Message137435
On Wed, Jun 1, 2011 at 10:30 AM, Stefan Krah <report@bugs.python.org> wrote:
>
>> Distutils doesn't validate PyPI server certificate, so this change
>> doesn't prevent from MITM attacks, but at least it makes package
>> submissions over wireless channels and public networks safer.
>
> Is that so? It's been a while, but I think e.g. ettercap is a highly
> automated tool for MITM attacks that isn't very hard to use.
This patch won't help against properly baited ettercap, but will
prevent transit sniffing of weakly protected passwords.
--
anatoly t. |
|
Date |
User |
Action |
Args |
2011-06-01 15:11:12 | techtonik | set | recipients:
+ techtonik, loewis, barry, tarek, eric.araujo, Arfrever, skrah, alexis |
2011-06-01 15:11:11 | techtonik | link | issue12226 messages |
2011-06-01 15:11:11 | techtonik | create | |
|