Live data from Hacker News

LogJ4 Security Inquiry – Response Required

daniel.haxx.se

111–120 of 128 posts

Re: LogJ4 Security Inquiry – Response Required

#111
post #104

Earlier quoted context omitted.

It's not about open source maintainers. This isn't an "open source" problem further than the fact that Daniel's software is used in a product they are using. Daniel could take a couple of seconds to ignore this email and there was very little time wasted. The real "disrespect" should be whatever engineer put Daniel's name into the spreadsheet that blasted out these emails. Someone didn't do their job and is checking…

Daniel could take a couple of seconds to ignore this email and there was very little time wasted. So, in your opinion, sending spam or robocalls is not in the least bit disrespectful to whomever is on the receiving end?

Not in this context. This wasn't spam, this was a person with the information they had trying to close the loop on some information an engineer put into a a spreadsheet. This message was not "irrelevant" in the context that the person sending it had. This was not a robocall trying to extort money.

As I noted in another thread: A simple response pointing to the license should be the default response to requests like this which can be automated.

Re: LogJ4 Security Inquiry – Response Required

#112

OK, a large corporation legal team doesn't understand the nuance of ownership of open-source software. Do we mock every single open source guy who displays the same amount of cluelessness about the inner workings of a business because I see plenty of that displayed here and everywhere else.

I am sure their lawyers know exactly how software licenses work. I also bet that the list of dependencies they used for this mass email was probably not generated by a lawyer.

Yes, the idea that this company paid a lawyer to go through its tech stack and figure out who owns the code relied upon by the company is fairly ridiculous. Either a lawyer drafted a template email for the company to send to its suppliers, or a lawyer (read: intern) was given a list of suppliers to email on behalf of the company, or a lawyer wasn't involved at all.

But in software communities (and particularly in FOSS communities) tech people can do no wrong; every time a tech company does an aggressive or foolish or otherwise objectionable thing, there must be a dastardly lawyer somewhere pulling the strings.

Re: LogJ4 Security Inquiry – Response Required

#113
post #88

More accurately "a clueless IT lackey at a Fortune 500 company" sent the mail. I doubt the chairman was pounding the board table and barking "We demand answers from Haxx!"

It didn’t come from IT/engineering. This is legal/compliance.

It's signed off "Information Security". The template email might have been drafted by legal/compliance, but it is surely for the IT guys to figure out what code they use in their tech stack and lead those discussions.

Re: LogJ4 Security Inquiry – Response Required

#114
post #67

The document uses a monospace font, and the redacted name can be seen to be 10 characters long. Based on the 2019 Fortune 500 list, that gives these possible candidates: Activision, Alaska Air, Albertsons, Altice USA, Amazon.com, Ameriprise, AutoNation, BB&T Corp., Bed Bath &, Blackstone, Booz Allen, BorgWarner, Burlington, CBRE Group, Chesapeake, CMS Energy, CVS Health, Dean Foods, DTE Energy, Enterprise, Eversource…

From the article: "The email comes from a fortune-500 multi-billion dollar company that apparently might be using a product that contains my code, or maybe they have customers who do. Who knows?" The "or maybe they have customers who do" makes me think that this company must provide services to other companies, so probably not a Mcdonald's or Albertson's or something like that.

McDonalds provides services to other companies? that's the whole point of McDonalds?

Re: LogJ4 Security Inquiry – Response Required

#115

>>I answered the email very briefly and said I will be happy to answer with details as soon as we have a support contract signed. This made my day. If a wealthy individual takes your tools and then calls for help while fixing-up their shed with said tools, do not move a muscle until you agree on the fee.

I expect they'll gladly sign a support contract with Daniel.

As a commercial SaaS vendor we received these same emails from all of the major banks / insurance companies. It's interesting to see that we got some on the Monday after the issue was discovered and some a few weeks later, with some showing a clear understanding of the risk in the context of our product and some looking like a standard copy/paste. Gives you a rare behind-the-scenes view of the information security practices of these companies.

Re: LogJ4 Security Inquiry – Response Required

#116

> "Thank you for your reply. Are you saying that we are not a customer of your organization?" Isn't this the sort of question you'd ask your own side, first?

I would bet this was sent out to a list that was put together that contained all of their "partners" which was in turn compiled from various other spreadsheets. Including one that had a 'support contact' column, or something like that and they assumed any that had that value was a partner. Over the course of the 6 years that the sheet has been cut and paste in various formats, they completely lost where any of it came from in the first place.

Re: LogJ4 Security Inquiry – Response Required

#117
post #5

I wonder what their reply is about. They probably have no idea what/who they are really talking to, and it's probably not some kind of legal trap.

It's a reply to David/Daniels email to the F500 org. The dev didn't post a screenshot of their reply, but they mentioned this - "I answered the email very briefly and said I will be happy to answer with details as soon as we have a support contract signed."

There is a reply from the company at the bottom of the post.

Re: LogJ4 Security Inquiry – Response Required

#118
It reads like this was a form letter that was to be sent out to all their actual paid partners, and after the massive game of telephone that is corporate hierarchy, it somehow became all dependencies they had contacts for. And somewhere someone filled out a form, probably years ago, with his email on it as the maintainer of a dependency they use (because leaving it blank isn't allowed). And he got caught up in that mass email, totally dumb, but also could easily see how it can happen.

Re: LogJ4 Security Inquiry – Response Required

#119

Earlier quoted context omitted.

Understanding the nuances of ownership and who is responsible for what is quite an important skill for corporate lawyers.

If you are dealing with 1000s of cases, you can't apply nuances to every single of them. You are all are supposed to be smart software engineers. Probably know about pre-mature optimization and efficient path. Here's a secret about communications -- Mass emailing works and is very efficient. I'm sure you are the same person who rants about a recruiter reaching out to you even though you are the creator of Python. Rea…

> Here's a secret about communications -- Mass emailing works and is very efficient.

Especially for the sender.

Re: LogJ4 Security Inquiry – Response Required

#120
Is there a product out there that makes it easy for open source maintainers to offer enterprise support services?

I think support is probably the best way of making money from open source, but a lot of maintainers are unlikely to have everything set up to do so (business entities, contracts, ways to receive payment, probably a dozen other things that you'd never think of, etc.).

Like Stripe Atlas for open source consulting?

Post reply on HN