6 ms·
It seems particularly crazy to me that many people find out about security releases (or any releases) like this. What happens when one doesn't make the front pa
by endtwist 14y ago
It seems particularly crazy to me that many people find out about security releases (or any releases) like this. What happens when one doesn't make the front page of HN?
Apologies for the shameless plug but at BundleScout we've been working on a tool to notify you when things like this happen[1]. It's not perfect, but it's a step up from this I'd hope.
[1] https://bundlescout.com/search?q=django https://bundlescout.com/search?q=django
- archivator 14y agoLike what exactly? Anyone using Django in a production environment, should be following django-announce anyway - https://groups.google.com/forum/?fromgroups#!forum/django-announce https://groups.google.com/forum/?fromgroups#!forum/django-an...
- bconway 14y agoI imagine most people sign up for the announcement and/or security mailing lists of the products that are critical to their infrastructure.
- glfomfn 14y agoYour tool doesn't currently show the last security update, according to your website last update was 2 months ago. Django wise, there is the Google group which you can be follow for all updates , you can also subscribe to the RSS feed of django's weblog. Your tool seems interesting, i like the idea of being able to keep a list of all the software i use in a single place and get notified when a new update comes out(had a similar idea myself), however i would need some kind of reassurance that such an application is reliable and wont let me in the dark for some important update.
- endtwist 14y agoTypically, the updater runs about once a day. If you take another look, it will show the latest security update :) We're working very, very hard to guarantee that no updates go missed and ensure that you receive a notification within 24 hours of any update going out. And while, yes, you can watch the RSS feed or Google group, do you really want to do that for Django and the other 29 libraries you use?
- glfomfn 14y agoIt shows the update now, it didn't when i posted my reply, however its still fast enough compared to when it was announced by django's official communication channels. A bit off topic but i have some thoughts on the website since i might be interested to using it in the future: It would be great if you could lower the 'within 24 hours' to something like 'within 2 hours'. I understand the difficulty of that since you are tracking over 100.000 packages according to the homepage but a 24 hours dilation is a bit too much, i don't deploy code yet in any high traffic sites which could be subject to a 0day security attack but still i find the dilation too much to consider it as a viable option for the future.
- jacobian 14y agoWe don't just announce this stuff on HN; there's a whole lot more: * Post security release announcements to our blog. * Post announcements to django-announce, a very low-traffic mailing list specifically for security announcements. * Post announcements to django-users, a mailing list with over 20,000 subscribers from all over the Django community. * Post announcements to django-developers, where most of the people who hack on Django hang out. * Publicize these releases on Twitter, Reddit, HN, etc. Further, we work with people who re-distribute Django (e.g. as part of RHEL/Fedora/Ubuntu/etc.) and people who use Django in high-risk areas to get them early access to security notifications [1]. So yeah, we make a lot of noise about security issues. BundleScout looks nice, but it kinda sucks that you'd make people pay to hear about security issues. We're going to continue to do our best to make sure people find out about them quickly and for free. [1] https://docs.djangoproject.com/en/dev/internals/security/#requesting-notifications https://docs.djangoproject.com/en/dev/internals/security/#re...
- lawnchair_larry 14y agoI appreciate this. Second, I think the severity of XML external entity injection is understated in the advisory. This class of vulnerability isn't just a DoS in general. Does something about Django specifically limit the impact to just a DoS?
- jacobian 14y agoYes: Django only uses XML in one very limited place, the serialization parsing framework, which isn't exposed publicly in any way. It's used for data backup/restore as well as for test fixtures, but that's it. Further, the same framework also supports JSON, and it's extremely rare to find a Python developer who's going to chose XML over JSON. So in terms of Django itself the attack surface is extremely small. That said, if you're parsing XML in your own code you should be looking at defusedxml, also announced today: http://blog.python.org/2013/02/announcing-defusedxml-fixes-for-xml.html http://blog.python.org/2013/02/announcing-defusedxml-fixes-f.... So maybe we should make a bigger point about that? If you've got suggested edits to the announcement let me know, happy to incorporate 'em.
- 14y ago
- Scramblejams 14y agoI'm old fashioned, I guess. I deploy my apps on Debian stable, and they (like most distros) have a competent security team which stays on top of all this stuff. I have a script running on all my servers which looks for available security updates to my installed packages every few hours and emails me in the event. Sidenote: This is one reason why I avoid virtualenv and its ilk for my apps unless I absolutely have to use them (e.g. need a newer version of something to get a feature I can't live without) -- I don't toss aside the good work of vigilant security pros lightly.