10 ms·
GitHub taking down tools allowing defenders to reproduce the Log4j vulnerability
- schleck8 5y agoSo what? There is plenty of ressources on how to fix the vulnerability. Those who really want to see the code will find it anyways, both maliscious actors and admins. This mostly prevents skids from getting hold of it and using it against their school etc
- jimmyvalmer 5y agoGithub taking down whitehat tool for reproducing vulnerability. The title as it stands begs the question: Who is "allowing defenders", Github or the tools? Also "defenders" is a weird word to use here.
- hvgk 5y agoRemember GitHub is not Git. Needs to be pushed elsewhere. Everywhere.
- overflyer 5y agoBut there's not only Github. They can just use Gitlab or if that does not work Codeberg. Somehow the whole industry really seems to be content with bootlicking any of the Big Five.
- _fizz_buzz_ 5y agoGithub is owned by Microsoft. Github IS the big five.
- 0xdeadb00f 5y agoThat's OPs point though.
- _fizz_buzz_ 5y agoIs it? So Github is bootlicking itself?
- jackothy 5y agoDevelopers are bootlicking Github when they keep deciding to host stuff there.
- Y_Y 5y agoGitHub is running on momentum at this point. I only use it for cloning nowadays. They've even made that a hassle, I'd like to use SSH for all my connections, but it seems like they'd prefer I got their shitty custom tool, or used https and typed a lot of passwords. These days for preference I'll use shart (sr.ht) or, even better, the project's own git server.
- weikju 5y agossh works fine for me.. what issue are you having?
- ascar 5y agoI think it defaults to showing the https cloning link when you're not logged in (and possibly don't have your public key added to your github account). While logged in it also defaults to ssh for me and works just fine.
- nyuszika7h 5y agoYou can easily work around that by putting this in your .gitconfig: [url "git@github.com:"] insteadOf = git://github.com/ insteadOf = http://github.com/ insteadOf = https://github.com/
- DiabloD3 5y agoThis is literally magic and has been yoinked into my dotfiles.
- loxias 5y agoOr just, ya know, a $5 linode holds my git repos just fine. :) The problem is the centralization/SPOF itself, not whatever platform or SPOF used.
- jchw 5y agoThe problem with betting on the underdog is that the internet is still young. GitHub has momentum; it may not have a guaranteed long-term future, but as of now it is the open source project forge with the best long-term outlook. If you had bet on Google Code, your project is at least still accessible today. If you bet on Sourceforge, the same is true, although for a period of time you could’ve had your own project page distributing malware. (I am aware that it has changed hands since these incidents, but this still happened nonetheless.) GitLab also seems like an OK bet… but from there on out, it feels like you have to be careful. A random Gitea instance is never a safe bet. Even if you run it on your own, you don’t know how long you’ll be around to keep the lights on; life is fragile. I still find Golang’s module cache mechanism to be bothersome in some regards, but I think they were on the money with their concerns. It’s probably the only way modules can stay “decentralized” with confidence. But, that solution requires at least one central entity that is trusted and can shoulder the costs of such a service; and it only solves a narrow portion of the problem, relevant to the module system of a single programming language. There’s no easy way out; nothing is truly autonomous. Explicitly organized groups of people running a legitimate business probably have a better long-term outlook than a band of cypherpunks running P2P services, or what have you. (Believe me, it pains me to say it, because I sure wish it wasn’t so.) In this way, I think it’s obvious why people pick GitHub. It’s because it’s in the best position of the best segment for code hosting. It’s backed by a billion dollar multinational corporation. It’s been around the block a few times and is a robust business of its own. Even if your concern isn’t longevity, GH is still giving you the best standing as far as network effects go. It’s just hard to blame anyone.
- faeyanpiraat 5y agoBlockchain to the rescue! /s
- arkadiyt 5y agoThere's a mirror here: https://codechina.csdn.net/mirrors/feihong-cs/JNDIExploit https://codechina.csdn.net/mirrors/feihong-cs/JNDIExploit
- loxias 5y agoFinding information that is "censored" or restricted by going to a Chinese source ... gobsmacking levels of irony. :D
- canadatom 5y agomost the large enterprise has a direct connection to THE internet
- mgbmtl 5y agoI get what you mean, but also worth noting that the vulnerability was discovered by Chen Zhaojun of Alibaba Cloud Security Team.
- Tabular-Iceberg 5y agoI guess it’s safe to assume that the actual discovery happened a long time ago and the CCP has already pwned everyone they wanted to using the vulnerability already. Responsible disclosure with Chinese characteristics.
- adrianN 5y agoLiterally every country in the world hoards every zero day they can get their hand on.
- Tabular-Iceberg 5y agoYes, I expect the NSA to get first dibs on using anything Amazon discovers too. Two wrongs do not make a right. And I’m not sure how good of a strategy it really is, at least not for the west. The value in using zero days for attacking enemies is highly speculative and not subject to public scrutiny, but the value in rolling out fixes as soon as possible to protect against anyone else is easily felt by everyone. I believe independent security researchers still exist, and they are worth fighting for.
- erk__ 5y agoIs there any indications that it was taken down by GitHub and not by the owner themself?
- christophetd 5y agoIt's a good point. I added a disclaimer to the tweet while confirming this, but I'm confident it's a GitHub takedown following their new policy: https://github.blog/2021-04-29-call-for-feedback-policies-exploits-malware/ https://github.blog/2021-04-29-call-for-feedback-policies-ex...
- christophetd 5y agoIf anyone working at GitHub reads this, I opened support ticket #1425405 to request a confirmation.
- testplzignore 5y agoUpdate to that post: https://github.blog/2021-06-04-updates-to-our-policies-regarding-exploits-malware-and-vulnerability-research/ https://github.blog/2021-06-04-updates-to-our-policies-regar...
- runeks 5y agoIs there any indication that the owner took it down himself while claiming GitHub did it?
- floatingatoll 5y agoThey do this every time, and have a previously stated spproach of blocking zero day attack scripts for the first X days of a zero day, when they deem it sufficiently dangerous to the Internet. So, yes, yet again, they’re doing this, just as they always do. Is there something new this time that makes this newsworthy?
- naikrovek 5y agoI'm much more worried about everyone on this site just believing everything they read, then instantly getting mad instead of doing a simple "is this really true" search or even gaining a single data point of their own. this whole culture is just freaking ripe for manipulation. it's so easy.
- turminal 5y agoEvery time this happens we should think about how powerful github has become and why are we collectively allowing this.
- floatingatoll 5y agoI’d love to read a longform blog post about that. Anything that fits into a tweet has already been said a bunch of times already, and hasn’t made a compelling case that there’s a problem here. I’m pretty sure they only takedown exploit code, not scanner code, but people often choose not to distinguish those conceptually, which makes it quite difficult to have a discussion about it. Also, see top reply on this post, which references a dual-use policy: https://twitter.com/_mph4/status/1470343429599211528 https://twitter.com/_mph4/status/1470343429599211528
- jokowueu 5y agogithub isnt powerful
- mdp2021 5y agoI think it meant "powerful" in terms of reliance. When the storage has the items, good, when it locks you out, you are left itemless. (A limited redundancy warning, along the lines of having mirrors, archives, distributed information etc.)
- yellow_lead 5y agoThe author of this tweet asks for upvotes on Twitter[1]. isn't that against rules? [1] https://twitter.com/christophetd/status/1470293533416427524?s=20 https://twitter.com/christophetd/status/1470293533416427524?...
- aspenmayer 5y agoPretty sure upvoting for agreement is okay? Also, policing what people say outside HN doesn’t seem productive or supported by the rules.
- xenocratus 5y ago> Don't solicit upvotes, comments, or submissions. Users should vote and comment when they run across something they personally find interesting—not for promotion. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html (just quoting what seems relevant, don't know if this actually falls under that item in the guidelines)
- christophetd 5y agoThanks for pointing this out. To make sure I respect the rules, I removed my tweet linking to the HN thread suggesting people to upvote it for the matter to have more visibility.
- christophetd 5y agoIf that's against the rules, let me know and I will remove the post. It was never my intention to go against HN rules. (I suggested that people upvote the thread for visibility in the community and to start the discussion. When something reaches HN frontpage, I believe it's the voice of the community, not mine anymore)
- christophetd 5y agoI have now removed the tweet linking to this HN thread to ensure I am abiding by HN rules.
- yessirwhatever 5y agoDon't upload it to fucking Github. And fuck github.
- numlock86 5y agoThanks for these elaborate arguments against GitHub. This really gave me some insights and ideas I didn't have previous reading your reasoning. I'll consider using an alternative now. Thanks again for your effort. /s
- yessirwhatever 5y agoYou're welcome. /s
- pbhjpbhj 5y agoSorry to be un-HN-like, but thanks for the laugh :D
- loxias 5y agoI'm honestly kinda surprised. The policy seems willfully ignorant of the Streisand effect. I get the reasons behind it, I'm just surprised it wasn't laughed down at some internal Github planning meeting. "No, that'll never work Dave! 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0, remember?"
- ascar 5y agoFor anyone else who is wondering what's up with that hex string: AACS encryption key controversy https://en.m.wikipedia.org/wiki/AACS_encryption_key_controversy https://en.m.wikipedia.org/wiki/AACS_encryption_key_controve...
- yrro 5y agoDoes the key still work?
- loxias 5y agoInteresting question. I have no idea if it's still relevant, though I imagine it is, and with the magical bytes being siloed in some file far, far away from VLC and libaacs. It always strikes me as amusing that here we are, in the 21st century, and people are still trying to use shibboleths as a reasonable and scalable means of security. At least "ourhardworkbythesewordsguardedpleasedontsteal(c)AppleComputerInc" has some internal humor to appreciate. Tangentially, FCKGW-... ;)
- btbuilder 5y agoThis is disappointing. I used this tool to understand the vulnerability within the first few hours of response. It allowed me to prove mitigations worked, and therefore gave certainty.
- exikyut 5y agoWhoever wants this gone is actively scrubbing it from GitHub (ie, it seems to be GitHub doing this). A few moments ago I found https://github.com/0x727/JNDIExploit https://github.com/0x727/JNDIExploit, but while browsing around the repo suddenly went 404. Wow. However, it seems that the way GitHub handles forks vs user deletions is that when a user deletes a fork (or it's Done For Them™), it seems that the fork "root owner" is transferred within the chain to someone else. I don't quite get it. Or maybe something else is going on. In any case, a few minutes ago https://github.com/search?l=&q=filename%3AJNDIExploit.iml&type=code https://github.com/search?l=&q=filename%3AJNDIExploit.iml&ty... was showing JNDIExploit under "0x727", but now the page is showing the repo "owned" by a different user (with the network graph on the repo page showing everyone else as forking the repo from that new user). So the above search link is your best bet to finding the repo. It's currently listed as owned by "zzwlpx", but you'll probably see a different user (especially if https://github.com/zzwlpx/JNDIExploit https://github.com/zzwlpx/JNDIExploit no longer works). It currently has 245 forks, so good luck, GitHub, keeping this squashed. [Edit: I now see a comment mentioning that GitHub has a policy of trying to squash 0days for the first X days, which is a very understandable reaction given that it's where everyone goes, from the skiddies who just like seeing things burn (and prevent everyone from having nice things, to the researchers trying to respectfully evaluate damage. Sigh.] --- Some other things I found while playing with GitHub search: https://github.com/zhuowei/GhidraLog4Shell https://github.com/zhuowei/GhidraLog4Shell https://github.com/samjcs/log4shell-possible-malware https://github.com/samjcs/log4shell-possible-malware https://github.com/mbechler/marshalsec/ https://github.com/mbechler/marshalsec/
- christophetd 5y agoThat's useful, thanks for sharing! Based on this, it seems extremely likely that GitHub has taken down JNDIExploit, as opposed to its owner removing it themselves. (See the question raised in https://news.ycombinator.com/item?id=29537822 https://news.ycombinator.com/item?id=29537822)
- ozim 5y agoYou all know that in Germany for example it is strictly forbidden to publish/code such tools. From what I know there are also other countries that do the same. So now GitHub would have to implement region availability not to get into trouble with German law. Let alone this is so fresh that preventing script kiddies from downloading a tool is perfectly valid move.
- tastroder 5y agoYeah nah. While the particular law is incredibly vague nonsense, if the purpose of the tool is security research or to harden your infrastructure against the impact of the vulnerability (as opposed to preparation of an actual crime) it would not be illegal to publish this in Germany.
- pbhjpbhj 5y agoCould you go into this a bit, is there caselaw you're relying on? AIUI (and I've not being following closely) Germany's equivalent to CFAA (in USA, or CMA in UK) makes the provision of 'hacker' tools capable of being used for intrusion to be a crime. Honestly, I thought it was an absolute liability law (that you can't work around by proving you had no ill intent)?
- tastroder 5y agoIANAL but the few cases I'm aware off have all been thrown out. The hacker tool provision in question starts out from a position of intent [0] (which was part of why a high profile case where a journalist sued themselves was thrown out). I'm honestly not aware of a case where this was successfully applied in court since it's inception in 2007. I might have missed some smaller stuff over the years but as long as you're not actively advertising your make-pretend "dual use" malware exclusively on the dark net you'd likely be fine. Germany's supreme court has relatively early on argued on a pretty strict interpretation of the paragraph (according to various publications related to [1] back around 2010). There have apparently been a few search warrants that referenced it but otherwise it's pretty much the toothless tiger you'd expect from a country that relies on potentially "dual use" software the paragraph would likely apply to in wider interpretations (or at least seems to be in constant talks with spyware manufacturers for their own executive branches). [0] https://dejure.org/gesetze/StGB/202c.htm https://dejure.org/gesetze/StGB/202c.htm [1] https://dejure.org/dienste/vernetzung/rechtsprechung?Text=2%20BvR%202233/07 https://dejure.org/dienste/vernetzung/rechtsprechung?Text=2%... edit: Okay, apparently I've missed a few [3] where it was actually applied. Maybe don't spy on people using keyloggers, but I'm sure other laws cover that part as well. [3] https://dejure.org/dienste/lex/StGB/202c/1.html https://dejure.org/dienste/lex/StGB/202c/1.html
- e12e 5y agoLooks like original is up? Or is it a re-upload? https://github.com/Jeromeyoung/JNDIExploit-1 https://github.com/Jeromeyoung/JNDIExploit-1
- artdigital 5y agoA GitHub employee replied on Twitter: https://twitter.com/_mph4/status/1470343429599211528 https://twitter.com/_mph4/status/1470343429599211528 > I just personally looked into this and can confirm we did not take down this repo nor are we actively removing Log4j related content from @github , consistent with our policies re: dual-use Maybe too early to grab pitchforks?
- christophetd 5y agoI made wrong assumptions when writing this tweet. I clarified this on Twitter. Apologies for the confusion. Not sure if it makes sense to delete the tweet / thread.
- christophetd 5y agoThe tweet has been removed. Now that this has been clarified, I don't want to be a vector for spreading inaccurate information.
- spixy 5y agogood, but too late, damage for the company was already done
- zx14 5y agoThanks for the fake news.
- bla3 5y agoIf a tweet is wrong and you're not out to spread FUD, you delete the tweet. That's standard procedure.
- throwoutway 5y agoIs it? Usually I see people post replies apologizing and including the truth
- ithinkso 5y ago
- christophetd 5y agoUPDATE: GitHub CISO pointed out that GitHub did NOT take down the JNDI Exploit repository. https://twitter.com/_mph4/status/1470343429599211528 https://twitter.com/_mph4/status/1470343429599211528 https://twitter.com/christophetd/status/1470346676053422081 https://twitter.com/christophetd/status/1470346676053422081 This is surprising, considering what is outlined in a previous comment[1]. I hope GitHub provides more transparency on the takedown actions for "malicious content / exploits" like they do for DCMA notices[2]. Apologies for making wrong assumptions. I removed the original Tweet (see screenshot[3] for the original). [1] https://news.ycombinator.com/item?id=29538151 https://news.ycombinator.com/item?id=29538151 [2] https://github.com/github/dmca https://github.com/github/dmca [3] https://i.imgur.com/sJe3OTI.png https://i.imgur.com/sJe3OTI.png
- TruthWillHurt 5y agoSure, a tool for defenders... like Kali Linux is for security researchers..