10 ms·
Apache Log4j vulnerability shows the importance of SBOMs of running apps
- mikro2nd 5y ago"Oh, just run `node install` and you'll be fine..."
- deleted 5y ago[deleted]
- karmicthreat 5y agoOr worse, `curl xxx.com/install.sh | sudo bash`
- jaboutboul 5y agoYou really can’t blame developers for wanting ease of use when it comes to software and tool/library installation. At the same time it is incumbent upon people at all levels of the chain to make sure that security (and effective tools for managing it) are part of the mindset as well as the process.
- invalidname 5y agoThis is Java so no: node install... There are Maven dependency commands though.
- cabernal 5y agoEven when the supply chain attacks are not related to the JS ecosystem, JS/NPM gets mocked - inaccurately even...
- simion314 5y ago>Even when the supply chain attacks are not related to the JS ecosystem, JS/NPM gets mocked - inaccurately even... js/npm really desirves it, I lost many hours last week because the shitty philosophy of spiting things not in libraries but in mainly functions and add on top of that packages with incorrect package.json, packages that depend on git repositories or shit where package X is bugged on node version Y so you should upgrade node but if I upgrade node then package W is now incompatible. (I inherited this project os is not my fault it uses outdated stuff or shit that is not longer cool). With this Java log library it seems it does logging and you don't need also a leftpad and isOdd to have it working, some other library that just defines colors, some other library that changes the output from plain text to csv etc. IMO using 1 lib for logging, 1 for unit tests, 1 for db access, 1 for http, 1 for GUI makes sense , what is stupid is if this 5 libraries combined will depend on 100+ libraries , we need to push against this since the npm philosophy and CV driven development is spreading.
- johnisgood 5y agoExactly. People think it is modular and such a great thing to do, but it is not. Maybe it just has to do with flexing. How many libraries do you have? I have 9000! And then in reality it is just one function per library. Or... I have no idea why they think that this is a good thing to do. Can anyone in favor of having "isOdd" function as a library tell me?
- onion2k 5y agoIf anything, the log4j problem goes a long way to highlight that the "package hell" of node_modules isn't limited to JS apps. log4j is a problem that affects compiled apps written in a mature language. All of the usual complaints about JS apps apply (lots of dependencies, code that's not been audited, developers just adding things without proper consideration, etc), but without the usual "lol javascript isn't a real language!" undertone.
- mikro2nd 5y agoFully agree! The point I was trying for is that dependencies have to be managed -- something I've been blathering into the void for a decade, now, without any noticeable impact. Maybe now I'll get those juicy consulting gigs... ;)
- cperciva 5y agolog4j is a problem that affects compiled apps written in a mature language As a C developer, I disagree with the assertion that Java is a mature language. It's only 26 years old! (And in a practical sense even younger than that, since it has changed a lot since the early versions.)
- Zababa 5y agoIt also shows that you have to care not only about the dependencies of your application, but also about the dependencies of applications that you use like Elasticsearch.
- p2t2p 5y agoActually me who's running a stack of services on Node.JS written in TypeScript had a wonderful weekend. I had my birthday on Sunday and took my girls to Christmas fare. So did my colleagues. The other half of the company were busy resolving the incident ;-)
- samwillis 5y agoSince Log4Shell I have asked this question a few times and never really had a solid answer. Why are we not all using some sort of outbound firewall for our apps? Is there something fundamental (other than the administration of it) that stops it being the standard, or even possible? With everyone using un-curated package managers such as NPM and PiPy there is also the chance of a package being compromised. At least if we had outbound firewalls it could help mitigate these problems. It seems to me that there is an incredible opportunity for someone with the right background to build this (I wish it was me). I tend to use PAASs like Heroku for my apps and would love it if this was built in! They even know (most of) what other infrastructure my apps talk to. Why is it not part of Docker? (Obviously everyone should already be using inbound WAF such as CloudFlare)
- 323 5y agoWindows has an enabled by default outbound firewall. The problem is that most apps want to connect to the net these days (check for updates, telemetry, ....) so when an app is installed it adds a firewall exception.
- samwillis 5y agoSure, on desktop. But for a server app (which you built and manage) where you are only talking to known endpoints everything else should be blocked, but we don’t do it. We all use platforms for our apps where anything we use could be compromised and connect to the outside world!
- 323 5y ago> where you are only talking to known endpoint everything else should be blocked I just realized that neither the Windows Firewall, nor the Linux one (ufw/iptables at least) allow you to block based on domain names. They only allow IP address rules.
- samwillis 5y agoExactly, there is a technical limitation (I understand why) of only blocking by IP not hostname, if the IP changes it breaks. Why has this not been solved in the last 50 years? You should be able to block by hostname, it’s how networks are defined. We are an industry of problem solvers but this one seems to have been ignored.
- 323 5y agoSomething like this code notary should be integrated in the OS. When you install an app, the OS records a list of all it's components (declared in a manifest), and when a vulnerability is discovered the OS could quickly disable the affected apps (or apply a quick remediation).
- invalidname 5y agoYou have BOM in maven. You can block dependencies in a maven/gradle build which will fail the build if a sub dependency brings that in. The article incorrectly states that only Java 11 and lower are vulnerable. It's true that they are more vulnerable but newer JDK versions can still be attacked. It's just harder.
- mnd999 5y agoNo, we’re not gonna buy your shitty SAAS just to parse some .pom files. If we’re feeling particularly lazy we might even just do mvn dependency:tree
- mrweasel 5y agoIf you’re me, doing operations for X number of clients, having a tool that would have allowed me to know which clients use which version of log4j would have saved me hours yesterday. I don’t know exactly what library random developer at each customer use, nor do I have access to their code. It would have been nice to be able to easily look up which few clients I need to call.
- dogma1138 5y agoYou don’t need to buy anything just use CycloneDX and OWASP Dependency Track https://news.ycombinator.com/item?id=29542271 https://news.ycombinator.com/item?id=29542271
- chopin 5y agoDoes anyone know why one is protected with higher Java versions? I parsed the vuln as being solely in the log4j library.
- bzzzt 5y agoNewer Java versions disable deserialization of remote classes via LDAP. You're still vulnerable to deserialization of existing classes, but to exploit that there have to be exploitable classes on the classpath already.
- toyg 5y agoLog4j2 uses some JVM features to resolve some addresses, and these features can end up blindly loading external classes in the affected JVMs. Note that non-affected JVMs are still vulnerable to other issues triggered by that resolution process, just not as bad as loading untrusted remote objects. So you should upgrade log4j2 even if you use a non-vulnerable JVM.
- d23 5y agoThis is essentially just an ad for their service, no? Why is this being upvoted? I'm surprised "SBOM" is actually an acronym people would recognize enough to upvote without reading the article.
- gundmc 5y ago"SBOM" almost always refers to Service Bill of Materials in my experience. So not even the acronym would stand out in this usage.
- richardwhiuk 5y agoUsually "Software Bill of Materials".
- gundmc 5y agoYeah, popular usage seems to have shifted over recent years. I'm sure my experience is biased by my close work with discrete manufacturing. Searching Google incognito does seem to validate your assertion.
- mrweasel 5y agoIf your doing software which will need to pass an FDA audit, having a “SBOM” is required, though most would use “SOUP”, software of unknown providence. In these cases I can see a service like this be very useful. There’s a ton of stuff on HN which is just ads for SaaS companies, at least this is new and different. It’s might also be something many are interested in, in light of the Log4j exploit. It would have help me a great deal.
- PaulDavisThe1st 5y agothis seems to represent a rather limited concept of what an actual SBOM would need to be, rather impacted by someone working (primarily?) with non-compiled languages. If your app depends on compiled libraries, then the build-time options used to construct the library are as important as version and checksum information. I see this a lot on HN and the links here - lots of developers for whom a "dependency" is literally a file of non-compiled code, and thus not subject to changes in behavior unless edited. This is not true for compiled languages (and, for all I know, might not even be true for some non-compiled languages).
- hagbard_c 5y agoI just had a look at Airsonic [1] since I'm both a user and a developer and happened upon a related question on Github. Not having access to any fancy-schmancy "SBOM SAAS tool (<blink>try it now for free!!1!</blink>) I just git-grepped the repo which gave me 2 hits. Looking at those I found they were caused by (Apache) commons-logging.jar containing stubs to interface with Log4j. Problem solved. [1] https://github.com/airsonic-advanced/airsonic-advanced/issues/706 https://github.com/airsonic-advanced/airsonic-advanced/issue...