[HN Gopher] Account Takeover and Malicious Replacement of Ctx Pr...
___________________________________________________________________
Account Takeover and Malicious Replacement of Ctx Project
Author : sashk
Score : 10 points
Date : 2022-05-24 18:08 UTC (4 hours ago)
(HTM) web link (python-security.readthedocs.io)
(TXT) w3m dump (python-security.readthedocs.io)
| samwillis wrote:
| I think it's increasing obvious that uncurated package managers
| (PyPI, NPM, etc.), while so brilliant for discoverability and
| development speed, expose a very large security risk. It seems to
| me there are two options:
|
| - curated package manager, potentially paid, that ensure the
| security of the libraries available.
|
| - languages/platforms that are able to sandbox, with permissions,
| at the library level.
|
| I'm not sure what the way forward is but I don't think the status
| quo can necessarily continue.
___________________________________________________________________
(page generated 2022-05-24 23:02 UTC)