LogJ4 Security Inquiry – Response Required
daniel.haxx.se
LogJ4 Security Inquiry – Response Required
1–10 of 128 posts
Re: LogJ4 Security Inquiry – Response Required
#2Yeah, well, I've been quite shocked how rookie some F500 devs can be and how dysfunctional large corporations can also be. Probably what happened here is someone wrote a script that compiled the dependencies of all projects they have and they sent this same email to all of them (!) regardless of any actual or potential use of log4j.
Re: LogJ4 Security Inquiry – Response Required
#3"...The level of ignorance and incompetence shown in this single email is mind-boggling...no code I’ve ever been involved with or have my copyright use log4j and any rookie or better engineer could easily verify that..." Yeah, well, I've been quite shocked how rookie some F500 devs can be and how dysfunctional large corporations can also be. Probably what happened here is someone wrote a script that compiled the depe…
Re: LogJ4 Security Inquiry – Response Required
#4Re: LogJ4 Security Inquiry – Response Required
#5Re: LogJ4 Security Inquiry – Response Required
#6"We are happy to provide you with support regarding this issue for $5000/day"
Then if they accept, proceed to do nothing for 10 days, then reply you find none of your code is impacted and they are safe then bill them $50k.
Re: LogJ4 Security Inquiry – Response Required
#7I assume some developer/supplier used curl and provided a list of third party code and licenses they use.
In the aftermath of the log4j incident, companies now target everyone about this issue partly to learn about potential exposure that they are not aware yet, eg exploited infrastructure of depending services like newsletter or analytics services.
Yes, it's annoying and pointless to spam this mails to open source projects. But at least someone is now behind auditing the supply chain.
Re: LogJ4 Security Inquiry – Response Required
#8It's actually fantastic to receive such email. You can answer: "We are happy to provide you with support regarding this issue for $5000/day" Then if they accept, proceed to do nothing for 10 days, then reply you find none of your code is impacted and they are safe then bill them $50k.
Re: LogJ4 Security Inquiry – Response Required
#9I wonder what their reply is about. They probably have no idea what/who they are really talking to, and it's probably not some kind of legal trap.