Live data from Hacker News

LogJ4 Security Inquiry – Response Required

daniel.haxx.se

121–128 of 128 posts

Re: LogJ4 Security Inquiry – Response Required

#121
post #93

Earlier quoted context omitted.

If there's no expired support contract, that would be making a false statement of fact in order to get someone to sign a contract and pay me money. It's plausible that that would be fraud. Of course it's also plausible that that's not fraud at all. But I have no way to know for sure unless I ask a lawyer, which needless to say I wouldn't do. And if it turns out that it is fraud, well, the legal department of Fortune…

Opensource license is a form of contract. I provide free 5 minute support to new users. And good luck suing me if I am not even US/EU based. Departments (small managers) are authorized to spend small money without approval, lets say up to 200 euro/month. If they send this type of emails, someone ass is on fire. They will DO spend it just to get legal green light. Anyway, I do not see reason to hold back, just because…

Why would you lie about a contract being expired when you could just say, "this software is provided without warranty (see license) - I offer support services starting at $X/day" and likely see the same result?

Re: LogJ4 Security Inquiry – Response Required

#122
post #88

More accurately "a clueless IT lackey at a Fortune 500 company" sent the mail. I doubt the chairman was pounding the board table and barking "We demand answers from Haxx!"

It didn’t come from IT/engineering. This is legal/compliance.

Even more clueless then!

Re: LogJ4 Security Inquiry – Response Required

#123
post #50

"...The level of ignorance and incompetence shown in this single email is mind-boggling...no code I’ve ever been involved with or have my copyright use log4j and any rookie or better engineer could easily verify that..." Yeah, well, I've been quite shocked how rookie some F500 devs can be and how dysfunctional large corporations can also be. Probably what happened here is someone wrote a script that compiled the depe…

When I worked at a large, but not F500, company I had to once every 6-12 month or so fill in a spreadsheet with all third-party dependencies, with their licenses and some other info, the project I was working on used. I then emailed this to a mystery person and never heard anything back ever. I can easily see someone pulling out these spreadsheets and just emailing away without any developer, rookie or otherwise, bei…

Your story is all too common. Have you ever seen that old TV show Lost? I think these kinds of stories are the reason why pointlessly pushing the button in that show was such a popular and memorable trope. Things that people "have to do" but no one knows why, and they just keep doing it over and over...because what if? I feel your pain

Re: LogJ4 Security Inquiry – Response Required

#124
post #96
post #18

Earlier quoted context omitted.

In a Fortune 500 company, I'd imagine it could be quite difficult to definitively prove that they are not a customer of any one organization. The company I work for is not Fortune 500, but we have several Fortune 500 customers. The amount of inane bullshit we have to deal with as a result is mind-boggling.

I recall an incident of large company paying whatever bill they receive and only to find out that they never had a contract with some of the companies and never receiving any service.

If it makes you feel better, it goes both ways; I once signed up for a utility, got service, and discovered months later that they somehow completed the paperwork to give me service but not to actually bill me.

Re: LogJ4 Security Inquiry – Response Required

#125
I think daniel's reaction is appropriate and well thought. One can suppose thousands of these emails asking for free work have been sent. There is close to zero chance his demand for a support contract would get past the first filter. Whereas making a blog post about it makes for a good story and also has more chances to get the attention of the right people at this company. Even if it's slightly aggressive.

Re: LogJ4 Security Inquiry – Response Required

#126

Earlier quoted context omitted.

It's a reply to David/Daniels email to the F500 org. The dev didn't post a screenshot of their reply, but they mentioned this - "I answered the email very briefly and said I will be happy to answer with details as soon as we have a support contract signed."

There is a reply from the company at the bottom of the post.

and it's short and a bit befuddling

Re: LogJ4 Security Inquiry – Response Required

#127
post #85

Versus asking for a support contract because I don't really want to support anyone like this long term, I would have sent an invoice... If it gets paid, I answer the questions, if it doesn't everyone knows where everyone stands. I also think it's easier to get an invoice paid versus trying to negotiate a support contract.

He’s not trying to negotiate a support contract. It’s a polite “fuck off”.

Yes he is.

> In my tweet and here in my blog post I redact the name of the company. I most probably have the right to tell you who they are, but I still prefer to not. (Especially if I manage to land a profitable business contract with them.)

If he wasn't trying to land a contract, then he would have posted the company name.

Re: LogJ4 Security Inquiry – Response Required

#128

Earlier quoted context omitted.

Opensource license is a form of contract. I provide free 5 minute support to new users. And good luck suing me if I am not even US/EU based. Departments (small managers) are authorized to spend small money without approval, lets say up to 200 euro/month. If they send this type of emails, someone ass is on fire. They will DO spend it just to get legal green light. Anyway, I do not see reason to hold back, just because…

Why would you lie about a contract being expired when you could just say, "this software is provided without warranty (see license) - I offer support services starting at $X/day" and likely see the same result?

A already have enough work on $X/day. If they need to be compliant and treat me like their corporate drone, I am happy to comply. I can charge X*5 and spend one week working on my opensource project.

This is basic marketing. Airbnb, Facebook, Amazon etc are allowed to do shady stuff, but single contractor should be clean as lilium?

Post reply on HN