News: 1640239084

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Alibaba Cloud slapped by Chinese ministry for mishandling Log4j

(2021/12/23)


China's Ministry of Industry and Information Technology has suspended Alibaba Cloud's membership of an influential security board to protest its handling of the Log4j flaw.

The move appears odd as The Apache Software Foundation [1]credited Alibaba Cloud's Chen Zhaojunfor identifying and reporting the Log4J flaw in the first place. You might think Alibaba Cloud deserves a parade for identifying a dangerous flaw, and showing that Chinese bug-hunters can match it with the world's best.

But according to Chinese outlet [2]The 21st Century Herald , Chinese authorities were displeased with the cloud giant's response.

[3]

The outlet reported that Alibaba drew ire for not reporting the security vulnerabilities to MIIT in a timely manner and not effectively supporting the ministry’s network security threat and vulnerability management efforts.

[4]

[5]

As punishment, the ministry suspended Alibaba Cloud’s position on its security board for six months. After six months, the ministry will reassess Alibaba Cloud’s corrective measures and suitability.

The Register has been unable to find the document the herald referred to, and Neither MIIT nor Alibaba have released public statements about the decision, so we are in the dark about Beijng's reasoning.

[6]Belgian defence ministry admits attackers accessed its computer network by exploiting Log4j vulnerability

[7]Bad things come in threes: Apache reveals another Log4J bug

[8]Over Log4j? VMware has another critical flaw for you to patch

However, we can speculate.

We know that the bug was reported to the Apache Foundation on November 24th.

[9]

A timeline of the Log4j incident by Cisco's Talos security team [10]states news of the flaw leaked to GitHub on November 30th.

Talosand Cloudflare reported both reported they detected exploits of the bug in the wild before it was disclosed, and fixed, once on December 1 and again on December 2.

Just how the authors of those exploits learned of the bug is not known.

[11]

Another piece of evidence, a since-deleted tweet from an account using the handle @P0rZ9, has been [12]dated as debuting a dozen hours before the Apache Foundation issued its patch on December 10th.

A since-deleted GitHub post from December 9th, made by an Alibaba staffer, is also suspected to have been published before the patch. The Wayback Machine has preserved the post [13]here .

If Alibaba staffers were the source of the GitHub leaks, Beijing may wish to punish the company for that error.

Or perhaps Alibaba didn't meet local reporting requirements. Chinese companies are required to report vulnerabilities in their own software to MIT’s National Vulnerability Database website within two days, and Alibaba Cloud is likely to have lots of Log4j its own systems and customers' cloudy rigs. [14]Provisions on Security Loopholes of Network Products , which went into effect in September encourages Chinese companies to report bugs in other software.

Perhaps the scariest possible reason Alibaba has been punished is that Beijing is miffed the company reported the flaw to Apache, thereby denying China a zero day exploit that had enormous offensive potential. ®

Get our [15]Tech Resources



[1] https://logging.apache.org/log4j/2.x/security.html

[2] https://m.21jingji.com/article/20211223/ae117ea5f6fc0aef611ed854ab9e9855.html

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YcRW2mRDdFSzw7rSO0Id6wAAANI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YcRW2mRDdFSzw7rSO0Id6wAAANI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YcRW2mRDdFSzw7rSO0Id6wAAANI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/12/21/belgium_defence_ministry_log4j_exploited/

[7] https://www.theregister.com/2021/12/19/log4j_new_flaw_cve_2021_45105/

[8] https://www.theregister.com/2021/12/17/vmware_criticial_uem_flaw/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YcRW2mRDdFSzw7rSO0Id6wAAANI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://blog.talosintelligence.com/2021/12/apache-log4j-rce-vulnerability.html

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YcRW2mRDdFSzw7rSO0Id6wAAANI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://twitter.com/nealmcb/status/1470799353333833731

[13] https://web.archive.org/web/20211209185411/https://github.com/tangxiaofeng7/apache-log4j-poc

[14] http://www.gov.cn/gongbao/content/2021/content_5641351.htm

[15] https://whitepapers.theregister.com/



sanmigueelbeer

China's Ministry of Industry and Information Technology has suspended Alibaba Cloud's membership of an influential security board to protest punish its handling of the Log4j flaw

TFTFY

Last paragraph

cookieMonster

sounds about right

Re: Last paragraph

pavel.petrman

Already at "ministry’s network security threat and vulnerability management efforts" I thought if what eventually constitutes the last paragraph. Security threat and vulnerability management indeed.

BOFH in Training

I am reading in many places that many state actors are using this exploit. Including suspected China state actors.

Imagine if China was aware of this issue before the rest of the world..........

Cutting off nose to spite face?

Anonymous Coward

Is there an equivalent Chinese proverb?

Saying your star player will be booted off the football team is a bit daft. Alibaba could very much just find more of these issues and without a forum to discuss, do the same again, putting MIIT at a disadvantage.

But hey this is above my pay grade, brighter people than me can see the wisdom in it.

Re: Cutting off nose to spite face?

Anonymous Coward

Pride often makes people do very silly things.

I'm guessing publicising it ...

Anonymous Coward

... wasn't in the interests of "The Party" ?

the phrase "pour encourager les autres" seems apt.

The college graduate is presented with a sheepskin to cover his
intellectual nakedness.
-- Robert M. Hutchins