Live data from Hacker News

Pysa: An open source tool to detect and prevent security issues in Python code

engineering.fb.com

11–20 of 28 posts

Re: Pysa: An open source tool to detect and prevent security issues in Python code

#11
post #9

Earlier quoted context omitted.

How fast does Pysa typically run? If I want to run it as part of my CI system, how much additional time might I expect it to add? Obviously this varies from code base to code base, but I'm curious what the experience at Instagram is like?

For Instagram (millions of LOC), the analysis gives feedback to engineers in about 65 minutes on average - note that this is in the context of a diff run: We compare the results of a run on the base revision to the proposed changes, running the tool once or twice depending on whether we hit the cache. It's hard to say how long it'll take on your repository as it depends on a lot of factors, but hopefully that provide…

That's super helpful. I'm currently at Eventbrite, and we're probably in the same order of magnitude.

Re: Pysa: An open source tool to detect and prevent security issues in Python code

#12

One of the authors of the blog post and software engineer working on Pysa here - happy to answer any questions you may have :)

Python 2 and 3 or 3 only? I looked for this on the linked site, and it wasn't immediately obvious.

Re: Pysa: An open source tool to detect and prevent security issues in Python code

#13
post #12

One of the authors of the blog post and software engineer working on Pysa here - happy to answer any questions you may have :)

Python 2 and 3 or 3 only? I looked for this on the linked site, and it wasn't immediately obvious.

Pyre & Pysa try to do a best-effort analysis of Python 2, and supports Python 2 style taint annotations, but most of the code we analyze at Facebook is Python 3.6+.

Re: Pysa: An open source tool to detect and prevent security issues in Python code

#14
post #6

One of the authors of the blog post and software engineer working on Pysa here - happy to answer any questions you may have :)

Does Pysa require the code to be fully type hinted? or will it work on non-type hinted code also?

In addition to what Sinan said, we've had success running on fully untyped codebases. These are you some strategies that you can use to get results on untyped codebases: https://pyre-check.org/docs/pysa-coverage.html

Types will definitely make Pysa find more issues, but you don't need 100% coverage, or really more than the minimal coverage described in that doc I linked, to start finding some issues.

Re: Pysa: An open source tool to detect and prevent security issues in Python code

#15

One of the authors of the blog post and software engineer working on Pysa here - happy to answer any questions you may have :)

Not sure if you can answer this, but what are some classes of security bugs you can find with Pysa? I've only worked on smaller codebases so security I've dealt with is mostly AuthN/AuthZ.

Re: Pysa: An open source tool to detect and prevent security issues in Python code

#16

One of the authors of the blog post and software engineer working on Pysa here - happy to answer any questions you may have :)

Not sure if you can answer this, but what are some classes of security bugs you can find with Pysa? I've only worked on smaller codebases so security I've dealt with is mostly AuthN/AuthZ.

You can find most of security issues with Pysa that you can model as a taint flow problem. Examples could be flows to function that enable code execution or shell injection, SQL injection, SSRF, XSS and many others. As long as you can model the security issue in a taint-flow model then Pysa should be able to detect these issues. These are the configuration we share with Pysa where you can find examples of bug categories we detect https://github.com/facebook/pyre-check/blob/master/stubs/tai...

Re: Pysa: An open source tool to detect and prevent security issues in Python code

#17

One of the authors of the blog post and software engineer working on Pysa here - happy to answer any questions you may have :)

Not sure if you can answer this, but what are some classes of security bugs you can find with Pysa? I've only worked on smaller codebases so security I've dealt with is mostly AuthN/AuthZ.

Pysa can find any bug that you can model as a flow of data from one place to another. That includes your standard web app bugs like SQLi, RCE, etc., also some AuthN/AuthZ bugs depending on how you do your checks. Concretely, this is a list of the vulnerabilities Pysa able to catch out of the box without any customization: https://github.com/facebook/pyre-check/blob/6975ff55fc59b7b9...

Re: Pysa: An open source tool to detect and prevent security issues in Python code

#18

One of the authors of the blog post and software engineer working on Pysa here - happy to answer any questions you may have :)

This is very interesting work. I've been looking for something exactly like this to use on a large C application -- specifically to be able to annotate various API's as sources of different kinds of data, checks on how the data types are permitted to be used together, and operations that transform one kind to another. Compared to taint analysis we want to allow more categories than tainted/untainted, and transforming items between categories. Do you have any recommendations for similar tools that work with C?

Re: Pysa: An open source tool to detect and prevent security issues in Python code

#20
post #19

One of the authors of the blog post and software engineer working on Pysa here - happy to answer any questions you may have :)

What is the story behind the name? Was that always the name?

It reminds me of the Spanish word "paisa"...
Post reply on HN