Популярность имеет свои минусы. Чем популярней язык программирования, тем выше его распространённость, а значит найдутся те кто поспешит воспользоваться этим.
С ростом популярности Python всё больше на PyPi появляется вредоносных пакетов. Трояны, стиллеры и доставщики более опасных вредоносов.
Команда PyPi постоянно мониторит подобные случаи но и их возможности достигли предела. В результате сервис временно закрывает возможность заливки новых пакетов и регистрации юзеров.
PyPI new user and new project registrations temporarily suspended
Возможно одной из причин большого наплыва вредоносов является резко возросшая доступность их создания. Сегодня любой, даже не программист, может попросить у ChatGPT написать необходимый код и все инструкции для атаки.
Основной тип атаки - рассчёт на опечатку в названии пакета. Если невнимательный программист случайно установит pilow или djangoo, считай что вредонос уже в системе.
Чтобы избежать подобных факапов я рекомендую:
▫️ Всегда работайте в виртуальном окружении, неизвестные проекты устанавливайте внутри контейнеров.
▫️ Используйте файл requirements.txt вместо ручной установки пакетов
▫️ Очень внимательно пишите названия пакетов, а после написания проверьте еще раз. Сверьте с названием из документации.
▫️ После успешных тестов всегда фиксируйте версию пакета. Бывали случаи когда опасный код добавляли в новые версии. К тому же и без этой опасности не рекомендуется ставить по умолчанию последнюю версию.
▫️ Используйте вспомогательные инструменты для проверки безопасности, например https://pyup.io/safety или https://github.com/PyCQA/bandit. Они помогут не только найти опасный код в чужих пакетах, но и ваш код проверит на уязвимости.
Будем надеяться что PyPi переосмыслит методы борьбы с вредоносами, например внедрит ИИ для проверки как симметричный шаг.
#offtop
#ZCASH/USDT analysis :
#Zcash is currently in an uptrend, consistently making new highs while trading above the 200 EMA. The price is now retracing towards the 200 EMA and a key support level. It is anticipated that the price will test this zone and rebound, allowing the bullish momentum to continue and potentially leading to a retest of previous highs.
TF : 1D
Entry : $49.5
Target : $79
SL : $39.9
#ZEC getting ready for bullish breakout very soon! Strong flip off from the trendline resistance might trigger massive rally, ZEC appears promising; quantum-resistant blockchains are projected to perform more effectively when market conditions improve.
$ZEC #ZECUSDT#ZCASH
https://x.com/CryptoBull_360/status/2040431968773652859?s=20
🚀 Zcash and Dash Surge Amid Bitcoin and Ethereum Gains Following U.S.-Iran Ceasefire
Zcash and Dash have experienced significant price increases over the past week, with Zcash rising by 49% and Dash by nearly 53%, surpassing the gains of Bitcoin and Ethereum, which saw increases of 8% and 9% respectively. According to NS3.AI, the upward trend in Bitcoin and Ethereum followed the announcement by U.S. President Donald Trump of a ceasefire with Iran. CoinGecko data indicates that Zcash was trading at $371, Dash near $46, while Monero also saw a 7% increase during the same period.
#Zcash#Dash#Bitcoin#Ethereum#Cryptocurrency#Ceasefire#USIran#PriceSurge#Monero#CryptoMarket#BTC#DASH#ZEC
🚀 Zcash's Potential Surge: Traders Predict 60% Chance of Reaching $420
Zcash (ZEC) has experienced a significant rise, with traders on Myriad now predicting a 60% probability of the token reaching $420 this month. According to NS3.AI, Zcash saw an increase of over 62% in the past week, with its price recently hovering around $380. The odds on Myriad shifted dramatically from 80% against the move on Thursday to 60% in favor by Friday.
#Zcash#ZEC#Cryptocurrency#CryptoTrading#PricePrediction#Myriad#NS3AI#CryptoSurge#Blockchain#DigitalAssets
🚀 Monero and Zcash Expected to Launch on Mainnet Soon
Monero (XMR) is anticipated to go live on the mainnet within one to two months, according to Foresight News. The chain client pull request has successfully passed simulation testing. To address privacy observation issues with XMR, THORChain plans to create a dedicated Asgard vault composed of all validator nodes.
In parallel, Bittensor (TAO) is being developed alongside Monero, aiming for a simultaneous launch. Additionally, Zcash (ZEC) is expected to launch on the mainnet by the end of April.
#Monero#XMR#Zcash#ZEC#Mainnet#Blockchain#Cryptocurrency#THORChain#Bittensor#PrivacyCoins#TAO
🚀 Zcash Open Development Lab Unveils Strategic Direction Focused on Post-Quantum Security
On April 13, Zcash Open Development Lab (ZODL) founder Josh Swihart announced the latest developments for Zcash, emphasizing a strategic direction centered on post-quantum security, scalability, and user experience. According to BlockBeats, Swihart likened the initiative to the Artemis II lunar mission, highlighting the pursuit of seemingly impossible goals through technological breakthroughs. The ZODL team revealed that Zcash is entering the 'Zcash IV' phase, aiming to build infrastructure akin to a 'lunar base' to support the protocol and applications' secure expansion to billions of users, while advancing the vision of privacy transactions without large-scale financial surveillance.
On the product and technology front, ZODL continues to iterate, with its 3.3.x version now available on iOS and Android, featuring new hardware wallet connection management, SDK upgrades, and multiple user experience enhancements. Key developments include advancing Keystone wallet functionality and upgrading the address system (ZIP 316, UIVK/UFVK). Meanwhile, the Zcash core team has addressed several system issues and is progressing with the Zallet alpha version development, strengthening unified address standards and wallet interaction experience to lay the foundation for future scalability and performance improvements.
Additionally, ZODL disclosed ongoing growth in application data and participation in a stablecoin privacy summit to enhance industry collaboration. However, due to increased regulatory and network restrictions, ZODL has temporarily removed its app from Russian app stores. The team emphasized that privacy is not optional but a fundamental need in the digital age, and they will continue to accelerate delivery pace to promote ZEC adoption and ecosystem development.
The core of Zcash Open Development Lab is to develop an open, self-custodial private financial platform, aiming to expand ecosystem interoperability through collaboration and bring protected ZEC transactions to the global mainstream market.
#Zcash#ZODL#PostQuantumSecurity#Cryptocurrency#Privacy#Blockchain#Scalability#UserExperience#KeystoneWallet#Zallet#Stablecoin#FinancialPrivacy#EcosystemDevelopment#DigitalPrivacy#OpenDevelopment#ZEC