You better have patched those Log4j holes or we'll see what a judge has to say – FTC

Apply fixes responsibly in a timely manner or face the wrath of Lina Khan

The US Federal Trade Commission on Tuesday warned companies that vulnerable Log4j software needs to be patched … or else.

In case any system administrators last month somehow missed the widespread alarm over vulnerabilities (CVE-2021-44228, CVE-2021-45046, CVE-2021-44832) in the Java logging package, the trade watchdog said Log4j continues to be exploited by a growing number of attackers and urged organizations to act now before it's too late.

The FTC is advising companies to consult the US Cybersecurity and Infrastructure Security Agency's (CISA) guidance on dealing with the Log4j flaws. If companies fail to fix their code and lose customer data, the FTC says it may just see what a judge thinks about that.

"The duty to take reasonable steps to mitigate known software vulnerabilities implicates laws including, among others, the Federal Trade Commission Act and the Gramm Leach Bliley Act," the commission said. "It is critical that companies and their vendors relying on Log4j act now, in order to reduce the likelihood of harm to consumers, and to avoid FTC legal action."

The commission pointed to the example it had made – with the help of the Consumer Financial Protection Bureau and 50 US states and territories – of hacked credit reporting firm Equifax, which agreed to pay $700m to settle charges that it exposed the personal information of 147 million people in 2017. In that instance it was a vulnerability in another open source project that permitted the data heist: Apache Struts.

The tribulations of Equifax may not be the threat the FTC thinks it is, given the skepticism about the commission's effectiveness. Privacy advocacy groups like EPIC note that not much has changed for the data gathering industry in recent years.

Europe's beating the US on data protection

In 2018, the Consumer Financial Protection Bureau, under Acting Director Mick Mulvaney, appears to have wrapped up its investigation of Equifax without seeking subpoenas or obtaining testimony from Equifax executives, or testing Equifax's security [PDF]. So much for oversight.

In testimony before the the House Committee on Financial Services on February 14, 2018, EPIC executive director Marc Rotenberg lamented the lack of a comprehensive US data protection regime like Europe's GDPR and noted the FTC's limited ability to protect data under the "Safeguards Rule" of the Gramm-Leach-Bliley Act.

In short, advocacy groups appear to believe the trade watchdog's bark is worse than its bite.

The Open Markets Institute, a progressive think tank, went so far as to denounce the FTC's 2019 $5bn privacy violation settlement with Facebook – now living under the assumed name Meta – as ineffective and woefully insufficient.

”If we had a strong privacy law on the books, Mark Zuckerberg would already be in jail for his serial lying about Facebook’s abuse of Americans’ data," said Senator Ron Wyden (D-OR) on Tuesday.

"Congress has the opportunity to act now by passing a comprehensive privacy law that can cut off the flow of data to Facebook’s outrage machine by setting strong new rules for how companies can collect, share and use Americans’ personal information. That will go right to Facebook’s business model and hit its bottom line, which seems to be the only thing that company cares about.”

In May last year, after seeing its authority curbed by the US Supreme Court, the FTC begged lawmakers restore its ability to recover funds from fraudsters.

The appointment of Columbia Law School professor and tech company critic Lina Khan last year as Chair of the FTC has raised hopes that the commission can become more effective in policing irresponsible or unlawful behavior among corporate giants, particularly in the tech industry. Khan's influential 2017 paper Amazon’s Antitrust Paradox was a deep dive into how the existing outdated anti-trust laws greatly benefited the tech giants.

The commission at least offers this commitment:

"The FTC intends to use its full legal authority to pursue companies that fail to take reasonable steps to protect consumer data from exposure as a result of Log4j, or similar known vulnerabilities in the future."

You have been politely cautioned. ®

Other stories you might like

  • SpaceX Starlink satellite streaks now present in nearly fifth of all astronomical images snapped by Caltech telescope

    Annoying, maybe – but totally ruining science, no

    SpaceX’s Starlink satellites appear in about a fifth of all images snapped by the Zwicky Transient Facility (ZTF), a camera attached to the Samuel Oschin Telescope in California, which is used by astronomers to study supernovae, gamma ray bursts, asteroids, and suchlike.

    A study led by Przemek Mróz, a former postdoctoral scholar at the California Institute of Technology (Caltech) and now a researcher at the University of Warsaw in Poland, analysed the current and future effects of Starlink satellites on the ZTF. The telescope and camera are housed at the Palomar Observatory, which is operated by Caltech.

    The team of astronomers found 5,301 streaks leftover from the moving satellites in images taken by the instrument between November 2019 and September 2021, according to their paper on the subject, published in the Astrophysical Journal Letters this week.

    Continue reading
  • AI tool finds hundreds of genes related to human motor neuron disease

    Breakthrough could lead to development of drugs to target illness

    A machine-learning algorithm has helped scientists find 690 human genes associated with a higher risk of developing motor neuron disease, according to research published in Cell this week.

    Neuronal cells in the central nervous system and brain break down and die in people with motor neuron disease, like amyotrophic lateral sclerosis (ALS) more commonly known as Lou Gehrig's disease, named after the baseball player who developed it. They lose control over their bodies, and as the disease progresses patients become completely paralyzed. There is currently no verified cure for ALS.

    Motor neuron disease typically affects people in old age and its causes are unknown. Johnathan Cooper-Knock, a clinical lecturer at the University of Sheffield in England and leader of Project MinE, an ambitious effort to perform whole genome sequencing of ALS, believes that understanding how genes affect cellular function could help scientists develop new drugs to treat the disease.

    Continue reading
  • Need to prioritize security bug patches? Don't forget to scan Twitter as well as use CVSS scores

    Exploit, vulnerability discussion online can offer useful signals

    Organizations looking to minimize exposure to exploitable software should scan Twitter for mentions of security bugs as well as use the Common Vulnerability Scoring System or CVSS, Kenna Security argues.

    Better still is prioritizing the repair of vulnerabilities for which exploit code is available, if that information is known.

    CVSS is a framework for rating the severity of software vulnerabilities (identified using CVE, or Common Vulnerability Enumeration, numbers), on a scale from 1 (least severe) to 10 (most severe). It's overseen by, a US-based, non-profit computer security organization.

    Continue reading

Biting the hand that feeds IT © 1998–2022