Live data from Hacker News

Third High Severity CVE in Log4j Is Published

logging.apache.org

1–10 of 335 posts

Re: Third High Severity CVE in Log4j Is Published

#3
post #2

On behalf of all information security people everywhere, I want to thank Apache for all the wonderful Christmas presents this year. I hope you step on a Lego.

This attitude should stop. They're volunteers. It's open source. Users are required to use such piece of software at their own will and risk. Log4j didn't ever get a single penny from most (all?) of their users, and now they should take all the blame. Why?

The disclosure process was terrible, they clearly had no time to perform a thorough validation of the hotfixes, and this is the result. Why didn't anybody else step up to help them? Did any of the large companies using log4j pour some thousand dollars into the Apache foundation to let a couple of security-oriented engineers take a complete review of the patches?

But then, it's log4j developers and Apache that should be blamed. Bah. That's SO pretentious.

Re: Third High Severity CVE in Log4j Is Published

#4
Thanks to all Log4j developers. As users of your free software since ~20 years, we're sure that, if this vuln disclosure had been better and there were no sign of widespread in-the-wild exploitation, you would have done a better job at patching it, and a single release would have been enough.

We won't hold a grudge against you; open source means collaboration, and you don't blame hard-working people that give away their software for free for honest mistakes. Your software still did far more good than bad to the software world.

Thanks!

Re: Third High Severity CVE in Log4j Is Published

#5
post #2

On behalf of all information security people everywhere, I want to thank Apache for all the wonderful Christmas presents this year. I hope you step on a Lego.

This attitude should stop. They're volunteers. It's open source. Users are required to use such piece of software at their own will and risk. Log4j didn't ever get a single penny from most (all?) of their users, and now they should take all the blame. Why? The disclosure process was terrible, they clearly had no time to perform a thorough validation of the hotfixes, and this is the result. Why didn't anybody else ste…

>But then, it's log4j developers and Apache that should be blamed. Bah. That's SO pretentious.

Um, yeah. They wrote the idiotic code that allowed this to happen. Who should get the blame then, the users? Duh, no. Should the hackers taking advantage of the exploit? Maybe, some, but they wouldn't be able to do it if the code wasn't so badly wrritten.

>Why didn't anybody else step up to help them?

To me, this is the pretentious part. I didn't write the code, I don't use the code, so why in the world should I be expected to fix the code? Do you use the code? Why didn't YOU fix it?

Re: Third High Severity CVE in Log4j Is Published

#6
post #2

On behalf of all information security people everywhere, I want to thank Apache for all the wonderful Christmas presents this year. I hope you step on a Lego.

This attitude should stop. They're volunteers. It's open source. Users are required to use such piece of software at their own will and risk. Log4j didn't ever get a single penny from most (all?) of their users, and now they should take all the blame. Why? The disclosure process was terrible, they clearly had no time to perform a thorough validation of the hotfixes, and this is the result. Why didn't anybody else ste…

Log4J is bigger than all of V7 Unix. What do you need all that for?

Re: Third High Severity CVE in Log4j Is Published

#7
post #2

On behalf of all information security people everywhere, I want to thank Apache for all the wonderful Christmas presents this year. I hope you step on a Lego.

Having worked with security-minded institutions in the past, I've endured and participated in year(s)-long audits of three different open source software projects. The thing that amazes me is that nobody using this software ever did their due diligence. You literally get what you pay for. Kindly step on your own legos and be happy this didn't happen in early April.

Re: Third High Severity CVE in Log4j Is Published

#8
post #2

On behalf of all information security people everywhere, I want to thank Apache for all the wonderful Christmas presents this year. I hope you step on a Lego.

On behalf of open source software developers, go pay for commercial software yourself.

Re: Third High Severity CVE in Log4j Is Published

#9
If information security people would spend the same amount of time they are spending complaining about this vulnerability trying to educate their organisations on the importance of supporting open source solutions they depend on we wouldn’t be in this situation. I am sick of reading of very senior people complaining about the impact this vulnerability has had on their week when their companies don’t even contribute a penny to open source projects.

Re: Third High Severity CVE in Log4j Is Published

#10
post #5

Earlier quoted context omitted.

This attitude should stop. They're volunteers. It's open source. Users are required to use such piece of software at their own will and risk. Log4j didn't ever get a single penny from most (all?) of their users, and now they should take all the blame. Why? The disclosure process was terrible, they clearly had no time to perform a thorough validation of the hotfixes, and this is the result. Why didn't anybody else ste…

>But then, it's log4j developers and Apache that should be blamed. Bah. That's SO pretentious. Um, yeah. They wrote the idiotic code that allowed this to happen. Who should get the blame then, the users? Duh, no. Should the hackers taking advantage of the exploit? Maybe, some, but they wouldn't be able to do it if the code wasn't so badly wrritten. >Why didn't anybody else step up to help them? To me, this is the pre…

If you don’t use the code, you’re not vulnerable

> who should get the blame? The users?

If you leverage a ton of open source deps, shit is going to happen. You should not blame anyone.

But if you must, yes: blame the users that choose such piss-poor software.

Post reply on HN