5 ms·
What's the intention behind this repo? Seems to me the effort could have been better redirected towards fixing the insecure library instead. I'm not familiar wi
by lovelearning 5y ago
What's the intention behind this repo? Seems to me the effort could have been better redirected towards fixing the insecure library instead. I'm not familiar with the Go ecosystem - is there some "Go more secure than Java" culture of mocking there?
- Ygg2 5y agoNo. This is just mocking. I'm sure no library in <Insert language here> had scope creep that led to vulnerability.
- bradfitz 5y agoI'm the author of the "mocking". I prefer to call it coping. :) I had a CVE against my own code just yesterday. It happens. I made fun of myself too: https://twitter.com/bradfitz/status/1469015417679081472 https://twitter.com/bradfitz/status/1469015417679081472
- eecc 5y agoHeh, go errori checking FTW! Well you did choose your poison… ;)
- CuriousCosmic 5y agoIt's just a joke and taking the piss out of the whole ordeal more than anything else.
- tehlike 5y agoBradfitz is a pretty solid eng, and clearly doing this for fun.
- cmeacham98 5y ago> Seems to me the effort could have been better redirected towards fixing the insecure library instead. It's already fixed and released with the fix. I also like to steer away from this type of reasoning, because it's applicable to almost anything: why are you here commenting on HN when you could be helping with the fix or doing charity work?
- pkulak 5y agoTrust me, what I'm doing right now isn't productive either.
- pm90 5y agoIt’s a demonstration in golang of what the vuln is. The assumption (not a bad one) is that golang devs may not be familiar with Java things and happenings. I can actually use it and simulate what an attacker could do. So it lets golang devs play with the problem. The problem with this vuln is that since this library is a Java library that’s used everywhere, remediation is going to have a really long tail. There are a fuckton of apps that use this logger and it’s owners are not aware of it. Or it’s used in a part of a stack that’s not tracked yet… nobody can really tell.
- bradfitz 5y agoI wrote the repo. I preemptively apologized for the bad joke: https://twitter.com/bradfitz/status/1469523009484431363 https://twitter.com/bradfitz/status/1469523009484431363 https://twitter.com/bradfitz/status/1469523985998118925 https://twitter.com/bradfitz/status/1469523985998118925 It started with me reading seeing this tweet: https://twitter.com/_StaticFlow_/status/1469358229767475205 https://twitter.com/_StaticFlow_/status/1469358229767475205 And I was just thinking it'd be fun to implement an expander for those. (https://twitter.com/bradfitz/status/1469526259335974912 https://twitter.com/bradfitz/status/1469526259335974912)
- deleted 5y ago[deleted]
- xvector 5y agoIt's a good joke
- geodel 5y agoSeems you are not familiar with Java either as the insecure log4j2 library is already fixed by volunteers.
- eyelidlessness 5y agoI can only speak for me, but isolated demonstrations of security vulnerabilities have definitely helped me learn both how to anticipate and identify issues in real work. Jokes still work well for that purpose. Sure, it wasn’t a direct contribution to log4j but maybe it provides some reference material to someone building another library which could benefit from knowing the possible exploit.
- kyruzic 5y agoIts a joke. Its 100 lines total. Probably took an hour. Why didn't you fix a bug with an open source library instead of writing this comment?