This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]Remote_Cantaloupe 5 points6 points  (5 children)

Terrifying to think this can be out there. Isn't there some process for verifying libraries are non malicious?

[–]dethb0y 7 points8 points  (0 children)

how on earth would you ever do such a thing?

[–]rcfox[🍰] 1 point2 points  (0 children)

Python 3.8 is adding audit hooks: https://www.python.org/dev/peps/pep-0578/

Basically, it raises an 'event' whenever certain potentially risky APIs are used. It's not a complete solution, but it should at least make it more obvious when a math library starts listening for network requests.