China Regulators Suspend Alibaba Cloud Partnership Over Log4Shell Reporting (reuters.com) 29
AltMachine writes: "Chinese regulators on Wednesday suspended an information-sharing partnership with Alibaba Cloud Computing, a subsidiary of e-commerce conglomerate Alibaba Group, over accusations it failed to promptly report and address [the Log4Shell vulnerability]," reports Reuters, citing state-backed media reports. Alibaba Cloud recently discovered a major remote code execution vulnerability in the Apache Log4j2 component, notifying the U.S.-based Apache Software Foundation, but did not immediately report it to Ministry of Industry and Information Technology (MIIT,) China's telecommunications regulator.
MIIT said it then received a report from a third party about the issue (days after), rather than from Alibaba Cloud. "In response, MIIT suspended a cooperative partnership with the cloud unit regarding cybersecurity threats and information-sharing platforms, to be reassessed in six months and revived depending on the company's internal reforms," reports Reuters. According to Chinese laws, companies must report new vulnerabilities within 48 hours.
MIIT said it then received a report from a third party about the issue (days after), rather than from Alibaba Cloud. "In response, MIIT suspended a cooperative partnership with the cloud unit regarding cybersecurity threats and information-sharing platforms, to be reassessed in six months and revived depending on the company's internal reforms," reports Reuters. According to Chinese laws, companies must report new vulnerabilities within 48 hours.
you forgot to change the subject (Score:2)
Re: in china (Score:1)
Re: (Score:3)
In America you have to do whatever the media, advertisers and celebrities tell you to do.
No, they might trick you into doing it, but that's very different from being jailed or disappeared.
Re: (Score:2)
No, they might trick you into doing it, but that's very different from being jailed or disappeared.
Really? [wikipedia.org]
Re: (Score:2)
Re: in china (Score:2)
Re: (Score:2)
In America you have to do whatever the media, advertisers and celebrities tell you to do.
No you mustn't do that at all. That's the worst thing you could do.
I know because I was told by the other sides media, advertisers and celebrities.
Lol, dumb government (Score:2)
So you don't like that they reported a software issue to the vendor first.. so instead of raising an issue with their management and work with them, your reaction is to cut off their partnership to basically guarantee they don't share information with you down the road?
Re: (Score:2)
Do you think your own government doesn't think the same?
Re: (Score:2)
So was the protocol to inform the MIIT and then Apache or did somebody just forget to CC on the email?
Is China saying that they don't want security vulnerabilities reported to the sponsoring/owning organization responsible for correcting them for the public good?
Man, you'd think they were looking for back doors or something.
Re: Lol, dumb government (Score:3)
Re: (Score:2)
It's sad how paranoid people become when you mention the word "China".
The Chinese government has a law that says vulnerabilities like this must be reported to it. They didn't follow that law. It's very simple, no need to introduce conspiracy theories.
If you examine the last year's worth of CVEs, you will find that many of them were reported by Chinese nationals, often ones working for Chinese companies like Huawei and Alibaba.
Re: (Score:2, Informative)
No. They didn't like it that they reported to the vendor and NEVER reported as law stated to the MIIT, and that the MIIT had to learn about the bug from a 3rd party instead. The law states that a person finding a bug has to report to MIIT and can but not obligated to the vendor.
Re: (Score:2)
The law states that a person finding a bug has to report to MIIT and can but not obligated to the vendor.
No.. the regulations require vendors and operators - not individual security researchers report vulnerabilities to the state agencies and register their own vulnerability systems with the ministry - as a cloud provider they may be providing service to certain state entities with whom they must abide certain rules; There is not information here that Alibaba found the product they are providing is impa
Re: (Score:2)
Re: (Score:2)
They already weren't sharing the information. What's the point of a partnership like that?
Because they might share information about pertinent vulnerabilities they find in popular software they use if the partnership exist. There could be a multitude of reasons in that ranging from a mistake or inattentiveness by people who were sending the write-ups; all the way up to the most extreme - the reason they failed to "share" might well have been the government's own fault, if the government had made the
Re: (Score:2)
So the biggest most dangerous vulnerability and they 'just forgot' to pass on the info...
Again. What's the point of a partnership like that?
Re: (Score:2)
So the biggest most dangerous vulnerability and they 'just forgot' to pass on the info...
An unmerited assumption. They found a bug in an outside product that a 3rd party vendor (Apache) is responsible for in their capacity as a researcher - that any researcher experimenting with and considering using the library could have discovered. It's not been given that they discovered it by observing incidents of it being exploited against their network product causing an incident on their production network tha
Submitter is a wumao subtmitting CCP (Score:2, Insightful)
state propaganda. Even the most cursory look at their post history makes this blatantly obvious. Thanks for helping /. become a CCP mouthpiece BeauHD.
Re: (Score:3)
What the fuck does this have to do with anything? Is there anything in the summary or in the linked reuters report that is propaganda?
Ad Hominem at best...
does Alibaba suddenly think its in the US (Score:2)
What's Jack Ma up to these days? (Score:2)
Serious question what's Jack up to? Whatever he *is* doing will be abruptly halted and I suspect he'll be spending a few months missing again.
If Jack Ma would have farted in public (Score:1)
they also would have suspended the partnership.
They are just looking for any reason to get control over these domestic threats to the PArty.
Wehrkraftzersetzung in Chinese (Score:3)
Iâ(TM)m surprised their response has taken this long. The alibaba cloud security engineer made the vulnerability known to the whole world instead of delivering it to the party silently, thereby robbing the CCP of the easiest hacking access to world wide IT infrastructure in years. I do not feel so confident about his social credit score and health.
Annoyed they didn't get a head start on exploiting (Score:2)
China is upset because by reporting it to Apache first, that meant the couldn't exploit it before the world knew about it.
Thanks Alibaba cloud for doing the right thing here.
all their work .. gone .. (Score:3)
Poor communist party .. their hacker's favourite backdoor now gone .. oifc China would have4 loved to be told first so they could bury the existence of the vul just a bit longer for yet one other database download ..
"According to Chinese laws, ... (Score:2)