Austin Dern is a user on mastodon.social. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

holy shit.

reddit.com/r/Python/comments/8
twitter.com/x0rz/status/994116

"The ssh-decorator package from Python pip had an obvious backdoor"

sends host + username + password to an external website

@nightpool @codl holy shit IN PLAINTEXT even what the jesus everfucking shit

@fluffy @nightpool @codl And if it weren't bad enough: logging it as 'passowrd'.

@Austin_Dern @nightpool @codl I can actually see them having done that on purpose to fool automated warning/checker things. It’s an anti pattern I saw a few times at Amazon internally to escape a code auditor process.

Austin Dern @Austin_Dern

@fluffy @nightpool @codl Surely is to sneak past automated checking, yes. It's the laziness that gets me. If they titled like, 'networkSuccess' or 'connectStatus' or even 'misc1' then you'd have something too boring to pay attention to if you caught it being passed on your network.

· Web · 0 · 0