Alibaba Cloud slapped by Chinese ministry for mishandling Log4j
- Reference: 1640239084
- News link: https://www.theregister.co.uk/2021/12/23/alibaba_cloud_in_trouble_with/
- Source link:
The move appears odd as The Apache Software Foundation [1]credited Alibaba Cloud's Chen Zhaojunfor identifying and reporting the Log4J flaw in the first place. You might think Alibaba Cloud deserves a parade for identifying a dangerous flaw, and showing that Chinese bug-hunters can match it with the world's best.
But according to Chinese outlet [2]The 21st Century Herald , Chinese authorities were displeased with the cloud giant's response.
[3]
The outlet reported that Alibaba drew ire for not reporting the security vulnerabilities to MIIT in a timely manner and not effectively supporting the ministry’s network security threat and vulnerability management efforts.
[4]
[5]
As punishment, the ministry suspended Alibaba Cloud’s position on its security board for six months. After six months, the ministry will reassess Alibaba Cloud’s corrective measures and suitability.
The Register has been unable to find the document the herald referred to, and Neither MIIT nor Alibaba have released public statements about the decision, so we are in the dark about Beijng's reasoning.
[6]Belgian defence ministry admits attackers accessed its computer network by exploiting Log4j vulnerability
[7]Bad things come in threes: Apache reveals another Log4J bug
[8]Over Log4j? VMware has another critical flaw for you to patch
However, we can speculate.
We know that the bug was reported to the Apache Foundation on November 24th.
[9]
A timeline of the Log4j incident by Cisco's Talos security team [10]states news of the flaw leaked to GitHub on November 30th.
Talosand Cloudflare reported both reported they detected exploits of the bug in the wild before it was disclosed, and fixed, once on December 1 and again on December 2.
Just how the authors of those exploits learned of the bug is not known.
[11]
Another piece of evidence, a since-deleted tweet from an account using the handle @P0rZ9, has been [12]dated as debuting a dozen hours before the Apache Foundation issued its patch on December 10th.
A since-deleted GitHub post from December 9th, made by an Alibaba staffer, is also suspected to have been published before the patch. The Wayback Machine has preserved the post [13]here .
If Alibaba staffers were the source of the GitHub leaks, Beijing may wish to punish the company for that error.
Or perhaps Alibaba didn't meet local reporting requirements. Chinese companies are required to report vulnerabilities in their own software to MIT’s National Vulnerability Database website within two days, and Alibaba Cloud is likely to have lots of Log4j its own systems and customers' cloudy rigs. [14]Provisions on Security Loopholes of Network Products , which went into effect in September encourages Chinese companies to report bugs in other software.
Perhaps the scariest possible reason Alibaba has been punished is that Beijing is miffed the company reported the flaw to Apache, thereby denying China a zero day exploit that had enormous offensive potential. ®
Get our [15]Tech Resources
[1] https://logging.apache.org/log4j/2.x/security.html
[2] https://m.21jingji.com/article/20211223/ae117ea5f6fc0aef611ed854ab9e9855.html
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YcRW2mRDdFSzw7rSO0Id6wAAANI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YcRW2mRDdFSzw7rSO0Id6wAAANI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YcRW2mRDdFSzw7rSO0Id6wAAANI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/12/21/belgium_defence_ministry_log4j_exploited/
[7] https://www.theregister.com/2021/12/19/log4j_new_flaw_cve_2021_45105/
[8] https://www.theregister.com/2021/12/17/vmware_criticial_uem_flaw/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YcRW2mRDdFSzw7rSO0Id6wAAANI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://blog.talosintelligence.com/2021/12/apache-log4j-rce-vulnerability.html
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YcRW2mRDdFSzw7rSO0Id6wAAANI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://twitter.com/nealmcb/status/1470799353333833731
[13] https://web.archive.org/web/20211209185411/https://github.com/tangxiaofeng7/apache-log4j-poc
[14] http://www.gov.cn/gongbao/content/2021/content_5641351.htm
[15] https://whitepapers.theregister.com/
Last paragraph
sounds about right
Re: Last paragraph
Already at "ministry’s network security threat and vulnerability management efforts" I thought if what eventually constitutes the last paragraph. Security threat and vulnerability management indeed.
I am reading in many places that many state actors are using this exploit. Including suspected China state actors.
Imagine if China was aware of this issue before the rest of the world..........
Cutting off nose to spite face?
Is there an equivalent Chinese proverb?
Saying your star player will be booted off the football team is a bit daft. Alibaba could very much just find more of these issues and without a forum to discuss, do the same again, putting MIIT at a disadvantage.
But hey this is above my pay grade, brighter people than me can see the wisdom in it.
Re: Cutting off nose to spite face?
Pride often makes people do very silly things.
I'm guessing publicising it ...
... wasn't in the interests of "The Party" ?
the phrase "pour encourager les autres" seems apt.
China's Ministry of Industry and Information Technology has suspended Alibaba Cloud's membership of an influential security board to protest punish its handling of the Log4j flaw
TFTFY