PyPI Security
talkpython.fm
talkpython.fm
In the ML (now called AI) space for example, it's not uncommon to download random binaries from the internet containing model weights, scripts, etc. Sometimes even at runtime (!!!) Lots of bad practices across the industry there that wouldn't be tolerated in other contexts.
IME, half the instructions got tested just once prior to publication, on the developer's laptop or if you're lucky AWS instance and that's it. No pinned versions of anything, so if you come across something you want to try (or rather, if it gets pushed to your desk by someone higher-up accompanied by a "we need AI now!!!" note) you'll first have to spend hours upon hours trying to pin down Python package versions just to get the Python part to install, then you gotta mess with CUDA versions because obviously these haven't been documented either... Nasty shit.
I still haven't found any way to run it in a VM using consumer hardware (GPU continues to refuse to work). A second install of the OS on a second drive is so insanely clunky to switch between, I'd really like to not have to keep doing that.
in 2013 I had to buy hardware for it but by 2018 everything supported it out of the box
I haven't checked recently but a while ago most distros defaulted to letting anyone peep into other users' home dirs. Moreover there has been so many exploits over the years letting a user gain root privileges that, for the purpose of security, unix users are akin to a bathroom lock.
Yeah, no.
(I was looking into it in the context of running Fusion 360 in a Windows VM though, not Stable Diffusion or any ML.)
By that I mean, you want to use a private pip repo in your company, you upload `yourcompany_secretproject` to it and tell people to install it. Now the only way to prevent yourself being hacked is to publicly register an empty package `yourcompany_secretproject` on pypi.org. Oh and also hope the admins don't notice it and remove it because it's empty (which they have said they will).
Insane situation.
Genuinely asking.
PyPI’s security features have undergone a significant expansion since the backend rewrite back in 2017; I think it’s accurate to say that, since then, it has consistently been on the forefront (amongst its peer indices) in terms of adding scopeable API tokens, MFA, secret scanning, and most recently trusted publishing).
(FD: The company I work for helped add some of those features[1][2].)
[1]: https://blog.trailofbits.com/2019/06/20/getting-2fa-right-in...
[2]: https://blog.trailofbits.com/2023/05/23/trusted-publishing-a...
transcript link: https://talkpython.fm/episodes/transcript/435/pypi-security