Live data from Hacker News

LogJ4 Security Inquiry – Response Required

daniel.haxx.se

81–90 of 128 posts

Re: LogJ4 Security Inquiry – Response Required

#81

For everyone boggling at the tone of the email, stop for a moment and have a guess at how many different sources of software they think the average large corp has on their books let alone on their infra. It can literally be hundreds or thousands of different sources. And each of those will have their own topology. This is clearly a scatter-gun survey because they're realised they really have no idea of their exposure…

[deleted]

Re: LogJ4 Security Inquiry – Response Required

#82
If you want a company to change their behavior, give them a reason to do so. Daniel has quite a platform being a well known maintainer, but instead of using that platform to shame the company in question, he politely emails back to the person sitting with an outdated excel sheet of 500 suppliers. That person didn't decide that the "email everyone on this list demanding info" strategy was a good idea.

To actually make a difference when you have a platform, use it. Tweet-shame them so that the fallout actually reaches the manager in question. This is just complaining about a behahavior while at the same time more or less doing everything possible to encourage that behavior.

Re: LogJ4 Security Inquiry – Response Required

#83
This is golden and characterises a surprising amount of my experience of communications with large corporations:

>> Thank you for your reply. Are you saying that we are not a customer of your organization?

It's just so beautifully orthogonal. Oh, and they got his name wrong in the salutation.

Re: LogJ4 Security Inquiry – Response Required

#84

I don't want to defend this company, but my company (a dev tool used by many other companies) receives a handful of these a day. It's almost the exact same email, and they're just mass-sending them. It's not personal, and it's pretty standard. The tone feels off if you assume a human wrote it. But that's only because it's a form letter their legal department wrote for them to send off. They probably collected "depend…

Better to reply "yes, we are affected. Your support contract has expired, please renew at XYZ".

Re: LogJ4 Security Inquiry – Response Required

#85

Versus asking for a support contract because I don't really want to support anyone like this long term, I would have sent an invoice... If it gets paid, I answer the questions, if it doesn't everyone knows where everyone stands. I also think it's easier to get an invoice paid versus trying to negotiate a support contract.

He’s not trying to negotiate a support contract. It’s a polite “fuck off”.

Re: LogJ4 Security Inquiry – Response Required

#86

For everyone boggling at the tone of the email, stop for a moment and have a guess at how many different sources of software they think the average large corp has on their books let alone on their infra. It can literally be hundreds or thousands of different sources. And each of those will have their own topology. This is clearly a scatter-gun survey because they're realised they really have no idea of their exposure…

Also, for any FOSS author who gets one or more of these inquiries don't laugh it off or write blog posts mocking the sender. Take it as the business opportunity it is and send a professional response indicating your willingness to help them navigate through this, at least as it relates to your bit of code, for customers with paid support plans. You want money, they have money and you can trivially provide them something at least some of them are willing to pay up for with a potential opportunity for a non-trivial longer term relationship.

This is the best kind of sales call: they are coming to you.

Re: LogJ4 Security Inquiry – Response Required

#87
post #67

The document uses a monospace font, and the redacted name can be seen to be 10 characters long. Based on the 2019 Fortune 500 list, that gives these possible candidates: Activision, Alaska Air, Albertsons, Altice USA, Amazon.com, Ameriprise, AutoNation, BB&T Corp., Bed Bath &, Blackstone, Booz Allen, BorgWarner, Burlington, CBRE Group, Chesapeake, CMS Energy, CVS Health, Dean Foods, DTE Energy, Enterprise, Eversource…

From the article: "The email comes from a fortune-500 multi-billion dollar company that apparently might be using a product that contains my code, or maybe they have customers who do. Who knows?"

The "or maybe they have customers who do" makes me think that this company must provide services to other companies, so probably not a Mcdonald's or Albertson's or something like that.

Re: LogJ4 Security Inquiry – Response Required

#89

I find it a bit sad that a tech literate group is bashing a non-literate group fo people. The entire reason your salary is much larger than many other career paths is because of your ability to deal with technology. The premise that when the less educated and informed try to question something they don't understand only to be left with pandering and jabs is disingenuous. The questions although perhaps better phrased…

> I find it a bit sad that a tech literate group is bashing a non-literate group fo people.

Creating a software bill of materials is a technical task. Managing software security risk is a technical task. These need to be performed by a technically literate person.

A Fortune-500 company has the resources to pay for such technical competence. They are not a mom-and-pop shop.

No Fortune-500 CEO would get their teeth done by a fly-by-night "dentist", nor would they hire "builders" who can't nail two planks together. They would pay for the expertise. If they don't know how to find the expert they would pay for the expertise of finding the expert first and then they would pay for the expertise.

But this is not what they did. They found someone who is both lacking the necessary technical common sense and is terribly arrogant. That is worthy of ridicule. And I'm not ridiculing the individual employee but the whole company.

> The premise that when the less educated and informed try to question something they don't understand only to be left with pandering and jabs is disingenuous.

That idea flies when a student is lost in the woods. When an economic juggernaut combines technical illiteracy with a lack of tack they can get the sharp ends of our tongues.

> The entire reason your salary is much larger than many other career paths is because of your ability to deal with technology.

Won't be for long if we silently support huge companies to employ muppets. Which is why asking for a support contract is the right answer here.

Re: LogJ4 Security Inquiry – Response Required

#90

I don't want to defend this company, but my company (a dev tool used by many other companies) receives a handful of these a day. It's almost the exact same email, and they're just mass-sending them. It's not personal, and it's pretty standard. The tone feels off if you assume a human wrote it. But that's only because it's a form letter their legal department wrote for them to send off. They probably collected "depend…

Better to reply "yes, we are affected. Your support contract has expired, please renew at XYZ".

So... lie to someone who is making an effort to protect customer data in order to steal money?
Post reply on HN