attacks can exploit gaps between source code and distributed packages. Today, if PyPI were to be compromised, attackers could serve malicious packa
by darkamaul 2y ago
Supply chain attacks can exploit gaps between source code and distributed packages. Today, if PyPI were to be compromised, attackers could serve malicious packages even if the source code is clean.
Attestations provide cryptographic proof linking published packages to specific code states. This proof can be verified independently of PyPI - reducing exclusive trust in the package index.
Worth noting, attestations aren't a complete defense against index compromises since an attacker could simply stop serving attestations (though this would raise alerts for users monitoring their dependencies' attestation status).
Is this a silver bullet? No. If an attacker compromises a project's source repository, attestations won't help. However, it meaningfully reduces certain attack vectors and moves us towards being able to cryptographically verify the entire chain from source code to deployed package.
(Disclaimer: I helped build this feature for PyPI)
- amelius 2y ago> Is this a silver bullet? No. If an attacker compromises a project's source repository, attestations won't help. But that's a huge attack surface.
- MattPalmer1086 2y agoAnd one that needs a different solution. Update: That a control doesn't solve all problems is irrelevant. By that measure, we would have no controls at all.
- amelius 2y ago> And one that needs a different solution. Does the community have any ideas about that?
- MattPalmer1086 2y agoIf you're asking how we can prevent people breaking in to a source code repository, the answer is mostly just the same as anything. Patch, apply principle of least privilege, make sure everyone uses strong authentication. Monitor the system. For SCM specific controls we could also require signed commits, apply branch protection and any other system specific controls, and enforce code reviews before commit.
- amelius 2y agoThat doesn't sound like a lot of fun, and I wonder if it is reasonable to ask from maintainers who do this work in their spare time.
- amelius 2y agoMaybe in the near future we could have an AI system that: - Connects to HDMI - Monitors any text that's on the screen - Checks that the user is watching the screen (or at least is at the computer) - Checks that any changes committed into the Git repository have been at least on the user's screen for X seconds, while they were sitting near the computer.