Settings

Theme

Alibaba researchers went rogue and disclosed Log4j now CCP is making Alibaba pay

twitter.com

132 points by gcmac 4 years ago · 14 comments

Reader

ranguna 4 years ago

To save you a click: https://www.scmp.com/tech/big-tech/article/3160670/apache-lo...

The HN link links to a twitter post that links to the above link.

oefrha 4 years ago

A misleading and inflammatory dupe of https://news.ycombinator.com/item?id=29658342.

  • hankchinaski 4 years ago

    > Notifying vendors first about security flaws is a cybersecurity industry norm, but a new law encourages Chinese companies to first notify the government

    There is nothing misleading or inflammatory

kevcampb 4 years ago

Submitted previously as https://news.ycombinator.com/item?id=29646949 but didn't get traction. Clearly it needed a punchier title.

There's no suggestion that China gets any first say on 0-days. The law in question re reporting is at http://www.gov.cn/gongbao/content/2021/content_5641351.htm and states that you must immediately notify vendors of security flaws, and then the MIIT within 2 days.

  • DyslexicAtheist 4 years ago

    > Clearly it needed a punchier title.

    and it's fitting that Mdm. Perlroth is the one to provide that "punchier title".

    She's _the_ definition of an unhinged talking head of infosec. Her book on 0days ("this is how they tell me the world ends") is full of logical fallacies, jumping to conclusions, lacks technical understanding, etc., yet somehow she manages to now speak about cyber on behalf of all of us and everyone is applauding her shit takes whenever some news drop. There are plenty of capable women in cyber who we could amplify. But no! We have to give a podium to this carrion.

gregw2 4 years ago

I read recently Chinese law required them to disclose the bug to the government within two days of disclosing it to vendor and that's why Alibaba was punished.

Now I read they have to give it to the government first.

Big difference. Which is the truth and how do we know?

thecleaner 4 years ago

This raises my trust in Chinese security researchers. Log4j bug is one of the biggest security loopholes ever and these researchers knew exactly what they were doing when they made the announcement - avoiding a potential catastrophic comprise via Chinese state hackers. I totally admire the guts of these people.

SOMA_BOFH 4 years ago

I wonder if this was due to engineers releasing it on their own or if management had their back.

thanatos519 4 years ago

Hey, at least they didn't hurt the feelings of the Chinese people!

Putting Alibaba in the corner for 6 months is an incredibly petty response, but no surprise at all.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection