Sign in

Nina Zakharenko

@nina.codes
2.9K followers 210 following 246 posts

pythonista, dev, prev open source security @ google, prev board of directors of the PSF, recurse center alum. opinions my own. she/her

PostsRepliesMedia
Nina Zakharenko @nina.codes · 31/08/2026
Thank you Al. I’d be honored to serve on the board again. There are so many amazing candidates this year and only 4 open wears. I’m wishing everyone good luck.
060
Nina Zakharenko @nina.codes · 18/05/2026
Thanks for a great talk! I’m looking forward to checking out debug wand! github.com/savannahostr...
github.com
GitHub - savannahostrowski/debugwand: An *experimental* zero-preparation remote debugger for Python applications running in *local* Kubernetes clusters or Docker containers.
An *experimental* zero-preparation remote debugger for Python applications running in *local* Kubernetes clusters or Docker containers. - savannahostrowski/debugwand
040
Nina Zakharenko @nina.codes · 17/05/2026
@miketheman.com and @sethmlarson.dev share some of the accomplishments of the PSF security team this year. That’s a lot of work for two people! And shoutout to the sponsors who make it possible to fund their roles.
0124
Nina Zakharenko @nina.codes · 16/05/2026
Now up at #PyconUS is Core Python Dev @savannah.dev talking about the Art of Live Process Manipulation
1111
Nina Zakharenko @nina.codes · 16/05/2026
And again, thank you to Alpha Omega and @openssf.org for funding PyPI Security. 🎉 openssf.org/community/al...
060
Nina Zakharenko @nina.codes · 16/05/2026
As a maintainer, move to trusted publishing and let go of long-lived tokens. docs.pypi.org/trusted-publ...
131
Nina Zakharenko @nina.codes · 16/05/2026
The attackers tried again 2 months later. So what can you do to spot phishing attacks? 1. Move to WebAuthn / passkeys 2. Let your password manager be the judge. It won’t autofill without extra verification if the domain mismatches. 3. Hover before you click. Especially on mobile.
110
Nina Zakharenko @nina.codes · 16/05/2026
Financial support from AlphaOmega means there’s paid staff on hand for incident response. (That’s Mike) That means the responsibility doesn’t fall to volunteers or open source maintainers.
110
Nina Zakharenko @nina.codes · 16/05/2026
PyPI required 2 factor for all maintainers in January of 2024. Two factor is better, but still phishable. But WebAuthn (aka passkeys) are resistant because the signing process fails for a domain that doesn’t match. And there’s no new security education required.
110
Nina Zakharenko @nina.codes · 16/05/2026
Thousands of daily downloads a day isn’t bad, right? But this library was a dependency in the HuggingFace transformers library. With 30 MILLION downloads a day. And the dependency wasn’t pinned.
110
Nina Zakharenko @nina.codes · 16/05/2026
Of four compromised accounts, num2words was the most popular, with thousands of daily downloads. If your version wasn’t pinned, you were downloading malware. The attacker was able to generate their own API tokens, This mirrored an attack on npm a few weeks prior.
110
Nina Zakharenko @nina.codes · 16/05/2026
Getting a malicious domain taken down is not straightforward or fast. Services like Google Safe Browsing took weeks to update.
110
Nina Zakharenko @nina.codes · 16/05/2026
The attack came in the form of a sophisticated man-in-the-middle attack. All headers and traffic were passed on to PyPI as normal. But now the attackers have a valid session and can take actions on your behalf until the session expires.
130
Nina Zakharenko @nina.codes · 16/05/2026
If you can phish one maintainer, you could potentially ship malware to countless others. As a package maintainer, your email address is probably in your package metadata, or publicly visible on your GitHub profile. Would you catch this on your phone?
A slide showing the difference of a link to pypi.org versus a very similar but malicious URL
110
Nina Zakharenko @nina.codes · 16/05/2026
Right now at the #pyconus security track is @miketheman.com from the PSF talking about the anatomy of a PyPI phishing attack. Room 103ABC
190
Reposted by Nina Zakharenko
Juanita Gomez @juanitagomezr.bsky.social · 04/05/2026
I'm so excited to be chairing the newly launched Security Track at PyCon US with Seth! We have amazing speakers and talks for everyone interested in securing the Python ecosystem 🙌
0146
Nina Zakharenko @nina.codes · 13/05/2026
See you there!
010
Nina Zakharenko @nina.codes · 13/05/2026
See you there!
000
Nina Zakharenko @nina.codes · 11/05/2026
Alright, who’s going to PyCon this weekend?
350
Reposted by Nina Zakharenko
William Woodruff (1.3.6.1.4.1.55738) @yossarian.net · 11/04/2026
Brocards for vulnerability triage blog.yossarian.net/2026/04/11/Broca… #security #oss
2106
Nina Zakharenko @nina.codes · 14/04/2026
Seven injured her toe and had to be put under. Here she is afterwards, trapped in a cone of shame, high as a kite.
White dog wearing a plastic e-collar staring into space
340
Reposted by Nina Zakharenko
Seth Larson @sethmlarson.dev · 13/11/2025
“Trailblazin’ Python Security” at #PyConUS 2026! 🔥🏕️ I’m co-hosting the NEW security-themed talk track at PyCon US 2026 with @juanitagomezr.bsky.social and @nnja.bsky.social and we need your talks!! CFP open until December 19th, submit your #Python #Security talks now: us.pycon.org/2026/speakin...
us.pycon.org
Proposing a Talk
PyCon US 2026
098
Nina Zakharenko @nina.codes · 24/05/2025
I recently had an issue with an Uber ride, and could not get through to a person. I couldn’t even get the AI chatbot to give me a phone number. It politely told me to get lost. I guess it’s just the lesser of two evils, but I uninstalled the app and switched to Lyft.
020
Nina Zakharenko @nina.codes · 24/05/2025
I sprained my neck getting a massage so I feel ya
000
Nina Zakharenko @nina.codes · 24/05/2025
I loved that show so much, I was so heartbroken when it was cancelled.
110
Nina Zakharenko @nina.codes · 19/08/2023
I even react to cassava flour, which is supposed to be allergen friendly. Other culprits could be yeast or nickel-containing foods. The most frustrating thing has been that every single test has come back normal. I’m happy to DM if you’d like to chat about it.
000
Nina Zakharenko @nina.codes · 19/08/2023
I’ve developed a lot of similar issues. This might be a clue… it could be a symptom of long Covid or post-viral illness. www.goodforyouglutenfree.com/celiac…
A screenshot of text describing sensitivity to grains as a long Covid symptom.
100
Nina Zakharenko @nina.codes · 03/08/2023
Was it full of kids? I’ve been debating doing this.
110
Nina Zakharenko @nina.codes · 01/08/2023
Congratulations Ashley! GitHub is lucky to have you.
010
Nina Zakharenko @nina.codes · 31/07/2023
While they might not know how to bypass it, they should check the intranet for how to request account help. I think there might be a path forward.
110
Nina Zakharenko @nina.codes · 31/07/2023
Thanks for the summary. Glad to see that hasn’t changed!
010
Nina Zakharenko @nina.codes · 21/05/2023
Danger butts
010
Nina Zakharenko @nina.codes · 21/05/2023
If you’re scratching up your keyboards you might have bigger problems
000
Nina Zakharenko @nina.codes · 20/05/2023
I have a similar book from 1977!
000
Nina Zakharenko @nina.codes · 20/05/2023
@therealfitz.com
120
Nina Zakharenko @nina.codes · 19/05/2023
Or unmade it rather 😅
010
Nina Zakharenko @nina.codes · 19/05/2023
“I did this. I made this.”
110
Nina Zakharenko @nina.codes · 19/05/2023
Loving the feed full of delightful selfies this morning. Great idea @bnb.im
120
Nina Zakharenko @nina.codes · 19/05/2023
A very cathartic activity between jobs!
000
Nina Zakharenko @nina.codes · 19/05/2023
Thank you for this! It’s simple enough even I can follow it.
000
Nina Zakharenko @nina.codes · 19/05/2023
One of my favorites. I smashed that car in the background.
291
Nina Zakharenko @nina.codes · 19/05/2023
Even Mr. The Plague turned into the worst version of himself.
010
Nina Zakharenko @nina.codes · 19/05/2023
Also curious 👀 every time I try to dive into that world I get overwhelmed by all the options
110
Nina Zakharenko @nina.codes · 19/05/2023
Hashtags don’t work yet, but I believe they’re on the roadmap. Also, welcome! 👋
030
Nina Zakharenko @nina.codes · 18/05/2023
Another favorite look: sequin + blazer. I’ve rented this one and it’s also comfortable + stretchy. No pockets though.
000
Nina Zakharenko @nina.codes · 18/05/2023
Right? And pockets! If you end up trying it ask a friend for a referral code. Or I can DM you a link on birdsite.
000
Nina Zakharenko @nina.codes · 18/05/2023
Second best thing is you don’t have crap cluttering up your closet you’re never going to wear again because by the time the next fancy pants event rolls around you’re yet a different size and your tastes have changed
000
Nina Zakharenko @nina.codes · 18/05/2023
Best thing is most items on RTR has user reviews with photos of real people wearing the items. And you can sort by measurements similar to yours. Also, dunno how you feel about shiny but sequin sweatpants are a thing…
100
Nina Zakharenko @nina.codes · 18/05/2023
It’s a great way to evaluate what you even like anymore. Pre-Covid I’d squeeze myself into stupid dresses and high heels. Post-Covid if it’s not stretchy I won’t last more than half an hour.
100
Nina Zakharenko @nina.codes · 18/05/2023
Rent the runway. If you sign up for a high-end membership for a month you can order a bunch of different options to try on. They event have a decent selection of suits although your size in top + bottom might not be available.
100