Hacker News new | ask | show | jobs
by fancl20 1177 days ago
Yeah and they failed to report to China's MIIT within the time window... https://www.wsj.com/articles/china-halts-alibaba-cybersecuri...

(To be clear the obligation is not they have to report to Chinese government first. They just totally forgot to tell the government agency for coordinating these kind of security incident cross companies)

1 comments

TBF at least half of the firms did't give a fuck to the specific regulation at that time, and given the rumor that the bug is found when a Security Engineer (who works on product security instead of vulnerability research) decided to learn CodeQL I'm not surprised nobody on his report chain cared enough.

... and oh hi are you the same fancl20 on <that mostly-defunct Chinese Twitter-clone> some 15 years ago?

Yes I’m… hmmm you can contact me by my id at gmail if you want :)