Live data from Hacker News

Alibaba researchers went rogue and disclosed Log4j now CCP is making Alibaba pay

twitter.com

1–10 of 15 posts

Re: Alibaba researchers went rogue and disclosed Log4j now CCP is making Alibaba pay

#4
I read recently Chinese law required them to disclose the bug to the government within two days of disclosing it to vendor and that's why Alibaba was punished.

Now I read they have to give it to the government first.

Big difference. Which is the truth and how do we know?

Re: Alibaba researchers went rogue and disclosed Log4j now CCP is making Alibaba pay

#5
post #4

I read recently Chinese law required them to disclose the bug to the government within two days of disclosing it to vendor and that's why Alibaba was punished. Now I read they have to give it to the government first. Big difference. Which is the truth and how do we know?

All of this was already discussed yesterday: https://news.ycombinator.com/item?id=29658977

Re: Alibaba researchers went rogue and disclosed Log4j now CCP is making Alibaba pay

#7
Submitted previously as https://news.ycombinator.com/item?id=29646949 but didn't get traction. Clearly it needed a punchier title.

There's no suggestion that China gets any first say on 0-days. The law in question re reporting is at http://www.gov.cn/gongbao/content/2021/content_5641351.htm and states that you must immediately notify vendors of security flaws, and then the MIIT within 2 days.

Re: Alibaba researchers went rogue and disclosed Log4j now CCP is making Alibaba pay

#8
post #5
post #4

I read recently Chinese law required them to disclose the bug to the government within two days of disclosing it to vendor and that's why Alibaba was punished. Now I read they have to give it to the government first. Big difference. Which is the truth and how do we know?

All of this was already discussed yesterday: https://news.ycombinator.com/item?id=29658977

Thanks

Re: Alibaba researchers went rogue and disclosed Log4j now CCP is making Alibaba pay

#10
post #6

A misleading and inflammatory dupe of https://news.ycombinator.com/item?id=29658342 .

> Notifying vendors first about security flaws is a cybersecurity industry norm, but a new law encourages Chinese companies to first notify the government

There is nothing misleading or inflammatory

Post reply on HN