> I haven’t seen 1/100 of this hatred for Apple iMessage vuln that led to NSO zero-click exploits, and I don’t get why.
I think there are a few reasons for this, and most of them aren’t based on logic, but emotion.
First, as bad as the NSO zero-click exploits are, they aren’t things that developers were potentially injecting into their own projects. So there is an easier force to “blame” — Apple (for making the mistakes in the first place — and to be clear, all software can have bugs) and NSO Group (for being pieces of shit) — whereas if you either chose Log4j for your own project, or more likely, chose a project/product that chose to use Log4j, the “who to blame” question becomes a lot less comfortable to answer.
At least with the NSO thing, there is a face of who the bad guy is. So it’s easy to sort of not hate Apple, provided Apple patched exploits as soon as they found them. That doesn’t mean that Apple, a company that has used its “better” security relative to its competitors one of its marketing messages, gets off easy. It’s a black mark for them for sure and will make it harder for the company to argue that it is so much more secure than x, y, z service or platform.
With Log4j, similar to OpenSSL, people have to grapple with the reality that they don’t really know a lot about a lot of the code they run — and even worse, acknowledge that they aren’t capable of understanding or auditing that code themselves. I certainly don’t understand a lot of the code and libraries I rely on for things I build. And if I really stop to think about that, that’s scary. Fortunately, my own projects are personal and aren’t taking data from others. But facing that reality can be a difficult pill to swallow. And Log4j is even worse than OpenSSL in a way, because one could be forgiven for having trust in a well-respected cryptographic library, and for not having a deep understanding of how that library works. But having an insecure logging library? That almost feels avoidable — even if it isn’t.
So people want to blame someone. And when it looks like the code — made by volunteers or not — wasn’t the best written, that’s an easy thing to go to. Rather than self-reflecting about all the libraries we use every day that we don’t think about the security or code quality of.
It doesn’t help that the disclosure, for a host of reasons, wasn’t good. That isn’t me blaming the Log4j team, it just is what it is. Disclosure wasn’t great and the fury to patch made some mistakes and now that there is outsized attention on the library, even more vulnerabilities have been found. Which is all understandable and indicative of what often happens in high stress situations.
Ultimately, we should all accept that mistakes happen and that this wasn’t done out of malice. We all have some level of culpability for what we choose to use in our projects. But mistakes happen.
And as you say, discussion is OK but disrespect isn’t. But I think we see lashing out because people want to find someone to blame.