Third High Severity CVE in Log4j Is Published
logging.apache.org
Third High Severity CVE in Log4j Is Published
1–10 of 335 posts
Re: Third High Severity CVE in Log4j Is Published
#2I hope you step on a Lego.
Re: Third High Severity CVE in Log4j Is Published
#3On behalf of all information security people everywhere, I want to thank Apache for all the wonderful Christmas presents this year. I hope you step on a Lego.
The disclosure process was terrible, they clearly had no time to perform a thorough validation of the hotfixes, and this is the result. Why didn't anybody else step up to help them? Did any of the large companies using log4j pour some thousand dollars into the Apache foundation to let a couple of security-oriented engineers take a complete review of the patches?
But then, it's log4j developers and Apache that should be blamed. Bah. That's SO pretentious.
Re: Third High Severity CVE in Log4j Is Published
#4We won't hold a grudge against you; open source means collaboration, and you don't blame hard-working people that give away their software for free for honest mistakes. Your software still did far more good than bad to the software world.
Thanks!
Re: Third High Severity CVE in Log4j Is Published
#5On behalf of all information security people everywhere, I want to thank Apache for all the wonderful Christmas presents this year. I hope you step on a Lego.
This attitude should stop. They're volunteers. It's open source. Users are required to use such piece of software at their own will and risk. Log4j didn't ever get a single penny from most (all?) of their users, and now they should take all the blame. Why? The disclosure process was terrible, they clearly had no time to perform a thorough validation of the hotfixes, and this is the result. Why didn't anybody else ste…
Um, yeah. They wrote the idiotic code that allowed this to happen. Who should get the blame then, the users? Duh, no. Should the hackers taking advantage of the exploit? Maybe, some, but they wouldn't be able to do it if the code wasn't so badly wrritten.
>Why didn't anybody else step up to help them?
To me, this is the pretentious part. I didn't write the code, I don't use the code, so why in the world should I be expected to fix the code? Do you use the code? Why didn't YOU fix it?
Re: Third High Severity CVE in Log4j Is Published
#6On behalf of all information security people everywhere, I want to thank Apache for all the wonderful Christmas presents this year. I hope you step on a Lego.
This attitude should stop. They're volunteers. It's open source. Users are required to use such piece of software at their own will and risk. Log4j didn't ever get a single penny from most (all?) of their users, and now they should take all the blame. Why? The disclosure process was terrible, they clearly had no time to perform a thorough validation of the hotfixes, and this is the result. Why didn't anybody else ste…
Re: Third High Severity CVE in Log4j Is Published
#7On behalf of all information security people everywhere, I want to thank Apache for all the wonderful Christmas presents this year. I hope you step on a Lego.
Re: Third High Severity CVE in Log4j Is Published
#8On behalf of all information security people everywhere, I want to thank Apache for all the wonderful Christmas presents this year. I hope you step on a Lego.
Re: Third High Severity CVE in Log4j Is Published
#9Re: Third High Severity CVE in Log4j Is Published
#10Earlier quoted context omitted.
This attitude should stop. They're volunteers. It's open source. Users are required to use such piece of software at their own will and risk. Log4j didn't ever get a single penny from most (all?) of their users, and now they should take all the blame. Why? The disclosure process was terrible, they clearly had no time to perform a thorough validation of the hotfixes, and this is the result. Why didn't anybody else ste…
>But then, it's log4j developers and Apache that should be blamed. Bah. That's SO pretentious. Um, yeah. They wrote the idiotic code that allowed this to happen. Who should get the blame then, the users? Duh, no. Should the hackers taking advantage of the exploit? Maybe, some, but they wouldn't be able to do it if the code wasn't so badly wrritten. >Why didn't anybody else step up to help them? To me, this is the pre…
> who should get the blame? The users?
If you leverage a ton of open source deps, shit is going to happen. You should not blame anyone.
But if you must, yes: blame the users that choose such piss-poor software.