Live data from Hacker News

Third High Severity CVE in Log4j Is Published

logging.apache.org

11–20 of 335 posts

Re: Third High Severity CVE in Log4j Is Published

#11
post #5

Earlier quoted context omitted.

This attitude should stop. They're volunteers. It's open source. Users are required to use such piece of software at their own will and risk. Log4j didn't ever get a single penny from most (all?) of their users, and now they should take all the blame. Why? The disclosure process was terrible, they clearly had no time to perform a thorough validation of the hotfixes, and this is the result. Why didn't anybody else ste…

>But then, it's log4j developers and Apache that should be blamed. Bah. That's SO pretentious. Um, yeah. They wrote the idiotic code that allowed this to happen. Who should get the blame then, the users? Duh, no. Should the hackers taking advantage of the exploit? Maybe, some, but they wouldn't be able to do it if the code wasn't so badly wrritten. >Why didn't anybody else step up to help them? To me, this is the pre…

I don't understand what the problem is if you don't use the code. Why does it matter to you if it gets fixed?

Re: Third High Severity CVE in Log4j Is Published

#12
post #9

If information security people would spend the same amount of time they are spending complaining about this vulnerability trying to educate their organisations on the importance of supporting open source solutions they depend on we wouldn’t be in this situation. I am sick of reading of very senior people complaining about the impact this vulnerability has had on their week when their companies don’t even contribute a…

> educate their organisations on the importance of supporting open source solutions

Githubs of the world could just gate downloads, pull requests etc. behind a payment to see what is the real valuation of open source software; I imagine it'd mostly settle around $0 excluding couple of big projects.

Re: Third High Severity CVE in Log4j Is Published

#13

Thanks to all Log4j developers. As users of your free software since ~20 years, we're sure that, if this vuln disclosure had been better and there were no sign of widespread in-the-wild exploitation, you would have done a better job at patching it, and a single release would have been enough. We won't hold a grudge against you; open source means collaboration, and you don't blame hard-working people that give away th…

Thanks to Log4J developers for turning me off to Java 20yrs ago due to their horrible API design and developer experience. Does not shock me that this security vulnerability happened, but it did shock me that so many people kept using this awful library.

I thus enjoyed a development career (mostly) free from this kind of needless pain and suffering.

Re: Third High Severity CVE in Log4j Is Published

#14

Thanks to all Log4j developers. As users of your free software since ~20 years, we're sure that, if this vuln disclosure had been better and there were no sign of widespread in-the-wild exploitation, you would have done a better job at patching it, and a single release would have been enough. We won't hold a grudge against you; open source means collaboration, and you don't blame hard-working people that give away th…

Thanks to Log4J developers for turning me off to Java 20yrs ago due to their horrible API design and developer experience. Does not shock me that this security vulnerability happened, but it did shock me that so many people kept using this awful library. I thus enjoyed a development career (mostly) free from this kind of needless pain and suffering.

The options at the time were even worse.

Re: Third High Severity CVE in Log4j Is Published

#15

Thanks to all Log4j developers. As users of your free software since ~20 years, we're sure that, if this vuln disclosure had been better and there were no sign of widespread in-the-wild exploitation, you would have done a better job at patching it, and a single release would have been enough. We won't hold a grudge against you; open source means collaboration, and you don't blame hard-working people that give away th…

Thanks to Log4J developers for turning me off to Java 20yrs ago due to their horrible API design and developer experience. Does not shock me that this security vulnerability happened, but it did shock me that so many people kept using this awful library. I thus enjoyed a development career (mostly) free from this kind of needless pain and suffering.

log4j2 has little to do with the log4j you claim turned you off 20 years ago and almost no one works directly to the logging library API rather than an slf4j facade.

Re: Third High Severity CVE in Log4j Is Published

#16
post #7
post #2

On behalf of all information security people everywhere, I want to thank Apache for all the wonderful Christmas presents this year. I hope you step on a Lego.

Having worked with security-minded institutions in the past, I've endured and participated in year(s)-long audits of three different open source software projects. The thing that amazes me is that nobody using this software ever did their due diligence. You literally get what you pay for. Kindly step on your own legos and be happy this didn't happen in early April.

> The thing that amazes me is that nobody using this software ever did their due diligence.

How could they be expected to? Reviewing all of the source code for log4j is not a walk in the park. Even if you thoroughly reviewed all the source code, would this specific exploit have crossed your mind?

The game theory and assumptions around a "logging" library probably led a lot of organizations to not even consider it a potential threat and focus their efforts elsewhere.

There is also the transitive dependency angle which turns this into more of a plague than a blame assignment session.

Re: Third High Severity CVE in Log4j Is Published

#17

Earlier quoted context omitted.

Thanks to Log4J developers for turning me off to Java 20yrs ago due to their horrible API design and developer experience. Does not shock me that this security vulnerability happened, but it did shock me that so many people kept using this awful library. I thus enjoyed a development career (mostly) free from this kind of needless pain and suffering.

log4j2 has little to do with the log4j you claim turned you off 20 years ago and almost no one works directly to the logging library API rather than an slf4j facade.

Fair enough. But to me it was the smell of a toxic Java ecosystem, where people had to use crappy software even though they knew how bad it was.

It took a simple problem and turned it into a clusterfuck of configuration and complexity.

Re: Third High Severity CVE in Log4j Is Published

#18
post #5

Earlier quoted context omitted.

This attitude should stop. They're volunteers. It's open source. Users are required to use such piece of software at their own will and risk. Log4j didn't ever get a single penny from most (all?) of their users, and now they should take all the blame. Why? The disclosure process was terrible, they clearly had no time to perform a thorough validation of the hotfixes, and this is the result. Why didn't anybody else ste…

>But then, it's log4j developers and Apache that should be blamed. Bah. That's SO pretentious. Um, yeah. They wrote the idiotic code that allowed this to happen. Who should get the blame then, the users? Duh, no. Should the hackers taking advantage of the exploit? Maybe, some, but they wouldn't be able to do it if the code wasn't so badly wrritten. >Why didn't anybody else step up to help them? To me, this is the pre…

> Um, yeah. They wrote the idiotic code that allowed this to happen.

And released it with NO WARRANTY. And no mega corp thought it’d be a good idea to try and buy one.

> To me, this is the pretentious part. I didn't write the code, I don't use the code, so why in the world should I be expected to fix the code? Do you use the code? Why didn't YOU fix it?

If you don’t use it, then noone’s expecting you to fix anything. But those out there using it for free, complaining that it’s broken, and not doing anything to help? They should hush their hush holes. Or open pull requests. But mostly hush their hush holes.

Re: Third High Severity CVE in Log4j Is Published

#19
post #11
post #5

Earlier quoted context omitted.

>But then, it's log4j developers and Apache that should be blamed. Bah. That's SO pretentious. Um, yeah. They wrote the idiotic code that allowed this to happen. Who should get the blame then, the users? Duh, no. Should the hackers taking advantage of the exploit? Maybe, some, but they wouldn't be able to do it if the code wasn't so badly wrritten. >Why didn't anybody else step up to help them? To me, this is the pre…

I don't understand what the problem is if you don't use the code. Why does it matter to you if it gets fixed?

Not approving of what OP said, I’d point out that everyone has an interest in it being fixed, because it’s a wide spread and severe CVE that impacts lots of software that we all probably use daily without knowing it.
Post reply on HN