Live data from Hacker News

LogJ4 Security Inquiry – Response Required

daniel.haxx.se

91–100 of 128 posts

Re: LogJ4 Security Inquiry – Response Required

#91
post #80

Earlier quoted context omitted.

It's not about open source maintainers. This isn't an "open source" problem further than the fact that Daniel's software is used in a product they are using. Daniel could take a couple of seconds to ignore this email and there was very little time wasted. The real "disrespect" should be whatever engineer put Daniel's name into the spreadsheet that blasted out these emails. Someone didn't do their job and is checking…

If they were accidentally infringing licenses, this scattershot approach may result in snitching on their own company. That's how a log4j security audit becomes an Oracle licensing debacle.

Yep, it can/will happen. My assumption is that this is related to Curl, which has a pretty well documented license. Responding to emails like this with an automated email pointing to the license at https://github.com/curl/curl/blob/master/COPYING seems like an obvious thing to have setup.

Namely: THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OF THIRD PARTY RIGHTS. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Re: LogJ4 Security Inquiry – Response Required

#92
post #13

Earlier quoted context omitted.

> proceed to do nothing for 10 days That would be fraud. No, start grep on the source code and a few things like that, then provide the results: "a detailed audit found no reference to log4js, so another audit was started which found no reference to any java code in the C source; it was repeated 5 times to confirm these promising results. Another audit followed the Boltzman brain hypothesis to check if the affected l…

> "No, start grep on the source code" Or print it out on hard copy, make interns read it line by line, then charge 400% of their labor as your management fee. What's the purpose of using regexps here? You're optimizing away your own revenue!

Also charge $1/page for the printing. Then ship it to them, in triplicate, and charge for the overnight shipping (it's an urgent bug after all).

Re: LogJ4 Security Inquiry – Response Required

#93

I don't want to defend this company, but my company (a dev tool used by many other companies) receives a handful of these a day. It's almost the exact same email, and they're just mass-sending them. It's not personal, and it's pretty standard. The tone feels off if you assume a human wrote it. But that's only because it's a form letter their legal department wrote for them to send off. They probably collected "depend…

Better to reply "yes, we are affected. Your support contract has expired, please renew at XYZ".

If there's no expired support contract, that would be making a false statement of fact in order to get someone to sign a contract and pay me money. It's plausible that that would be fraud.

Of course it's also plausible that that's not fraud at all. But I have no way to know for sure unless I ask a lawyer, which needless to say I wouldn't do. And if it turns out that it is fraud, well, the legal department of Fortune 500 companies tends to be pretty humorless.

Re: LogJ4 Security Inquiry – Response Required

#94

OK, a large corporation legal team doesn't understand the nuance of ownership of open-source software. Do we mock every single open source guy who displays the same amount of cluelessness about the inner workings of a business because I see plenty of that displayed here and everywhere else.

Understanding the nuances of ownership and who is responsible for what is quite an important skill for corporate lawyers.

If you are dealing with 1000s of cases, you can't apply nuances to every single of them.

You are all are supposed to be smart software engineers. Probably know about pre-mature optimization and efficient path.

Here's a secret about communications -- Mass emailing works and is very efficient.

I'm sure you are the same person who rants about a recruiter reaching out to you even though you are the creator of Python.

Reading through everyone's resume and tailoring a message is a waste of time and has the worst ROI for any salesperson.

"But Ha Ha Ha, you guys are clueless about not knowing operational efficiency of an mass communications. Ha Ha Ha"

Yeah, that's exactly how this sounds if the other side mocks HN/Engineers the same way you mock Sales and other "mass-outreach programs"

Re: LogJ4 Security Inquiry – Response Required

#95

OK, a large corporation legal team doesn't understand the nuance of ownership of open-source software. Do we mock every single open source guy who displays the same amount of cluelessness about the inner workings of a business because I see plenty of that displayed here and everywhere else.

Ummm... I think the curl license is displayed pretty publicly. So, yes - this email deserves to be mocked roundly.

and I mock you for being clueless about how mass outreach communications work

Re: LogJ4 Security Inquiry – Response Required

#96
post #18

> "Thank you for your reply. Are you saying that we are not a customer of your organization?" Isn't this the sort of question you'd ask your own side, first?

In a Fortune 500 company, I'd imagine it could be quite difficult to definitively prove that they are not a customer of any one organization. The company I work for is not Fortune 500, but we have several Fortune 500 customers. The amount of inane bullshit we have to deal with as a result is mind-boggling.

I recall an incident of large company paying whatever bill they receive and only to find out that they never had a contract with some of the companies and never receiving any service.

Re: LogJ4 Security Inquiry – Response Required

#97

OK, a large corporation legal team doesn't understand the nuance of ownership of open-source software. Do we mock every single open source guy who displays the same amount of cluelessness about the inner workings of a business because I see plenty of that displayed here and everywhere else.

Yeah, they get their pay check to understand the nuances :)

No, they get the paycheck to be effective in their process.

And "Ha Ha Ha You, for not knowing that"

Re: LogJ4 Security Inquiry – Response Required

#98

OK, a large corporation legal team doesn't understand the nuance of ownership of open-source software. Do we mock every single open source guy who displays the same amount of cluelessness about the inner workings of a business because I see plenty of that displayed here and everywhere else.

I am sure their lawyers know exactly how software licenses work. I also bet that the list of dependencies they used for this mass email was probably not generated by a lawyer.

Exactly, everything is a Search problem. Most organizations (recruiters, sales) have their own efficient Search algorithms. Unless you know the intricacies of that, you deserve to be mocked for displaying ignorance.

It's as dumb as mocking scammers for their methods. They are effective in their own way. Just because it didn't apply for you, doesn't mean they aren't making money out of this -- which is their ultimate goal. Their goal is not to satisfy your ego and custom tailor a message to you

Re: LogJ4 Security Inquiry – Response Required

#99
post #93

Earlier quoted context omitted.

Better to reply "yes, we are affected. Your support contract has expired, please renew at XYZ".

If there's no expired support contract, that would be making a false statement of fact in order to get someone to sign a contract and pay me money. It's plausible that that would be fraud. Of course it's also plausible that that's not fraud at all. But I have no way to know for sure unless I ask a lawyer, which needless to say I wouldn't do. And if it turns out that it is fraud, well, the legal department of Fortune…

Opensource license is a form of contract. I provide free 5 minute support to new users. And good luck suing me if I am not even US/EU based.

Departments (small managers) are authorized to spend small money without approval, lets say up to 200 euro/month. If they send this type of emails, someone ass is on fire. They will DO spend it just to get legal green light.

Anyway, I do not see reason to hold back, just because I am open source developer.

Re: LogJ4 Security Inquiry – Response Required

#100
post #93

Earlier quoted context omitted.

Better to reply "yes, we are affected. Your support contract has expired, please renew at XYZ".

If there's no expired support contract, that would be making a false statement of fact in order to get someone to sign a contract and pay me money. It's plausible that that would be fraud. Of course it's also plausible that that's not fraud at all. But I have no way to know for sure unless I ask a lawyer, which needless to say I wouldn't do. And if it turns out that it is fraud, well, the legal department of Fortune…

Just say that "there is no active support contract for your company at this time."
Post reply on HN