CISA Director on Log4j Vulnerability
1–10 of 85 posts
Re: CISA Director on Log4j Vulnerability
#2Re: CISA Director on Log4j Vulnerability
#3I’m sure this is the only community that might pay attention to a software BOM as mentioned in the article, but this is a great idea and makes a lot of sense (to me as a consumer at least).
I’d like to say the scanners were fast but not fast enough because the first wave of attacks was nearly instant. This was definitely a nightmare scenario where a simple unauthenticated GET could pull in a kit that was already live and ready to go.
Re: CISA Director on Log4j Vulnerability
#4I’m sure this is the only community that might pay attention to a software BOM as mentioned in the article, but this is a great idea and makes a lot of sense (to me as a consumer at least).
Developers are relying more and more on automated scanners and the likes to manage this. Your modern python or javaScript stack just has way too many packages and they change daily. Just look at your dependency lockfile balloon when a random dependency updates a point and brings in a few more packages. It’s really a horrible thing. I’d like to say the scanners were fast but not fast enough because the first wave of a…
Re: CISA Director on Log4j Vulnerability
#5Re: CISA Director on Log4j Vulnerability
#6Re: CISA Director on Log4j Vulnerability
#7Shouldn’t this be happening, like, yesterday?
Re: CISA Director on Log4j Vulnerability
#8Re: CISA Director on Log4j Vulnerability
#9Unless they spell out how they proactively support the one man hobbyist maintainer I don't believe them. https://xkcd.com/2347
Re: CISA Director on Log4j Vulnerability
#10“we are also convening a national call with critical infrastructure stakeholders on Monday afternoon” Shouldn’t this be happening, like, yesterday?