Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
donaldstufft
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
donaldstufft
13y ago
A great deal of the pain that Armin experienced is mostly due to the fact that Wheels are very new and aren't very polished yet. Additionally there is a vast wealth of technical debt in the packaging tools so it's quite easy to in
62.
▲
by
donaldstufft
13y ago
There is a way to make a virtualenv relocatable but it has some issues where it doesn't always work very well. I'm not sure offhand what those issues are though.
63.
▲
by
donaldstufft
13y ago
You're also forgetting that Python itself is a core part of most modern Linux distributions. This means that even for a minimal install of an OS there are often times packages already inside your site-packages that your operating syste
64.
▲
by
donaldstufft
13y ago
The recommended way to install pip has not been via easy_install for awhile. Generally we recommend using the ``get-pip.py`` script. Which with recent versions will also install setuptools for you.
65.
▲
by
donaldstufft
13y ago
<- PyPI Administrator. I have plans for either turning PyPI into a build farm, or making a secondary service that acts as a build farm for PyPI. We've just been more focused on cleaning up other issues.
66.
▲
Python on Wheels
(lucumr.pocoo.org)
151 points
by
donaldstufft
13y ago
|
74 comments
67.
▲
by
donaldstufft
13y ago
I have actually now asked Ernest, and that was basically the reason. Familiarity. He did most of the work and was more familiar so it enabled him to complete the work quicker. We still do use Chef on the python.org infra, just not for PyPI
68.
▲
PyPI Migrated to New Infrastructure
(mail.python.org)
52 points
by
donaldstufft
13y ago
|
18 comments
69.
▲
by
donaldstufft
13y ago
Importantly, every layer in the stack is responsible for it's own security. A consumer of this API should be making sure that it's optimally configured and configure it differently where it's not. Any project that isn'
70.
▲
by
donaldstufft
13y ago
Realistically there is a value to porting to Python 3, in a year and some months Python2 will no longer be receiving security updates from Python Core. This will get taken care of by third parties for awhile but I fully suspect this support
71.
▲
A Look at PyPI Downloads
(caremad.io)
2 points
by
donaldstufft
13y ago
|
0 comments
72.
▲
by
donaldstufft
13y ago
I'm not sure I'd called M2Crypto a much better API. It more or less exposes the OpenSSL API which is also notoriously hard to get right. Further more it hasn't seen an update since 2011, the SSL certificate for the bug tracke
73.
▲
by
donaldstufft
13y ago
That's our goal at least. Personally I feel if you use our higher level API and get something wrong, then that's a bug in our code that allowed you to do that. The lower level APIs we are exposing will hopefully be more easy to
74.
▲
by
donaldstufft
13y ago
1) Not currently (and it's unlikely to be able to do so) there's an addon to add it which has been talked about getting it into core. I do believe it's documented to use HSTS and TLS if you want your site secured and recommen
75.
▲
by
donaldstufft
13y ago
I'm not sure I fully understand the proposed fix here, how does it differ from the application simply including random chunks of data inside the response? This area of things isn't my strong suite, but assuming that this is analog
76.
▲
by
donaldstufft
13y ago
A browser will accept cookies from a HTTP response on a site that has HSTS set? A CSRF request from a plaintext subdomain would not include a header and would fail Django's CSRF for lacking a referrer header (Strict referrer checking o
77.
▲
by
donaldstufft
13y ago
@homakov, so you can get a browser to trust a cookie from a HTTP response under a domain protected by HSTS?
78.
▲
by
donaldstufft
13y ago
I've just woken up and I haven't tested it, but off the cuff I believe HSTS will prevent the browser from trusting a plaintext HTTP response at all. So you cannot force a cookie if I understand the blog post correctly. You'd
79.
▲
by
donaldstufft
13y ago
An unrelated HTTP session cannot set a cookie for another domain (unless it's a subdomain in which you have the more serious issue of session theft or session fixation). The solution to both of these problems is HSTS with the includeSu
80.
▲
by
donaldstufft
13y ago
Django's CSRF protection is perfectly fine other than issues with BREACH. In any case that you can edit the CSRF token you already can execute a much stronger attack (MITM, XSS, etc). If you have a way to set your own arbitrary cookie
81.
▲
by
donaldstufft
13y ago
The recently released pip 1.4 allows you to install from Wheels which does not use setup.py during install and executes no code from the package during install.
82.
▲
by
donaldstufft
13y ago
There's a difference between signing a tarball in it's entirety (in which case you'd get only one checksum) and checksumming every file inside the tarball and then signing that file.
83.
▲
by
donaldstufft
13y ago
> That's why you have to trust the author and NOT the source. The author is the first creator of the code and thus the person with the most ability to sign the code. Source of Trust, not Source of The Thing You Downloaded. The autho
84.
▲
by
donaldstufft
13y ago
Interestingly enough I actually I have a rough sketch of an idea which will probably get laid out in a future post. I started to add it to this one but it felt disjointed and crammed to add it so I figured I'd wait till later :) But yo
85.
▲
by
donaldstufft
13y ago
There actually is a good bit of problem with this method even in the browser space. For one, which key do you bundle? If it's a central root key see the part about Linux as that's essentially what they do. Also the part about not
86.
▲
by
donaldstufft
13y ago
1. Yes absolutely. I tried to not talk about specific signing implementations because this was mostly about that simply signing isn't enough, you need a trust model. 2. I'm actually a PyPI admin, a pip core developer, and one of t
87.
▲
by
donaldstufft
13y ago
Hmm, maybe I wasn't clear. I actually meant It's unmanageable for the administrators/owners of PyPI to verify each author in the way that the owners of Debian/Red Hat verify their package maintainers. Basically that the
88.
▲
Why Package Signing is not the Holy Grail
(caremad.io)
60 points
by
donaldstufft
13y ago
|
37 comments
89.
▲
by
donaldstufft
13y ago
You should be using setuptools now. There's distutils which was the original one and is part of the standard library, setuptools which extends distutils and adds some very useful things like dependencies, then distribute split off from
90.
▲
by
donaldstufft
13y ago
Because it makes you depend on urls instead of abstract name/version requirements. easy_install does provide some tooling to get around it but in general it shouldn't be used.
More ›