Live data from Hacker News

LogJ4 Security Inquiry – Response Required

daniel.haxx.se

1–10 of 128 posts

Re: LogJ4 Security Inquiry – Response Required

#2
"...The level of ignorance and incompetence shown in this single email is mind-boggling...no code I’ve ever been involved with or have my copyright use log4j and any rookie or better engineer could easily verify that..."

Yeah, well, I've been quite shocked how rookie some F500 devs can be and how dysfunctional large corporations can also be. Probably what happened here is someone wrote a script that compiled the dependencies of all projects they have and they sent this same email to all of them (!) regardless of any actual or potential use of log4j.

Re: LogJ4 Security Inquiry – Response Required

#3

"...The level of ignorance and incompetence shown in this single email is mind-boggling...no code I’ve ever been involved with or have my copyright use log4j and any rookie or better engineer could easily verify that..." Yeah, well, I've been quite shocked how rookie some F500 devs can be and how dysfunctional large corporations can also be. Probably what happened here is someone wrote a script that compiled the depe…

Let's hope they apply a similar amount of due diligence when the author responds with an offer to look into it for $800/hr with a 20 hour minimum.

Re: LogJ4 Security Inquiry – Response Required

#6
It's actually fantastic to receive such email. You can answer:

"We are happy to provide you with support regarding this issue for $5000/day"

Then if they accept, proceed to do nothing for 10 days, then reply you find none of your code is impacted and they are safe then bill them $50k.

Re: LogJ4 Security Inquiry – Response Required

#7
As far as I learned, a couple of big companies are sending this kind of mail to every provider, partner or copyright owner of code that they could find.

I assume some developer/supplier used curl and provided a list of third party code and licenses they use.

In the aftermath of the log4j incident, companies now target everyone about this issue partly to learn about potential exposure that they are not aware yet, eg exploited infrastructure of depending services like newsletter or analytics services.

Yes, it's annoying and pointless to spam this mails to open source projects. But at least someone is now behind auditing the supply chain.

Re: LogJ4 Security Inquiry – Response Required

#8

It's actually fantastic to receive such email. You can answer: "We are happy to provide you with support regarding this issue for $5000/day" Then if they accept, proceed to do nothing for 10 days, then reply you find none of your code is impacted and they are safe then bill them $50k.

It's fraud to bill someone T&M for time that wasn't actually spent. You're better off quoting it fixed-fee. :)

Re: LogJ4 Security Inquiry – Response Required

#9
post #5

I wonder what their reply is about. They probably have no idea what/who they are really talking to, and it's probably not some kind of legal trap.

It's a reply to David/Daniels email to the F500 org. The dev didn't post a screenshot of their reply, but they mentioned this - "I answered the email very briefly and said I will be happy to answer with details as soon as we have a support contract signed."
Post reply on HN