# Pkg: attack vectors

**URL:** <https://discourse.julialang.org/t/pkg-attack-vectors/18340>\
**Category:** Internals & Design\
**Tags:** security, package-manager\
**Created:** [December 5, 2018, 5:48pm UTC](https://discourse.julialang.org/t/pkg-attack-vectors/18340 "2018-12-05T17:48:28Z")\
**Posts on this page:** 6\
**Page:** 2

<div class="post-metadata">

**Author:** ![dcastel](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dcastel/32/10692_2.png) [@dcastel](https://discourse.julialang.org/u/dcastel)\
**Post date:** [December 8, 2019, 2:07pm UTC](https://discourse.julialang.org/t/pkg-attack-vectors/18340/21 "2019-12-08T14:07:22Z")

</div>

Thanks for the feedback @anon92994695. Such a distance check shouldn’t be too hard to implement, no? Name revocation should also be a thing then though (on package deprecation)? That might add to the implementation complexity.

I like that idea @chakravala! That would enable some ‘karma’-based system and such local settings could substantially reduce the attack surface. E.g. only trust: this list of packages I use commonly.

Additionally like for Deb packages allow for adding of cryptographic signatures.

---

<div class="post-metadata">

**Author:** ![anon92994695](https://avatars.discourse-cdn.com/v4/letter/a/ce7236/32.png) [@anon92994695](https://discourse.julialang.org/u/anon92994695)\
**Post date:** [December 8, 2019, 3:28pm UTC](https://discourse.julialang.org/t/pkg-attack-vectors/18340/22 "2019-12-08T15:28:34Z")

</div>

@dcastel - It wouldn’t take more than an afternoon to get a prototype up! This was one of my biggest gripes with the python package ecosystem. Made trying to find packages a pain, and also a security concern. Even look at R’s package system, it’s a little crazy to navigate and it’s fricking curated:  
 ![Screenshot from 2019-12-08 10-23-51](https://global.discourse-cdn.com/julialang/original/3X/f/b/fb360cc020077086ffe118038f9bd8f92a6ff8a6.png) ![Screenshot from 2019-12-08 10-23-40](https://global.discourse-cdn.com/julialang/original/3X/0/4/045e9f4d2ad369fceb112013e5964675eceb6b70.png)

Like how is that okay? And in my opinion pythons is worse, it’s just harder to easily show that it is… I prefer verbose naming in programming… Even if it makes code look longer, its so much more readable.

“Oh yea just install abc something or another and use that one function uh forget the name something like Ec\_i and some numbers you know”

Did they say “abc? ABC.RAP? abcADM?”  
_10 minutes of installs later_  
finds its `abcdeFBA`  
now which function?

```julia
Ec_iAF1260_flux1.rda, Ec_iAF1260_flux2. Ec_iJR904 . 

```

Nope nope nope. We can do way better with a tiny bit of effort.

---

<div class="post-metadata">

**Author:** ![dcastel](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dcastel/32/10692_2.png) [@dcastel](https://discourse.julialang.org/u/dcastel)\
**Post date:** [December 9, 2019, 7:27pm UTC](https://discourse.julialang.org/t/pkg-attack-vectors/18340/23 "2019-12-09T19:27:05Z")

</div>

> <https://twitter.com/zeynep/status/1204117877919490048>
>
> Patricia Aas 🐢🏳️‍🌈 @pati\_gallardo

---

<div class="post-metadata">

**Author:** ![garrison](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/garrison/32/209519_2.png) [@garrison](https://discourse.julialang.org/u/garrison)\
**Post date:** [May 26, 2020, 4:32pm UTC](https://discourse.julialang.org/t/pkg-attack-vectors/18340/24 "2020-05-26T16:32:45Z")

</div>

I just discovered [a recent preprint](https://arxiv.org/abs/2005.09535) subtitled “A Review of Open Source Software Supply Chain Attacks,” [via LWN](https://lwn.net/Articles/821092/). I haven’t looked through it in detail yet, but it seems like a very good summary of the real-world attacks that have happened to date through package managers/ecosystems, which Stefan’s post starting this thread asked about.

---

<div class="post-metadata">

**Author:** ![virtualgraham](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/virtualgraham/32/15200_2.png) [@virtualgraham](https://discourse.julialang.org/u/virtualgraham)\
**Post date:** [May 27, 2020, 9:56am UTC](https://discourse.julialang.org/t/pkg-attack-vectors/18340/25 "2020-05-27T09:56:57Z")

</div>

In regards to package deletion. If someone deletes a package repo, in many cases they deleted it for a reason or just dont want to maintain it anymore. Also allot of packages are forked by random people, just picking one of them would leave the job of maintaining it to them. Potentially a security threat.

But “automatically fork all registered packages” sounds like a good solution.

---

<div class="post-metadata">

**Author:** ![dcastel](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dcastel/32/10692_2.png) [@dcastel](https://discourse.julialang.org/u/dcastel)\
**Post date:** [September 17, 2020, 9:19am UTC](https://discourse.julialang.org/t/pkg-attack-vectors/18340/26 "2020-09-17T09:19:23Z")

</div>

I have been doing a lot of different things so no ‘afternoon’ prototype yet.

I still need to start reading into Pkg & Registry APIs/source to figure out how to implement this. And some more research/tips from other software ecosystems is probably valuable and desirable.

If anyone can point me to good learning resources for this, let me know!

Also if anyone else is already working on something similar, I’d love to know as well. Hooking into something existing/(re)combining is often easier. As a prototype could we leverage existing systems with RCall/PyCall?

[Previous page](https://discourse.julialang.org/t/pkg-attack-vectors/18340.md?page=1)
