Diving into PyPI package name squatting
(blog.orsinium.dev)
from repostbot33@lemmy.world to netsec@lemmy.world on 09 Nov 2023 18:00
https://lemmy.world/post/8025480
from repostbot33@lemmy.world to netsec@lemmy.world on 09 Nov 2023 18:00
https://lemmy.world/post/8025480
threaded - newest
Interesting article. I would have preferred to see more discussion of the great harm squatting can do to the public. It’s not just about taking up space in a database, malicious actors can hold a name with a malicious version of the software and just wait for victims to show up and pull it. (This is one obvious reason why companies squat names preemptively.)
I believe Python erred in having a flat namespace instead of using domain names you can secure and validate with DNS or something. Too late now, though.