Apache Log4j bug: China’s industry ministry pulls support from Alibaba Cloud
scmp.com
scmp.com
Things look great until the leaders are doing well, but all it takes is for 1 bad set of leadership for all to fall apart.
And Xi Jinping has guaranteed failure by removing term limits. Term limits meant that other ambitious political leaders were willing to wait and try their luck next turn. But with no term limits multiple generations of leaders are locked out of even the possibility of becoming the party leader, which means they have become a threat to Jinping.
And since so many people are now a threat to him, his selection criteria for people to lead different parts of the party and government has to be based entirely on loyalty rather than competence.
Which almost guarantees a lot of counter productive incompetence.
Mainland China never been ever close to constitutional rule. It's unbelievably naive to think that term limits would've ever been something other than a decoration, and a propaganda point with communists.
> The Communist Party of China proposed amending the Constitution, for the first time after 2004,[3] including writing Scientific Outlook on Development and Xi Jinping Thought into the Preamble,[4] and removing the provision that the President and Vice President "shall serve no more than two consecutive terms" from the Constitution.[5]
https://en.m.wikipedia.org/wiki/2018_National_People%27s_Con...
Judging their systems and dynamics from our point of view misses the point in some cases.
There's an eye opening video about "The Social Credit System" from CCC (Chaos Communication Conference). Take a look if you have time:
https://media.ccc.de/v/35c3-9904-the_social_credit_system
It's an hour long talk.
The argument has been that China needed a reset badly. Free-for-all capitalism hasn't been so great for most folks in the U.S. either, has it? That has been the justification for the heavy hand of the government during Xi's rule. There's also the argument that Western-style term limits prevent long-term strategic planning.
All of those are really tempting and solid arguments, especially given how corrupt China had become with capitalism-ruling-all, but one really does wonder.
As far as Alibaba goes, it's to my understanding that there are no real alternatives to Alibaba Cloud in China (unless you want to go for a foreign solution like AWS or Azure). It would seem that the current government thinks they can get away with making an example of the company as they see fit. There may be some geopolitical logic to that, because Xi's government seeks to make China more independent after Trump's trade wars, and if you have a big, wealthy internet company drawing in the country's top talent, then that's fewer that's e.g. going towards the semiconductor companies they now seek to bolster.
Now there may have been a "correct" policy solution to this, a la antitrust, but it seems Xi's government prefers to be heavy-handed. For me, that's setting some scary precedents, because as other commenters have said, it isn't clear how succession will be handled going forward, and it may well be brutal.
Two orderly successions with no political executions isn’t a particularly high bar…
disagree. Mao started the culture revolution because he was ousted and succeed in taking back the powers. its a high bar that all leaders after Mao didn't try another culture revolution.
It seems to me that term limits are mostly the reserve of countries that have a genuine fear of authoritarian takeovers from recent experience, e.g. the nonaligned countries in South America and Africa.
Countries with executive power vested in a member of Parliament don’t have such limits, hence how you get people like Merkel, Thatcher and Mark Rutte serving as Prime Minister for so long. You also have long-term planning with the maintenance of a professional civil service rather than political appointees and the use of cabinet level decision making rather than allowing the Head of Government to unilaterally make decisions.
America and France are really the only significant “western” (politically rather than geographically) countries you can say have term limits on executive power. In both cases the introduction of term limits are post-ww2 changes. To use either example as a criticism of “the west” as a whole requires a rather narrow view of the world I think.
No, he did not. He built a cabinet of marionettes, and set himself to be a gray cardinal to run the state from behind the curtain. Jiang Zemin then ousted him out of power.
You know nothing about China past the popular propaganda image they wanted Westerners to see.
By eliminating term limits in 2018 Xi Jinping was clearly signaling that he did not intend on relinquishing power.
It's interesting to me that they allowed that to happen, both the US, with its civilian control of the military, and the Soviets, with their convoluted division of manpower, equipment, and commands, took measures to stop that situation from occurring.
Wasn't Jiang still leading the military? Hu appears to be the only one that stepped down on time - but more from the rise of Xi rather than this rule.
I really really really want this to be true, but I don't think it's wise to discount China as a threat to worldwide autonomy just because they're behaving like typical authoritarians, and have the weaknesses that you'd expect from that kind of government.
Personally I think China's demographic issues should be more of a worry for them. The aftermath of the one-child policy, as well as all the selective abortion (under one-child, parents preferred to give birth to a boy) creating a imbalance between the number of men and women, means their population will start shrinking soon. And there will be a lot of only children supporting both of their parents when they start getting older, not to mention a glut of older folks leaving the workforce without equal replacement from the younger generations.
The major difference is their positions in economic transitions.
I think the biggest risk for China would be entering mediocrity and flatlining like Russia. Not growing seems to be their biggest fear.
If China was to deal with French, Japanese or Senegalese people, it would immediately crumble. All they can do is firefight for internal stability, or change enormously to inspire positively, but it's not yet looking that way.
Perhaps this translation is incorrect, but Chinese speaking commenters below think that it is accurate, so it's probably just the article being wrong (as usual), leading to incorrect conclusions that China is not a threat and will not succeed because they will shoot themselves in the foot etc, while reality is a lot more reasonable.
What, exactly, is it doing right now? This sounds a lot like "Tom Brady cannot succeed with his current height." Um, he already has, and continues to do so.
What do dictators do when their policies start failing and popularity declines?
They go to war. Nothing distracts the population as much. This is the biggest risk with China's expanding military power.
And since so many Americans are now a threat to the Democrats, their selection criteria for people to lead different parts of the party and government has to be based entirely on race and gender rather than competence.
Which almost guarantees a lot of counter productive incompetence.
I know about Dr. Sun's republic, Taiwan and "voting politburo" . But these are considered modern development which hasn't really sunk into physche of Chinese race worldwide.
Here it is: Verify. Report to 'vendor'. Immediately. Report to government including an analysis within 2 days.
Link to policy: http://www.gov.cn/gongbao/content/2021/content_5641351.htm
Link to past HN comment on this on another story on this topic: https://news.ycombinator.com/item?id=29653352
(archived version of the article: https://archive.md/Yvsca)
From your linked policy (translated by Apple):
>Article 7 Network product providers shall fulfill the following security vulnerability management obligations
>(2) Relevant vulnerability information shall be submitted [...] within 2 days
In this case, an Alibaba researcher found a bug in an Apache product, so this policy wouldn't seem to apply as Alibaba is not the vendor of the product.
It seems to say that they should notify the vendor (ie, Apache) as soon as possible, and notify the government within 2 days (according to rfoo they are not at all required to disclose it to the government since it's not their product, but they are encouraged to do so), not that they should notify the government first and then wait for approval to notify Apache.
According to google translate:
(1) After discovering or learning about the security vulnerabilities in the provided network products, they should immediately take measures and organize verification of the security vulnerabilities to assess the degree of harm and the scope of the security vulnerabilities; for the security vulnerabilities in their upstream products or components, they should Notify the relevant product provider immediately.
(2) The relevant vulnerability information should be reported to the Ministry of Industry and Information Technology's cyber security threat and vulnerability information sharing platform within 2 days. The content of the submission shall include the product name, model, version, and the technical characteristics, harm, and scope of the vulnerability that have security loopholes in network products.
So according to machine translation, the article is incorrect, and they do not have to notify the CCP first, instead they should have notified Apache first, and then the government within 2 days.
At the same time, the article doesn't say that China is going to stop supporting Alibaba Cloud, just that that the MIIT is freezing cybersecurity cooperation, as far as I understand the article there is no legal punishment or serious financial punishment, and it's not even clear that the cooperation with the MIIT didn't have other terms. It's not clear either that they followed the 2-day period.
Given that the punishment is rather obscure and really weak (okay, your country's CERT felt pissed off and won't talk to you for 6 months, but for megacorps like Alibaba, would they really care?), I don't think they are willing to break the rule, at least for now.
That's wrong. According to the text Alibaba is not required to report the bug to government at all. The 2 days term apply to "domestic network product provider" which would be ASF/log4j maintainers in this case. But they are not domestic so this does not apply.
Do you mean by redistributing log4j they became a "network product provider" of log4j?
AFAIK when the bug became popular on Dec 9, there are still many Java-based services running by Alibaba Cloud remain unfixed, and it caused chaos and panic among their "SRE"s.
However reading the regulation text again, now I'm not sure in this case what Alibaba should report:
> (二)应当在2日内向工业和信息化部网络安全威胁和漏洞信息共享平台报送相关漏洞信息。报送内容应当包括存在网络产品安全漏洞的产品名称、型号、版本以及漏洞的技术特点、危害和影响范围等。
It said they should report "the name, type and version of the product with the vulnerability, the 'technical characteristics' of the vulnerability and the impact". Does this mean, Alibaba should report, for example:
"Alibaba Cloud hosted Apache Flink stream computing service (whatever brand name they use) contains a pre-auth critical RCE vulnerability due to insecure processing of user input in version a.b.c till x.y.z"?
I'm not seeing how could the government know what the bug really is if "the product" means Alibaba Cloud's own product.
https://en.wikipedia.org/wiki/CERT_Coordination_Center
> The CERT Coordination Center (CERT/CC) is the coordination center of the computer emergency response team (CERT) for the Software Engineering Institute (SEI), a non-profit United States federally funded research and development center.
So many people attach their identity to their country of origin or citizenship. You can think of that what you want, but by avoiding "attacking the country" verbally, you shield your argument from that flavor of wumao vitriol.
The OP does this right: "CCP pulls support", not "China pulls support".
I see a similar thing with Israel - don't want to be portrayed as antisemitic? Address the administration, not the country.
This was using the law as a weapon to keep companies in check. If this had been another company firmly in the pocket of the CCP, this would have been overlooked and never made public.
Shit HN says. Can we avoid making such blanket statements, please and thank you.
I'm not sure if such behaviors would be desirable in any country.
Did they want to protect themselves before alerting anyone?
Did they want to use this to infiltrate others?
Probably yes.
> Did they want to use this to infiltrate others?
Also probably yes.
The NSA does the same thing. They stockpile security vulnerabilities and selectively tell the software vendors about some of them. They like to keep the "high value" vulnerabilities to themselves for use in exploits.
The WannaCry ransomware (see https://en.wikipedia.org/wiki/WannaCry_ransomware_attack and https://en.wikipedia.org/wiki/EternalBlue) did worldwide economic damage and was built on an NSA developed exploit. The NSA knew about this vulnerability in Windows for years and never told Microsoft.
Unfortunately all intelligence agencies everywhere will continue to take this cowboy approach. Until we can get these bad actors under control, their constant undermining of internet infrastructure will continue to hinder efforts to improve internet security.
And even if the end result has some overlap, there's a bit of an ethical difference between:
* developing an exploit that you keep quiet
* preventing others from talking about exploits they discover
I don't care which bunch of spies does it more. I don't want spies doing it at all.
Yah, I guess by not searching for new exploits tonight for public disclosure, I'm putting the entire software world marginally more at risk by "grubby inaction."
> I don't care which bunch of spies does it more. I don't want spies doing it at all.
I care: some bad actors in my government vs. forcing an entire massive economy to participate in bad actions will have massively different magnitudes of effect.
There's always going to be bad actors, but preventing 15% of the world's population from being good actors surely is a pretty significant thing.
It's not ethical. It's not professional. It's school boy stuff.
* Google Project Zero researcher: "we found a bug!"
* NSA (internally): "Damnit, scratch that one off the list boys.."
Note that the article is misleading as the rule doesn't require the disclosure must be made to the government first.
http://www.gov.cn/gongbao/content/2021/content_5641351.htm
Here is a machine translation of the relevant section that seems to agree with the GP:
>Article 7 Network product providers shall perform the following network product security vulnerabilities management obligations, ensure that their product security vulnerabilities are repaired in a timely manner and reasonably released, and guide and support product users to take preventive measures:
>(1) After discovering or learning about the security vulnerabilities in the provided network products, they should immediately take measures and organize verification of the security vulnerabilities to assess the degree of harm and the scope of the security vulnerabilities; for the security vulnerabilities in their upstream products or components, they should Notify the relevant product provider immediately.
>(2) The relevant vulnerability information should be reported to the Ministry of Industry and Information Technology's cyber security threat and vulnerability information sharing platform within 2 days. The content of the submission shall include the product name, model, version, and the technical characteristics, harm, and scope of the vulnerability that have security loopholes in network products.
>(3) Remediation of network product security vulnerabilities should be organized in a timely manner. For product users (including downstream manufacturers) that need to take measures such as software and firmware upgrades, network product security vulnerabilities and repair methods should be promptly informed of the product users who may be affected , And provide the necessary technical support.
I guess everyone has forgotten wikileaks and Snowden already.
If AWS didn't then their contract for service is deficient. If they had risks which affected their stock price they had obligations to other agencies too. The department of commerce, the federal communications agency, the US Cert, you name it.
Please, no accusations of whataboutery: I am trying to point out that if you are big enough to have economically relevant importance, OR if you supply goods and services to the state, any state, you have obligations in that state relationship.
if I was in government in China and ali baba cloud didn't check in, I might be witholding business too.
>Which almost guarantees a lot of counter productive incompetence.
This applies to every goverment and public institution regardless of its democratic roots
I hope the price Alibaba has to pay for it won't be too high.
Through I expect Alibaba to now fall-in-line wrt. Future decisions of this kind, it's not that they have much choice.
It probably gets labeled as a procedural error, i.e. the one(s) who report it to the log4j project thought it is already reported to the government, and the ones on the other side say they thought the first team would report it to the government. Then they "fall-in-line" by implementing a security report system where you can't make the mistake, which automatically reports to the government and you need to get "clearance" to report to the project authors.
Which, might have been what actually happened if I think about it.
The Ministry of Industry and Information Technology (MIIT) is suspending work with Alibaba Cloud as a cybersecurity threat intelligence partner for six months because the company did not immediately report a severe bug in the widely used logging software to the government agency, the 21st Century Business Herald reported. The ministry also said it would reassess whether to resume the partnership at that time, based on measures Alibaba has taken to correct the problem.
Losing the support of the agency could affect business prospects for the cloud computing unit of Alibaba, the owner of the South China Morning Post. However, specific losses for the country’s largest cloud business are hard to determine.
The MIIT launched a cybersecurity threat intelligence sharing platform in December 2019 to serve as a state-led alliance in dealing with security threats. Membership in the platform is government recognition of the member’s capabilities in spotting and managing threats.
The MIIT did not publish a public statement about its decision, and Alibaba did not respond to a request for comment.
The Log4j vulnerability has been described as a “nightmare” and “catastrophic”, with some experts saying it is the most severe cybersecurity threat ever by number of devices affected. The simple piece of Java-based software can be found in countless internet-connected devices, from Internet-of-Things products like televisions and cameras to the servers running cloud operations for tech giants like Amazon, Google and Microsoft.
The flaw first received widespread attention when it was publicly disclosed on December 9, after Alibaba Cloud Security Team engineer Chen Zhoujun discovered the flaw. Chen notified the Apache Software Foundation, the non-profit corporation that develops the open-source Log4j tool, by email on November 24.
According to a regulation passed this year, Chinese companies are obliged to report vulnerabilities in their own software to the MIIT through its National Vulnerability Database website. However, the Internet Product Security Loophole Management Regulation, which went into effect in September, only “encourages” companies to report bugs found in others’ software.
The MIIT cybersecurity management bureau released a statement on December 9 saying it was notified about the vulnerability by “relevant” cybersecurity institutions. The ministry summoned Alibaba Cloud and other cybersecurity firms to discuss the situation, it said. It also urged companies and the public to monitor for updates to patch their systems.
Cybersecurity industry norms encourage notifying vendors of security flaws first, giving them ample time to address the problem, before disclosing the issue to the public. Apache released a patch for the Log4j bug on December 6, three days before public disclosure.
Still, the effect of the bug’s discovery is expected to be wide-ranging because of Log4j’s ubiquity. Many people may not even be aware that their systems are compromised.
The exploit, known as Log4Shell, allows hackers to remotely execute code by getting it logged by the software. This became a problem in the Java edition of Microsoft’s game Minecraft, for example, allowing players’ to compromise others’ systems by sending malicious code through chat messages.
Cybersecurity experts on Twitter have commended the Alibaba Cloud engineer for responsibly disclosing the vulnerability directly to the tool’s developers.
Since the bug’s public disclosure, cybersecurity experts have warned of an increase in activity scanning for Log4j on vulnerable systems. Microsoft said on December 11 that it found that state actors connected with China, Iran, North Korea and Turkey have been both experimenting and exploiting the vulnerability."
Both those factors have changed. The Chinese people are not gonna tolerate an extended reduction in their quality of life. Anything short of rapid quality of life growth may be catastrophic for the people in power.
And on the other side, other countries have a lot of incentive to further make things difficult for China and it’s leadership.
>As recently as 31 May 2021, China's government has relaxed restrictions even more allowing women up to three children.
[0] https://en.wikipedia.org/wiki/One-child_policy#Abolition
This number is even worse than it appears though, since there are so many more men than women to begin with, thanks to the history of sex-selective abortion in the country. 12 million Chinese women were never born because their parents wanted a son instead of a daughter, and that's an extra 1.3 x 12 = 16 million children that will be missing from the next generation.
China's population is actually predicted to start shrinking in about 5 years.
A little overall population contraction isn't necessarily dire. The concerning thing is a decreasing fraction of the population being working age.
Ultimately, the most dire predictions have China's population halving over the next lifetime, and a sustained, big drop in youth. That's a pretty damning trend.
* Liberalizing birth restrictions can't have any effect on the number of workers until ~20 years later, and in practice much later than that.
* Once the population pyramid has begun to invert, you have fewer people of childbearing age. Reversing the policy cannot replace the children who were not born a few years ago to families who are now beyond the point of seriously considering more children.
* In practice, once having fewer children is socially normalized, it's difficult to have a larger family going forward, and...
* Once you have a severely inverted population pyramid, the cost of supporting elders increases and the economic situation of those of working age deteriorates, which tends to further suppress births.
It takes a long time for these trends to reverse.
Like there are many cases where governments tried to avoid an internal collapse by applying external pressure in form of starting a war.
There’s tens of millions of people with that name. The WHO did not want to stigmatize all of them which is why they skipped the letter. It had little to do with Xi Jinping alone.
The WHO moved to Greek lettering to avoid stigmatization faced by people who were being associated with different variants. It wouldn’t make much sense to do the same when you can avoid it by just skipping a letter.
There is a Mu variant of Covid[0]
Watching ADV China really helped me understand how bad the government is over there: https://youtube.com/c/ADVChina
https://www.youtube.com/watch?v=bpQFCcSI0pU
https://www.youtube.com/watch?v=a-GVcfP1zrg
And here's a pretty thorough analysis of the flaws with this theory: https://www.youtube.com/watch?v=ab-r0capbzk
Just watching the 'thorough' analysis video, he talks about some person who posted a paper about the source, and in the screenshot it shows Feb 2020. And says the source of the paper was from laowhy86's video, which is published April 2020.
I stopped watching there because it already makes no sense.
At timestamp 6:36 of his video [1], laowhy86 analyzes a copy of the draft "The possible origins of 2019-nCoV coronavirus" to conclude that the virus must have come from the lab. This preprint has been shown to be false by future scholarship (see the citations of the draft at [2] for some examples).
Potholer then analyzes the veracity of the claims within that preprint in his video [3], starting with an excerpt of [1] starting at 2:02.
So the timeline should be:
Feb. 2020 - Preprint published
->
Apr. 2020 - laowhy's video
->
May 2020 - potholer's rebuttal
[1] https://www.youtube.com/watch?v=bpQFCcSI0pU
[2] https://scholar.google.com/scholar?cites=1699435143784344899...
what country is that?
No, that's not because we're secretly in cahoots with communists—it's because we don't want a site that consists of lame flamewars and then turns itself into scorched earth and then heat death. We want thoughtful, curious conversation. If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.
Edit: your previous two comments were egregiously breaking the rules here as well—even worse actually. That's seriously not ok. Please review https://news.ycombinator.com/newsguidelines.html and stop posting like that, regardless of how strongly you feel about $country, and regardless of how legitimate your reasons are (which I'm sure they are). I don't want to ban you but we can't have accounts carrying on like that here.