Популярность имеет свои минусы. Чем популярней язык программирования, тем выше его распространённость, а значит найдутся те кто поспешит воспользоваться этим.
С ростом популярности Python всё больше на PyPi появляется вредоносных пакетов. Трояны, стиллеры и доставщики более опасных вредоносов.
Команда PyPi постоянно мониторит подобные случаи но и их возможности достигли предела. В результате сервис временно закрывает возможность заливки новых пакетов и регистрации юзеров.
PyPI new user and new project registrations temporarily suspended
Возможно одной из причин большого наплыва вредоносов является резко возросшая доступность их создания. Сегодня любой, даже не программист, может попросить у ChatGPT написать необходимый код и все инструкции для атаки.
Основной тип атаки - рассчёт на опечатку в названии пакета. Если невнимательный программист случайно установит pilow или djangoo, считай что вредонос уже в системе.
Чтобы избежать подобных факапов я рекомендую:
▫️ Всегда работайте в виртуальном окружении, неизвестные проекты устанавливайте внутри контейнеров.
▫️ Используйте файл requirements.txt вместо ручной установки пакетов
▫️ Очень внимательно пишите названия пакетов, а после написания проверьте еще раз. Сверьте с названием из документации.
▫️ После успешных тестов всегда фиксируйте версию пакета. Бывали случаи когда опасный код добавляли в новые версии. К тому же и без этой опасности не рекомендуется ставить по умолчанию последнюю версию.
▫️ Используйте вспомогательные инструменты для проверки безопасности, например https://pyup.io/safety или https://github.com/PyCQA/bandit. Они помогут не только найти опасный код в чужих пакетах, но и ваш код проверит на уязвимости.
Будем надеяться что PyPi переосмыслит методы борьбы с вредоносами, например внедрит ИИ для проверки как симметричный шаг.
#offtop
🇬🇧#UK - Il parlamento ha approvato in via definitiva una legge per eliminare i 92 “membri ereditari” della Camera dei Lord, la camera alta del parlamento. È una decisione storica che metterà fine a una consuetudine che durava da più di 700 anni. (ilPost)
@UltimoraPolitics24
🇬🇧#UK Trump has been at the center of discussion due to a breach of protocol.
British social media is discussing an incident in which US President Donald Trump walked past Queen Camilla to shake hands with his acquaintances, which was considered a breach of protocol.
🇬🇧#UK. Armed police spotted outside a McDonald's in Kensington.
Armed Police arresting a suspect outside McDonald's. Armed response was deployed due to intelligence suggesting high risk,possible weapon or violence, it's standard UK protocol for public safety. Police haven't released specifics on the exact reason or threat yet, as it's an active investigation.
(By the looks of one of those green dots, someone has had far too much coffee.)
Follow us -> LiveLeak
#UK: Il Regno Unito ha affermato che non parteciperà alle operazioni militari contro l'Iran, anche se il governo si è espresso in supporto agli obiettivi dichiarati dagli USA e Israele.
🇬🇧The Psychological Attack on the UK, Part 2 | UKColumn - 2021
If Bezmenov had been correct in just one or two of his predictions, then we might assume that coincidence was at work. In reality, he was correct in all of his predictions. Common sense therefore tells us that the plan he describes must be both real and effective. And that plan ultimately leads from 'Demoralisation' to 'Destabilisation', to 'Crisis' (Chaos) and then 'Normalisation' — so-called 'peace' (actually pacification) under a socialist/communist dictatorship of global scale.
In Part 2 as we tackle the key subversively targeted area of Security (covering the intelligence community, police and military), but first we address the demoralising and destructive plans detailed for Law and Order and Social Relations.
To recap, the following descriptive paragraph sets out the key warning within Story's highly detailed and meticulously researched book:
The European Union Collective Enemy of its members states
@ukcolumn@EastApp
#UK
🇬🇧The Psychological Attack on the UK: Start of a Series | UKColumn – 2021
Alex Thomson and Brian Gerrish discuss the origins of the psychological attack on the UK in the first part of a series. Our starting documentation and analysis centres on the book by Christopher Story: The EU Collective - Enemy of its Members States.
@ukcolumn@EastApp
#UK
🇬🇧#UK: Footage shows tens of thousands of protesters marching through London as two rival demonstrations, the “Unite the Kingdom” rally and a large pro-Palestine march, take place simultaneously across the capital.
According to police, at least 11 people have been arrested since the demonstrations began.
🇬🇧#UK: London is preparing for one of its largest public order operations in recent years as two major demonstrations, the pro-Palestine “Nakba Day” march and the “Unite the Kingdom” rally organised by Tommy Robinson, take place simultaneously this weekend in central London, alongside the FA Cup Final.
For the first time in a protest policing operation in the UK, live AI facial recognition will be used alongside aerial surveillance employing helicopters and drones, as well as armoured vehicles and large-scale specialist policing units deployed across the capital. Around 4.000 officers will be involved in the operation, with reinforcements from forces across England and Wales, as authorities reportedly prepare for "significant public order risks" across multiple protest routes.
(via Reuters & BBC)