Live data from Hacker News

LogJ4 Security Inquiry – Response Required

daniel.haxx.se

71–80 of 128 posts

Re: LogJ4 Security Inquiry – Response Required

#71

Many organizations document their 3rd party vendors and libraries and it doesn't surprise me that an automated email reached Daniel. Most likely someone mis-documented using one of Daniel's projects in a spreadsheet. I am personally a bit surprised about the responses here. It is completely reasonable for this email to reach Daniel and is most likely an artifact of bad documentation by engineers in the company. At th…

> At the scale this company is running the person/team sending out these emails do not have time to dig in and understand each dependency they are sending emails on. That alone is extremely disrespectful, it means they couldn't care less about the time of open source software maintainers. To say nothing of their "request" for review.

It's not about open source maintainers. This isn't an "open source" problem further than the fact that Daniel's software is used in a product they are using. Daniel could take a couple of seconds to ignore this email and there was very little time wasted.

The real "disrespect" should be whatever engineer put Daniel's name into the spreadsheet that blasted out these emails. Someone didn't do their job and is checking a box. How is the (possibly non-technical) person that is required for managing 100s of vendors and thousands of open source libraries supposed to verify all of that information?

I'm personally happy to hear that this company is trying to do SOMETHING to make sure that Log4j is patched even if it's a bit incompetent in it's implementation. There is not malice here.

Re: LogJ4 Security Inquiry – Response Required

#72

Earlier quoted context omitted.

Let's hope they apply a similar amount of due diligence when the author responds with an offer to look into it for $800/hr with a 20 hour minimum.

You're thinking small potatoes https://www.ign.com/articles/2019/03/26/man-steals-122-milli...

I'm not even mad.

Re: LogJ4 Security Inquiry – Response Required

#73

I find it a bit sad that a tech literate group is bashing a non-literate group fo people. The entire reason your salary is much larger than many other career paths is because of your ability to deal with technology. The premise that when the less educated and informed try to question something they don't understand only to be left with pandering and jabs is disingenuous. The questions although perhaps better phrased…

I find it sad that the security department of a Fortune 500 company is sending out emails demanding OSS maintainers respond within 24 hours or else.

You can feel sorry for the poor sap that was forced to embarrass himself, but it doesn't change the fact that everyone here feels like that company can get bent.

Re: LogJ4 Security Inquiry – Response Required

#74
post #67

The document uses a monospace font, and the redacted name can be seen to be 10 characters long. Based on the 2019 Fortune 500 list, that gives these possible candidates: Activision, Alaska Air, Albertsons, Altice USA, Amazon.com, Ameriprise, AutoNation, BB&T Corp., Bed Bath &, Blackstone, Booz Allen, BorgWarner, Burlington, CBRE Group, Chesapeake, CMS Energy, CVS Health, Dean Foods, DTE Energy, Enterprise, Eversource…

[deleted]

Re: LogJ4 Security Inquiry – Response Required

#75
I don't want to defend this company, but my company (a dev tool used by many other companies) receives a handful of these a day. It's almost the exact same email, and they're just mass-sending them. It's not personal, and it's pretty standard.

The tone feels off if you assume a human wrote it. But that's only because it's a form letter their legal department wrote for them to send off. They probably collected "dependencies" from the entire company (and someone wrote "curl"), and sent a mass email.

If you just reply with a simple "We're unaffected!" (or ignore them), you'll never hear from them again.

Re: LogJ4 Security Inquiry – Response Required

#76
Versus asking for a support contract because I don't really want to support anyone like this long term, I would have sent an invoice... If it gets paid, I answer the questions, if it doesn't everyone knows where everyone stands. I also think it's easier to get an invoice paid versus trying to negotiate a support contract.

Re: LogJ4 Security Inquiry – Response Required

#77

Earlier quoted context omitted.

Let's hope they apply a similar amount of due diligence when the author responds with an offer to look into it for $800/hr with a 20 hour minimum.

You're thinking small potatoes https://www.ign.com/articles/2019/03/26/man-steals-122-milli...

We used to joke about doing this at my last company. We knew for a fact that our accounts payable folks frequently paid invoices without doing any verification that they were valid.

I'm willing to guess this happens a lot more than people realize. I doubt we were the only people joking about it. People joke, other people hear, some of those follow up with action. The smart ones keep quiet and stop well before getting to $122M.

Re: LogJ4 Security Inquiry – Response Required

#78
post #40

Earlier quoted context omitted.

> Then if they accept, proceed to do nothing for 10 days, then reply you find none of your code is impacted and they are safe then bill them $50k. Hopefully you don't do that or encourage others to. Just because F500 companies are big, stupid, slow and greedy, doesn't exactly make stealing right.

>Just because F500 companies are big, stupid, slow and greedy, doesn't exactly make stealing right. That is precisely why it's right. These capitalists have stolen our labour, and corrupted our politics for centuries. `Stealing` it BACK is the ONLY way history has shown us works.

So this contract is the starting point for the next great Marxist revolution ?

Re: LogJ4 Security Inquiry – Response Required

#80

Earlier quoted context omitted.

> At the scale this company is running the person/team sending out these emails do not have time to dig in and understand each dependency they are sending emails on. That alone is extremely disrespectful, it means they couldn't care less about the time of open source software maintainers. To say nothing of their "request" for review.

It's not about open source maintainers. This isn't an "open source" problem further than the fact that Daniel's software is used in a product they are using. Daniel could take a couple of seconds to ignore this email and there was very little time wasted. The real "disrespect" should be whatever engineer put Daniel's name into the spreadsheet that blasted out these emails. Someone didn't do their job and is checking…

If they were accidentally infringing licenses, this scattershot approach may result in snitching on their own company.

That's how a log4j security audit becomes an Oracle licensing debacle.

Post reply on HN