Discussion
Loading...

Discussion

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Python Package Index
@pypi@fosstodon.org  ·  activity timestamp last month

PyPI now checks for expired domains to prevent domain resurrection attacks, a type of supply-chain attack where someone buys an expired domain and uses it to take over #PyPI accounts through password resets. #Python#OpenSource#SupplyChain#Security
https://blog.pypi.org/posts/2025-08-18-preventing-domain-resurrections/

  • Copy link
  • Flag this post
  • Block
Stéphane Bortzmeyer
@bortzmeyer@mastodon.gougere.fr replied  ·  activity timestamp last month
@pypi And what is a "custom domain name"? Why a special privilege for gmail.com?
  • Copy link
  • Flag this comment
  • Block
Stéphane Bortzmeyer
@bortzmeyer@mastodon.gougere.fr replied  ·  activity timestamp last month
@pypi Very good idea. But why using Domainr API instead of directly #RDAP to the registry?
  • Copy link
  • Flag this comment
  • Block
Patrick Mevzek
@pmevzek@framapiaf.org replied  ·  activity timestamp last month
@bortzmeyer @pypi Because not all #TLD registries joined the #RDAP fiesta 🙂 ? And in theory even a change of registrant, or maybe even DNS provider (or MX records) should trigger a "emails on this domain are not verified anymore" situation. As it should trigger certificates revocation too, which won't happen (hence shorter lifetimes as a solution).
  • Copy link
  • Flag this comment
  • Block
Stéphane Bortzmeyer
@bortzmeyer@mastodon.gougere.fr replied  ·  activity timestamp last month
@pmevzek @pypi But the article talks only about ICANN TLDs, which all have RDAP.
  • Copy link
  • Flag this comment
  • Block
Patrick Mevzek
@pmevzek@framapiaf.org replied  ·  activity timestamp last month
@bortzmeyer @pypi So either they forbid people using email addresses in ccTLDs (bad and probably not the case), or they consider that population to be more well-behaved regarding domain zombies (as they resurrect…) 🙂
  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.2.21 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login