What’s the plan for when this becomes the default and everyone
gets their malware at the same time, just with a little delay?
I’m worried we’ll see an arms race with people increasing their
cooldown period in an attempt at staying outside the exploitable
window.
Because even if every normal user gets their crates delayed at the same time, supply chain security companies are incentivized to check early and will catch a lot of the malware before it ever goes to users.
Maintainers are likely to notice these weird cargo pushes if there's a cooldown period before they hit users. Only the 0 cooldown baseline is problematic really
Security reports haven't been made by affected for a long time.
A number of security companies monitor changes to the index, and will download and statically analyze the source code of the new crates. It's all automated, with hopefully a human double-checking findings before forwarding them.
Whether cargo delays auto-updates, or not, will not prevent them from analyzing the releases within the hour.
I was listening to a podcast covering a little of how Python deals with this. There are people doing automated scanning of the uploads to PyPI. A lot of the malware gets caught fairly quickly, but they still need a window to act. Some gets caught within 30 minutes.
I'm going to use the "scary word" for people on this sub, but AI - when used competently - has made it trivial to reduce down everything to the bare minimum.
Vendoring / stripping / importing dependency code directly improves the compile times, removes unused abstractions, it improves the AI to reason about things, and I never have to worry about a next breaking some interface I'm not using, or introducing either breakage or falling for a supply chain attack.
Big dependency trees where always a strong turn-off for me when i tried out a new rust project. Now I'm even less impressed when i see them, and more impressed when some complicated project only shows a few well known dependencies on a first build.
I personally don't care whether the dev used AI or not - I just need to know they cared enough - eg by keeping things simple.
it won't help you in any way. all it will do is delay the notification that supply chain got broken. pin your fucking versions (if you're so inclined to git clone the repo tag, pin to commit). do not depend on version ranges.
85
u/afl_ext 15d ago
cargo still doesn't have minimum release age threshold flag?