[HN Gopher] Account Takeover and Malicious Replacement of Ctx Pr...
       ___________________________________________________________________
        
       Account Takeover and Malicious Replacement of Ctx Project
        
       Author : sashk
       Score  : 10 points
       Date   : 2022-05-24 18:08 UTC (4 hours ago)
        
 (HTM) web link (python-security.readthedocs.io)
 (TXT) w3m dump (python-security.readthedocs.io)
        
       | samwillis wrote:
       | I think it's increasing obvious that uncurated package managers
       | (PyPI, NPM, etc.), while so brilliant for discoverability and
       | development speed, expose a very large security risk. It seems to
       | me there are two options:
       | 
       | - curated package manager, potentially paid, that ensure the
       | security of the libraries available.
       | 
       | - languages/platforms that are able to sandbox, with permissions,
       | at the library level.
       | 
       | I'm not sure what the way forward is but I don't think the status
       | quo can necessarily continue.
        
       ___________________________________________________________________
       (page generated 2022-05-24 23:02 UTC)