frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

The peril of unquoted Python strings, and how they caused CVE-2024-9287

https://pythonkoans.substack.com/p/koan-12-the-blacksmiths-hammer
3•meander_water•1h ago

Comments

zahlman•5m ago
This is not about "unquoted Python strings".

It is about unquoted shell arguments, in the context of invoking the shell using Python's `subprocess` standard library. The title is grossly misrepresentative, and the substance is missing the point. There is nothing special about Python here; causing a string to contain quotes works much the same way as in other popular languages. Besides, `subprocess.run` et. al. make use of the shell opt-in; the default behaviour is to pass arguments to a named executable directly. Typically, correct function requires those arguments not to have quotes (for the shell to remove them, among other processing, when the shell is used). The article then spends way too long, and too much formatting, on explaining what is really a very simple concept. We don't need a "part" for every few sentences and code example.

The "koan" presentation also strikes me as very strange for a simple warning about a practical security risk. There is no need for deep philosophical thinking here. Just recognize the problem and follow the associated best practices.

Regarding the CVE, it's hard to imagine a circumstance in which an "attacker-controlled virtual environment" isn't already game over. In fact, the exploit relies on the attacker being able to create a virtual environment, which in any normal situation already implies full shell access. An exploit like this is basically only relevant to a situation in which party A exposes an interface to party B for creating virtual environments, then expects party C to run code in the resulting environment. So, basically, people providing third-party CI systems, which are already fraught with trust and supply-chain issues. And even then, using virtual environments doesn't generally require the activation script at all, and well-written automation probably shouldn't use it, because it needlessly introduces a state dependency.

A Closer Look Inside a Robot's Typewriter-Inspired Mouth

https://hackaday.com/2025/09/15/a-closer-look-inside-a-robots-typewriter-inspired-mouth/
1•warrenm•1m ago•0 comments

The Awe Keeps Dropping

https://morrick.me/archives/10137
3•mgrayson•7m ago•0 comments

The Sagrada Família Takes Its Final Shape

https://www.newyorker.com/magazine/2025/09/22/is-the-sagrada-familia-a-masterpiece-or-kitsch
1•pseudolus•7m ago•1 comments

TCG Automate – Scan and Identify Your Trading Cards and List to eBay in Seconds

https://www.tcgautomate.com
1•asassine•9m ago•0 comments

Helping Doug

https://theamericanscholar.org/helping-doug/
2•gmays•17m ago•0 comments

Switchborn – 007 – The Endgame You Forgot [video]

https://www.youtube.com/watch?v=q1OldPGF2mI
1•marcusfrex•20m ago•1 comments

The builder who photographed distant galaxies

https://www.bbc.com/news/articles/crkj08kmd67o
1•1659447091•23m ago•0 comments

Visualizing Algorithms (2014)

https://bost.ocks.org/mike/algorithms/
2•shminge•28m ago•0 comments

Lobbying and Regulatory Strategies of US Autonomous Vehicles Companies

https://cardog.app/blog/autonomous-vehicle-lobbying
1•samsullivan•38m ago•0 comments

Namibia's Caprivi Strip Exists Because the Germans Forgot Victoria Falls

https://www.cntraveler.com/stories/2013-03-04/caprivi-strip-namibia-zimbabwe-maphead-ken-jennings
2•nothrowaways•39m ago•0 comments

Thank HN: Rainbows End

4•cl42•39m ago•1 comments

Treat the AI like it's yourself

https://ryanglover.net/blog/treat-the-ai-like-it-s-yourself
1•rglover•42m ago•0 comments

Careless engineer stored recovery codes in plaintext, got whole org pwned

https://www.theregister.com/2025/09/15/ransomware_recovery_codes_plaintext/
2•Bender•49m ago•1 comments

After years of strife, AFRINIC has elected a board. Now the hard work begins

https://www.theregister.com/2025/09/15/afrinic_election_called_what_next/
1•Bender•50m ago•0 comments

Free Online Traceroute Tool

https://tracerouteai.com
1•wantering•54m ago•0 comments

Most Work Is Translation

https://aparnacd.substack.com/p/most-work-is-translation
2•jger15•54m ago•0 comments

Fighting human trafficking with self-contained applications

https://lwn.net/SubscriberLink/1036916/2b10f1356b7ab0e7/
5•chmaynard•56m ago•1 comments

PlugAndData – plug‑and‑play data pipeline with automatic interface generation

https://pluganddata.com/
1•DanielPlugnData•56m ago•1 comments

Post-quantum security for SSH access on GitHub

https://github.blog/engineering/platform-security/post-quantum-security-for-ssh-access-on-github/
3•fcambus•56m ago•0 comments

A smart AI personal executive assistant

https://www.pulse-ai.world/
2•xisen•57m ago•2 comments

Active NPM supply chain attack: Tinycolor and 40 Packages Compromised

https://socket.dev/blog/tinycolor-supply-chain-attack-affects-40-packages
27•feross•58m ago•4 comments

Roblox and Discord sued after teen's suicide, joining wave of litigation

https://www.independent.co.uk/news/world/americas/roblox-discord-lawsuit-teen-suicide-b2826315.html
2•donsupreme•1h ago•0 comments

Keeping SSH sessions alive with systemd-inhibit

https://kd8bny.com/posts/session_inhibit/
2•kd8bny•1h ago•0 comments

Project Linework – Stylized Vector World Maps

https://www.projectlinework.org/
1•oliverkwebb•1h ago•0 comments

The Shepherd: Minimalism in PID 1 [video]

https://fosdem.org/2025/schedule/event/fosdem-2025-5720-the-shepherd-minimalism-in-pid-1/
1•pykello•1h ago•0 comments

Why do software developers love complexity?

https://kyrylo.org/software/2025/08/21/why-do-software-developers-love-complexity.html
33•PaulHoule•1h ago•42 comments

Alarm and Overload

https://novum.substack.com/p/two-media-tactics-of-the-2020s
2•paulpauper•1h ago•0 comments

Science of Chess: What does it mean to have a "chess personality?"

https://lichess.org/@/NDpatzer/blog/science-of-chess-what-does-it-mean-to-have-a-chess-personalit...
1•tech_ken•1h ago•0 comments

Show HN: Summarize Any Article, Paper, or Video in 5 Bullet Points

https://unrav.io/summarize
4•rriley•1h ago•0 comments

Show HN: Labspace Directory – Biotech resource for lab space

https://www.labspacedirectory.com
2•ejhodges•1h ago•0 comments