Show HN: Pytroj - Infect .pyc files
github.com
github.com
Though they discourage the use of the .rbc files directly so not sure this is much to worry about as they change the bytecode format often enough.
Seriously, when is PyPI going to serve behind SSL? Oh wait, that's not secure too. Nevermind.
Of course, tooling for this would have to be written, or maybe even the jar-signing tools could be used (as eggs and jars are both zip files with metadata).
AFAIK, a typical code signing process required these steps:
1) Get a cert/key whatever, you can generate your own or some server can generate it for you. As long as both of you trust it, it's ok. 2) You sign your code and upload it to the server 3) When a client requests for the code, the client establish a secure channel with the server and then the server will send the key over with the data to the client. The client decrypts it. If you do this, the cert/key is usually generated by the server. 4) Or the key is somehow stored on the client side beforehand. This is logistical nightmare and potential security hole if the key is properly protected.
Since no sane person will choose 4) to distribute Python packages you can download from PyPI, you are stuck with 3). Guess what. You still need SSL. Am I wrong here, did I miss anything?
I was just trying to propose a way to make the PyPi repository somewhat more secure by making sure the maintainer signs the packages. This increases security somewhat (for example, if the server is compromised) in addition to SSL.
Btw, a nice (GUI) tool for examining/disassembling pyc files is: http://code.google.com/p/pychrysanthemum/ (it supports all the different python and bytecode versions without having to mess around with opcodes.py files...)
when was the last time you have read python files of installed 3rd party software to find viruses and trojans?
and even if you bothered, by simple obfuscation you would need to be an expert to identify a trojan in a python file.
In addition a simple way to find or clean up such a virus would be to compile .pyc files from their sources during a virus scan.
in short that can't be the reason.