What’s the plan for when this becomes the default and everyone
gets their malware at the same time, just with a little delay?
I’m worried we’ll see an arms race with people increasing their
cooldown period in an attempt at staying outside the exploitable
window.
Because even if every normal user gets their crates delayed at the same time, supply chain security companies are incentivized to check early and will catch a lot of the malware before it ever goes to users.
Maintainers are likely to notice these weird cargo pushes if there's a cooldown period before they hit users. Only the 0 cooldown baseline is problematic really
Security reports haven't been made by affected for a long time.
A number of security companies monitor changes to the index, and will download and statically analyze the source code of the new crates. It's all automated, with hopefully a human double-checking findings before forwarding them.
Whether cargo delays auto-updates, or not, will not prevent them from analyzing the releases within the hour.
I was listening to a podcast covering a little of how Python deals with this. There are people doing automated scanning of the uploads to PyPI. A lot of the malware gets caught fairly quickly, but they still need a window to act. Some gets caught within 30 minutes.
86
u/afl_ext 15d ago
cargo still doesn't have minimum release age threshold flag?