Anyone leading a shareholder action would love to see these emails. They are basic admissions that the company doesn't know how or from where it gets essential software.
LogJ4 Security Inquiry – Response Required
31–40 of 128 posts
Re: LogJ4 Security Inquiry – Response Required
#32As far as I learned, a couple of big companies are sending this kind of mail to every provider, partner or copyright owner of code that they could find. I assume some developer/supplier used curl and provided a list of third party code and licenses they use. In the aftermath of the log4j incident, companies now target everyone about this issue partly to learn about potential exposure that they are not aware yet, eg e…
Re: LogJ4 Security Inquiry – Response Required
#33OK, a large corporation legal team doesn't understand the nuance of ownership of open-source software. Do we mock every single open source guy who displays the same amount of cluelessness about the inner workings of a business because I see plenty of that displayed here and everywhere else.
Re: LogJ4 Security Inquiry – Response Required
#34I am personally a bit surprised about the responses here. It is completely reasonable for this email to reach Daniel and is most likely an artifact of bad documentation by engineers in the company. At the scale this company is running the person/team sending out these emails do not have time to dig in and understand each dependency they are sending emails on.
The response is as simple as "What library/product does this email pertain to?", "Please see the licenses for the libraries or products in question.", and what Daniel responded with as well: "I would be willing the dig in further for specific questions with a support contract.".
Re: LogJ4 Security Inquiry – Response Required
#35Re: LogJ4 Security Inquiry – Response Required
#36It's actually fantastic to receive such email. You can answer: "We are happy to provide you with support regarding this issue for $5000/day" Then if they accept, proceed to do nothing for 10 days, then reply you find none of your code is impacted and they are safe then bill them $50k.
> proceed to do nothing for 10 days That would be fraud. No, start grep on the source code and a few things like that, then provide the results: "a detailed audit found no reference to log4js, so another audit was started which found no reference to any java code in the C source; it was repeated 5 times to confirm these promising results. Another audit followed the Boltzman brain hypothesis to check if the affected l…
Or print it out on hard copy, make interns read it line by line, then charge 400% of their labor as your management fee.
What's the purpose of using regexps here? You're optimizing away your own revenue!
Re: LogJ4 Security Inquiry – Response Required
#37> Are you saying that we are not a customer of your organization? LOL.
Re: LogJ4 Security Inquiry – Response Required
#38It's actually fantastic to receive such email. You can answer: "We are happy to provide you with support regarding this issue for $5000/day" Then if they accept, proceed to do nothing for 10 days, then reply you find none of your code is impacted and they are safe then bill them $50k.
Re: LogJ4 Security Inquiry – Response Required
#39Re: LogJ4 Security Inquiry – Response Required
#40It's actually fantastic to receive such email. You can answer: "We are happy to provide you with support regarding this issue for $5000/day" Then if they accept, proceed to do nothing for 10 days, then reply you find none of your code is impacted and they are safe then bill them $50k.
Hopefully you don't do that or encourage others to. Just because F500 companies are big, stupid, slow and greedy, doesn't exactly make stealing right.