[Python-Dev] PYTHONHTTPSVERIFY env var

Chris Angelico rosuav at gmail.com
Sun May 10 01:44:13 CEST 2015


On Sun, May 10, 2015 at 4:13 AM, M.-A. Lemburg <mal at egenix.com> wrote:
> By providing a way to intentionally switch off the new default,
> we do make people aware of the risks and that's good enough,
> while still maintaining the contract people rightly expect of
> patch level releases of Python.

Just as long as it's the sysadmin, and NOT some random attacker over
the internet, who has the power to downgrade security. Environment
variables can be attacked in various ways.

ChrisA


More information about the Python-Dev mailing list