Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The dependency confusion article on Medium was a great read.


Beautifully simple! Exfiltrating data via a DNS request was a nice little trick too.


It's a really good article and apologies to the author for nitpicking but even as a bona fide Python fanboy I had to raise my eyebrows at this statement:

> Some programming languages, like Python, come with an easy, more or less official method of installing dependencies for your projects.


I mean, have you ever used a language like Java? Python has a bad package manager story, sure, but it has a package manager story - that's not actually particularly global afaik


Link for those who went straight to comments: https://medium.com/@alex.birsan/dependency-confusion-4a5d60f...


It's amazing that such a simple vulnerability can be leveraged in practice to gain access to so many machines on so many different organizations. Props to the researcher!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: